← Back to KHAO

GitHub · Kubernetes ·

One file, helpfully named “importantAWStokens,” contained admin credentials for three AWS GovCloud accounts

2 min read

Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.

◌ Single Source

CISA exposed plaintext passwords and cloud keys on GitHub for six months.

Beyond the passwords, the repo included GitHub tokens, sensitive YAML configuration files, and references to CISA’s own software-building environment.

Key facts

Summary

The US federal cybersecurity agency, tasked with protecting critical infrastructure, left admin credentials and AWS GovCloud keys in a public repository that sat undetected for half a year. A public repo maintained by a CISA contractor, ironically named “Private-CISA,” contained 844 MB of sensitive data including administrative credentials for AWS GovCloud accounts, CI/CD logs, Kubernetes manifests, and internal documentation. One file, helpfully named “importantAWStokens,” contained admin credentials for three AWS GovCloud accounts. After GitGuardian flagged the issue, the repository was taken down within approximately 26 hours, by May 15, 2026.

Read full article at Crypto Briefing →

#GitHub #Kubernetes