The reported exposure of AWS GovCloud keys and internal CISA credentials on a public GitHub repository is a stark reminder that secret management failures can undermine even the most security-focused organizations. According to the report, the repository exposed highly privileged AWS GovCloud credentials, plaintext passwords, tokens, logs, and internal build/deployment material, including access related to CISA’s DevSecOps and artifact systems. That kind of exposure is not just a credential leak; it can create risks around lateral movement, software supply-chain compromise, and long-term persistence.

This incident reinforces the need for strict controls around developer workflows: secret scanning must remain enforced, long-lived cloud keys should be replaced with short-lived role-based access, plaintext password storage must be eliminated, and public repositories should be continuously monitored for accidental exposure. The report also notes that the exposed AWS keys remained valid for around 48 hours after notification, which highlights why incident response speed matters as much as detection. Security agencies, contractors, and enterprises alike should treat GitHub, CI/CD, and cloud credentials as high-risk assets, because apparently even “Private-CISA” can become public when process controls lose a fight with human convenience.


Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

Source: CISA Admin Leaked AWS GovCloud Keys on Github via KrebsOnSecurity — published 18 May 2026.