Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ‘Marshals’ Release Schedule: When the Finale Hits Paramount Plus

    Everyone is navigating AI security in real time — even Google

    Today’s NYT Connections Hints, Answers for May 25 #1079

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • Shop
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    AI News TodayAI News Today
    Home»AI Reviews»Secret CISA credentials found in public GitHub repo
    AI Reviews

    Secret CISA credentials found in public GitHub repo

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A clown in bright clothes holds a laptop above his head.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025.

    The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by GitGuardian’s Guillaume Valadon, who was alerted to the repo’s presence by GitGuardian’s public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo’s owner.

    In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator.

    Testing by Seralys founder Philippe Caturegli showed that this was not a joke or hoax and that he was able to use the credentials in the Private-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level.”

    Krebs notes that the repo appeared to be managed by Virginia-based Nightwing, a CISA contractor. Nightwing has so far not commented publicly, instead referring questions back to CISA.

    This isn’t the first time CISA has screwed up—in fact, it’s not even the first time this year. In January, polygraph-failing acting CISA Director Madhu Gottumukkala uploaded sensitive government documents to ChatGPT after demanding and receiving an exemption to the agency policy that prohibited ChatGPT’s use by CISA personnel. Gottumukkala was removed from his role in February.

    CISA credentials Github public repo secret
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDemis Hassabis said this might be the ‘foothills of the singularity.’ What?
    Next Article From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing
    • Website

    Related Posts

    AI Reviews

    ‘Marshals’ Release Schedule: When the Finale Hits Paramount Plus

    AI Reviews

    Today’s NYT Connections Hints, Answers for May 25 #1079

    AI Reviews

    Inside the World’s Biggest Bet on Fusion Energy

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    ‘Marshals’ Release Schedule: When the Finale Hits Paramount Plus

    0 Views

    Everyone is navigating AI security in real time — even Google

    0 Views

    Today’s NYT Connections Hints, Answers for May 25 #1079

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    ‘Marshals’ Release Schedule: When the Finale Hits Paramount Plus

    0 Views

    Everyone is navigating AI security in real time — even Google

    0 Views

    Today’s NYT Connections Hints, Answers for May 25 #1079

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.