I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenamesThe US Cybersecurity and Infrastructure Security Agency left open a GitHub repository named “Private-CISA” containing plain-text passwords, private keys, tokens, and secrets – with obvious file names like “external-secret-repo-creds.yaml” and “AWS-Workspace-Firefox-Passwords.csv” – for six months.
GitGuardian researcher Guillaume Valadon, fresh off a recent talk on Kubernetes secret leaks, found the public repository on May 14, and toldthat he “quickly understood that the leak was bad and that time was running out. A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak gets.
” Valadon, who previously spent nine years at France’s CISA equivalent, ANSSI, told us the leak included tokens for CISA's internal JFrog Artifactory, Azure registry keys, AWS credentials, Kubernetes manifests, ArgoCD application files, Terraform infrastructure code, GitHub personal access tokens, and Entra ID SAML certificates. Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student dataGitGuardian reported the leaky repository to CISA on May 14, and the agency took it down a day later. that it was aware of the report and is investigating.
"Currently, there is no indication that any sensitive data was compromised as a result of this incident. ”he initially thought the repo “was a hoax, given how suspicious the directory names , file names , and their contents seemed too good to be true,” Valadon wrote. It wasn’t a hoax – “The Cybersecurity and Infrastructure Security Agency is aware of the reported exposure and is continuing to investigate the situation,” but it was a “catalogue of unsafe practices,” he added, containing passwords stored in plain text, backups committed to Git, and an “explicit” how-to guide for disabling GitHub's secret scanning.
After initially reporting the leak through the CERT/CC portal, and only receiving an auto-acknowledgement as of the morning of May 15 – a Friday – Valadonsecurity journalist Brian Krebs about the publicly exposed secrets, which seemed to speed up CISA’s processes. By 6 pm EST that night, the feds took down the repository. he gives CISA credit for quickly deleting the repository.
“Most of our responsible disclosures take much longer, and many are never fixed,” he said. “Managing to take the repository offline in a day is impressive work. ” He doesn’t know if any other parties with less altruistic intentions found the secrets first, although the fact that the repository was never forked would seem to indicate that it wasn’t widely circulated on the dark web.
“Each category of secret in the repository unlocks a specific attack path,” Valadon said. “Stacked together, they cover the full range: from destructive attacks and ransomware extortion to quiet, long-term persistence inside CISA's build and deployment pipeline. That last scenario worried me the most, and it's why I escalated through every channel we had until the repository was taken offline.
” Plus, the committer used both a CISA-issued contractor email and a personal Yahoo email across the same commits, and created the repository using a personal GitHub account.
“That mixed-identity pattern is one of the hardest surfaces for security teams to cover, and it's where the worst leaks happen,” Valadon said. ®I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'? Airbus gets HPC-as-a-service supercomputer from BullSecuritySecurityInfrastructure teams are facing a perfect storm: extended hardware lead times, rising costs driven by AI demand, and accelerated platform timelines.
From Prompt to Exploit: How LLMs Are Changing API AttacksJoin Druva experts for a compelling deep dive into what it takes to build an identity-first recovery strategy in this new threat landscape. Join Druva experts for a compelling deep dive into what it takes to build an identity-first recovery strategy in this new threat landscape. They’ll reveal how attackers use your profile as intel and show you how to make yourself harder to targetAI Found the Problem. Now What?
Step into the chaos of a live ransomware breach, test your response skills, and team up with other IT and security pros to outsmart cybercriminalsAirbus gets HPC-as-a-service supercomputer from BullMicrosoft refreshes Surface for Business lineup, starts AI PC upsell at $1,499Shadow AI invades the workplace, up 4x in the last yearSAP customers warned AI agents could put costs on autopilotX limits hot takes from freeloaders to 50 a dayShai-Hulud keeps burrowing: 314 npm packages infected after another account compromise Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warningsLSEG signs up for five more years of Cloud Foundation, but keeps quiet on how much it'll cost Indra rides off with £1.96B Transport for London ticketing deal as Oyster heads for back-office overhaul1 in 5 Brits think AI layoffs could trigger civil unrestNobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data
United Kingdom Latest News, United Kingdom Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Why America Can’t Walk Away from the Gulf Economies'The Gulf states can still build a future based on security, connectivity, capital, and social opening. And their success still matters to the United States and the world,' write Daniel Benaim and Elisa Ewers
Read more »
Aileen Wuornos, 'America's first female serial killer', forms unlikely relationship with woman in prisonThe story of Aileen Wuornos, a sex worker and serial killer, who formed an unlikely relationship with a woman in her 40s while in prison, and the impact of her traumatic childhood on her later life.
Read more »
America's most iconic bakery just arrived in the UK — one item is worth the hypeYou'll have to be quick if you want to try it.
Read more »
Trump is behaving like a dictator – America has to wake upThe US President's anti-weaponisation fund is a threat to American democracy itself
Read more »




