IC Technology & Surveillance — 2026-05-19
CISA Contractor Exposed AWS GovCloud Administrative Credentials on Public GitHub Repository
BLUFFormal attribution of unauthorized access is unlikely within 18 months of disclosure, but the six-month artifactory exposure and 48-hour post-takedown key validity leave CISA's software supply chain materially at risk.
A Nightwing contractor employee maintained the public GitHub repository "Private-CISA" from November 13, 2025 until the weekend of May 17–18, exposing administrative credentials to three AWS GovCloud accounts and plaintext passwords for dozens of CISA's internal systems 1. GitGuardian researcher Guillaume Valadon flagged the exposure to KrebsOnSecurity on May 15 after the account owner failed to respond to automated alerts, and Seralys founder Philippe Caturegli independently confirmed the credentials authenticated to the three GovCloud accounts at high privilege 1. Commit logs show the contractor explicitly disabled GitHub's default secrets-detection feature, and Caturegli reported the exposed AWS keys remained valid for 48 hours after the repository was removed 12. CISA told KrebsOnSecurity it is investigating and has found no current indication that sensitive data was compromised 12.
AnalysisThe most persistent risk is artifactory access: any actor present during the six-month window could have seeded backdoors propagating through every subsequent software build. Per KrebsOnSecurity reporting corroborated by two independent researchers, a formal determination of unauthorized access is
unlikely within 18 months of public disclosure, at moderate confidence, given a workforce reduced by roughly a third since early 2025 and cloud logs that may be incomplete. The 48-hour post-removal validity of AWS keys confirms credential management failures outlasted the takedown. A Congress-compelled IG investigation could surface access evidence CISA's degraded internal capacity cannot, making the unlikely assessment contingent on political will. Absent that, the agency closes the incident without supply-chain remediation of software built during the exposure window.
2 sources
- CISA Admin Leaked AWS GovCloud Keys on GitHub - Krebs on Security
- 'The Worst Leak That I've Witnessed': U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub - Gizmodo
View in full brief →