A major CISA leak of sensitive data came to light when it was discovered that a contractor for the Cybersecurity & Infrastructure Security Agency maintained a public repository on GitHub that contained credentials for privileged AWS GovCloud and a large number of internal CISA systems. According to cybersecurity experts, the public archive included files that revealed how CISA builds, tests, and deploys software internally.
See also: AWS CodeBuild: Misconfiguration put GitHub repos at risk

The discovery was made on May 15 when Guillaume Valadon, a researcher at security firm GitGuardian, contacted KrebsOnSecurity. Valadon’s company constantly scans public code repositories on GitHub and elsewhere for exposed secrets, automatically notifying account holders of any apparent exposure of sensitive data. Valadon reached out because the account holder was unresponsive and the information exposed was extremely sensitive.
The GitHub repository Valadon pointed out was called “Private-CISA” and contained a huge number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs, and other sensitive CISA data. Valadon noted that the exposed CISA credentials are a classic example of poor security hygiene, noting that commit logs on the problematic GitHub account show that the CISA administrator disabled the default setting on GitHub that prevents users from publishing SSH keys or other secrets to public code repositories.
See also: Grafana GitHub token breach: Code theft and blackmail

One of the exposed files, titled “importantAWStokens,” contained the administrative credentials for three Amazon AWS GovCloud. Another file exposed in the public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — contained plaintext usernames and passwords for dozens of internal CISA systems. According to Philippe Caturegli, founder of security consulting firm Seralys, those systems included one called “LZ-DSO,” which appears to be short for “Landing Zone DevSecOps,” the service’s secure code development environment.
Caturegli tested the AWS keys to see if they were still valid and to determine which internal systems the exposed accounts could access. Caturegli noted that the GitHub account that exposed CISA’s secrets displays a pattern consistent with an individual operator using the repository as a workspace or synchronization mechanism rather than as a curated project repository. He confirmed that the exposed credentials could authenticate three AWS GovCloud accounts at a high privilege level.
The file also contained plaintext credentials for CISA’s internal “artifactory” — essentially a repository of all the code packages they use to build software — representing an attractive target for malicious attackers looking for ways to maintain a persistent presence on CISA’s systems. As Caturegli explained, this would be a prime spot for lateral movement: “Backdoors in some software packages, and every time they build something new they deploy your backdoor left and right.”
See also: EtherRAT pretends to be management tools via fake profiles on GitHub

In response to questions, a CISA spokesperson said the agency is aware of the report, as reported by Krebs on Security , and is continuing to investigate the incident. Organizations should take immediate steps to protect themselves, including revoking and rotating all exposed credentials, implementing secret scanning, and using appropriate secret managers such as AWS Secrets Manager or HashiCorp Vault.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
