ThinkPatternGet the app
Story
TECHNOLOGY · MAY 18, 2026

CISA Contractor Exposes GovCloud Credentials in Public GitHub Repository

The Cybersecurity and Infrastructure Security Agency is investigating a six-month leak of administrative credentials and infrastructure data exposed by a government contractor on GitHub.

A contractor for the Cybersecurity and Infrastructure Security Agency (CISA), employed by Nightwing, exposed 844 MB of production infrastructure material in a public GitHub repository titled "Private-CISA." The repository, created on November 13, 2025, remained accessible for six months before being locked down following discovery by security researchers.

The leak included highly privileged administrative credentials for AWS GovCloud accounts, SSH keys, plaintext passwords, Azure registry keys, and Kubernetes manifests. Files such as "AWS-Workspace-Firefox-Passwords.csv" were among the exposed data. Researchers Guillaume Valadon and Philippe Caturegli flagged the incident, noting that the contractor had deliberately disabled GitHub's secret detection features to maintain the repository.

CISA spokesperson Marco DiSandro stated the agency is investigating the situation. The agency maintained there is currently no indication that sensitive data was compromised, though it acknowledged the need for additional safeguards to prevent future occurrences. The breach occurred as CISA has operated without a permanent director since January 2025 and has lost nearly a third of its workforce due to budget and staffing reductions under the second Trump administration.


Reported across 10 outlets
Actors
U.S. Department of Homeland SecurityNightwing

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play