Switch language한국어
Back to the list

U.S. cybersecurity agency leaks GovCloud keys on GitHub

TL;DR AI

Key summary

2 min read
  1. CISA is investigating a public GitHub leak from a contractor-managed repository that exposed AWS GovCloud keys, plaintext passwords, and internal DevSecOps files.

  2. Security researchers said some of the exposed keys were valid and could have granted high-privilege access to sensitive systems.

  3. CISA says it has found no evidence of misuse so far, but the exposure could have enabled malware insertion or broader compromise of U.S. government cloud infrastructure.

Read the original