Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
The Register (UK) ^ | 19 May 2026 | Jessica Lyons

Posted on 05/20/2026 5:15:42 AM PDT by Salman

The US Cybersecurity and Infrastructure Security Agency (CISA) left open a GitHub repository named “Private-CISA” containing plain-text passwords, private keys, tokens, and secrets – with obvious file names like “external-secret-repo-creds.yaml” and “AWS-Workspace-Firefox-Passwords.csv” – for six months.

GitGuardian researcher Guillaume Valadon, fresh off a recent talk on Kubernetes secret leaks, found the public repository on May 14, and told The Register that he “quickly understood that the leak was bad and that time was running out. A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak gets.”

Valadon, who previously spent nine years at France’s CISA equivalent, ANSSI, told us the leak included tokens for CISA's internal JFrog Artifactory, Azure registry keys, AWS credentials, Kubernetes manifests, ArgoCD application files, Terraform infrastructure code, GitHub personal access tokens, and Entra ID SAML certificates.

...

(Excerpt) Read more at theregister.com ...


TOPICS: Crime/Corruption; Government; News/Current Events; United Kingdom
KEYWORDS: anssi; argocd; artifactory; aws; azure; cisa; corruption; cybersecurity; entraidsaml; france; gitguardian; github; guillaumevaladon; internet; jessicalyons; jfrog; kubernetes; linux; terraform; unitedkingdom; windows
Message from Jim Robinson:

Dear FRiends,

We need your continuing support to keep FR funded. Your donations are our sole source of funding. No sugar daddies, no advertisers, no paid memberships, no commercial sales, no gimmicks, no tax subsidies. No spam, no pop-ups, no ad trackers.

If you enjoy using FR and agree it's a worthwhile endeavor, please consider making a contribution today:

Click here: to donate by Credit Card

Or here: to donate by PayPal

Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794

Thank you very much and God bless you,

Jim


Navigation: use the links below to view more comments.
first 1-2021 next last
Could be incompetence, could be deliberate sabotage.

Either way, there need to be prosecutions.

1 posted on 05/20/2026 5:15:42 AM PDT by Salman
[ Post Reply | Private Reply | View Replies]

To: Salman

Right.
I was going to say... everyone has a bad day, or makes a blatant mistake, but this just seems way to noobish for someone in that position.


2 posted on 05/20/2026 5:25:02 AM PDT by z3n (Kakistocracy)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

Severely doubt incompetence, someone needs a new one-rope swing!


3 posted on 05/20/2026 5:25:46 AM PDT by Aevery_Freeman (Islam extends a beggar's palm - whilst hiding the bloody fist! ~ a Minnesotan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

Or maybe it’s a trap.


4 posted on 05/20/2026 5:26:33 AM PDT by omni-scientist
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman
internal JFrog

In France?

5 posted on 05/20/2026 5:35:14 AM PDT by Libloather (Why do climate change hoax deniers live in mansions on the beach?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

DEI


6 posted on 05/20/2026 5:41:29 AM PDT by nwrep
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

Seems like a good way to transfer the information to foreign state hackers without leaving clear evidence of wrongdoing and leaving room for a defense of incompetence.


7 posted on 05/20/2026 5:48:17 AM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: omni-scientist

That was my thought too — a sort of cyber honey trap.


8 posted on 05/20/2026 5:52:19 AM PDT by Blurb2350 (posted from my 1500-watt blow dryer)
[ Post Reply | Private Reply | To 4 | View Replies]

To: omni-scientist

Bingo. Planted information to trace who tries to use it. They do that in espionage all the time. Give people certain pieces of decoy information to identify leakers and double agents.


9 posted on 05/20/2026 6:20:40 AM PDT by Codeflier (Don't worry....be happy)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Salman

And theses are The folks who deign to grant ME a clearance…


10 posted on 05/20/2026 6:26:02 AM PDT by jagusafr ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: omni-scientist

Honeypot. Too delicious to be intentional. Could be sabotage.


11 posted on 05/20/2026 6:30:46 AM PDT by paulcissa (The left hates you and wants you dead.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: paulcissa
Too delicious to be intentional a mistake.
12 posted on 05/20/2026 6:32:33 AM PDT by paulcissa (The left hates you and wants you dead.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Salman

That was no accident.

It was deliberate.

Prosecute to the fullest extent of the law.............


13 posted on 05/20/2026 6:43:56 AM PDT by Red Badger (Iryna Zarutska, May 22, 2002 Kyiv, Ukraine – August 22, 2025 Charlotte, North Carolina Say her name)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

Is this the same agency who, the day after the 2020 election, said there was absolutely no fraud involved and it was the most secure election ever?


14 posted on 05/20/2026 7:00:30 AM PDT by CFW
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

Top security officers at CISA should be under investigation for treason and removed from office while that investigation goes on.


15 posted on 05/20/2026 7:02:28 AM PDT by Wuli (ui)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

Why would they not use on-prem Github? If cost, guess what how much did this cost them?


16 posted on 05/20/2026 7:05:20 AM PDT by pas
[ Post Reply | Private Reply | To 1 | View Replies]

To: z3n

The media blaming Trump & Hegseth in 3..2..1


17 posted on 05/20/2026 7:08:34 AM PDT by unixfox (Abolish Slavery, Repeal the 16th Amendment)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Salman; dayglored; ShadowAce

I’m considering GitHub an untrustworthy platform. Why does the government have so much access to it’s interior files anyway?


18 posted on 05/20/2026 8:02:12 AM PDT by MikelTackNailer (she blinded me with science. And pheromones. And femininity. And...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

That agency has lost over a third of its government employees. This “leak” was caused by a contractor (used a contractor email address) not a Federal Civil Servant.


19 posted on 05/20/2026 8:13:31 AM PDT by XRdsRev (Justice for Bernell Trammell, black Trump supporter, executed in the street in broad daylight 2020.a)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salman

“Good enuf fer goberment work!”


20 posted on 05/20/2026 10:04:06 AM PDT by Uncle Lonny
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson