In a stunning display of stupidity, secret CISA credentials found in public GitHub repo

TL;DR AI
2 min readKey summary
Researchers found a public GitHub repository linked to CISA that exposed plaintext passwords, SSH private keys, tokens, and other sensitive assets.
The repo reportedly had secret-scanning protections disabled, and testing suggested the credentials could access multiple AWS GovCloud accounts.
The repository was later taken offline and was reportedly associated with CISA contractor Nightwing.
The exposure raises concerns about possible unauthorized access to government and cloud systems, and about contractor security practices at a U.S. cybersecurity agency.
