Switch language한국어
Back to the list

CISA Admin Leaked AWS GovCloud Keys on GitHub | Hacker News

TL;DR AI

Key summary

2 min read
  1. A report says a CISA contractor exposed AWS GovCloud keys on GitHub.

  2. A separate CSV reportedly contained plaintext usernames and passwords for dozens of internal CISA systems.

  3. The leak could have given attackers access to sensitive government infrastructure.

  4. It underscores weak secret management and the need for fast notification and credential rotation.

Read the original