U.S. cybersecurity agency leaks GovCloud keys on GitHub

TL;DR AI
2 min readKey summary
CISA is investigating a public GitHub leak from a contractor-managed repository that exposed AWS GovCloud keys, plaintext passwords, and internal DevSecOps files.
Security researchers said some of the exposed keys were valid and could have granted high-privilege access to sensitive systems.
CISA says it has found no evidence of misuse so far, but the exposure could have enabled malware insertion or broader compromise of U.S. government cloud infrastructure.
