Posted on 05/20/2026 5:15:42 AM PDT by Salman
The US Cybersecurity and Infrastructure Security Agency (CISA) left open a GitHub repository named “Private-CISA” containing plain-text passwords, private keys, tokens, and secrets – with obvious file names like “external-secret-repo-creds.yaml” and “AWS-Workspace-Firefox-Passwords.csv” – for six months.
GitGuardian researcher Guillaume Valadon, fresh off a recent talk on Kubernetes secret leaks, found the public repository on May 14, and told The Register that he “quickly understood that the leak was bad and that time was running out. A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak gets.”
Valadon, who previously spent nine years at France’s CISA equivalent, ANSSI, told us the leak included tokens for CISA's internal JFrog Artifactory, Azure registry keys, AWS credentials, Kubernetes manifests, ArgoCD application files, Terraform infrastructure code, GitHub personal access tokens, and Entra ID SAML certificates.
...
(Excerpt) Read more at theregister.com ...
Dear FRiends,
We need your continuing support to keep FR funded. Your donations are our sole source of funding. No sugar daddies, no advertisers, no paid memberships, no commercial sales, no gimmicks, no tax subsidies. No spam, no pop-ups, no ad trackers.
If you enjoy using FR and agree it's a worthwhile endeavor, please consider making a contribution today:
Click here: to donate by Credit Card
Or here: to donate by PayPal
Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794
Thank you very much and God bless you,
Jim
Either way, there need to be prosecutions.
Right.
I was going to say... everyone has a bad day, or makes a blatant mistake, but this just seems way to noobish for someone in that position.
Severely doubt incompetence, someone needs a new one-rope swing!
Or maybe it’s a trap.
In France?
DEI
Seems like a good way to transfer the information to foreign state hackers without leaving clear evidence of wrongdoing and leaving room for a defense of incompetence.
That was my thought too — a sort of cyber honey trap.
Bingo. Planted information to trace who tries to use it. They do that in espionage all the time. Give people certain pieces of decoy information to identify leakers and double agents.
And theses are The folks who deign to grant ME a clearance…
Honeypot. Too delicious to be intentional. Could be sabotage.
That was no accident.
It was deliberate.
Prosecute to the fullest extent of the law.............
Is this the same agency who, the day after the 2020 election, said there was absolutely no fraud involved and it was the most secure election ever?
Top security officers at CISA should be under investigation for treason and removed from office while that investigation goes on.
Why would they not use on-prem Github? If cost, guess what how much did this cost them?
The media blaming Trump & Hegseth in 3..2..1
I’m considering GitHub an untrustworthy platform. Why does the government have so much access to it’s interior files anyway?
That agency has lost over a third of its government employees. This “leak” was caused by a contractor (used a contractor email address) not a Federal Civil Servant.
“Good enuf fer goberment work!”
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.