<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0"
 xmlns:blogChannel="http://backend.userland.com/blogChannelModule"
>

<channel>
<title>Keyword: guillaumevaladon</title>
<link>https://freerepublic.com/tag/guillaumevaladon/</link>
<description></description>
<language>en-us</language>
<lastBuildDate>Wed, 20 May 2026 12:15:42 GMT</lastBuildDate>
<generator>Focus Forum</generator>
<ttl>15</ttl>

<item>
<title>America&#x26;#x27;s top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens &#x26;#x2013; and incredibly obvious filenames</title>
<link>https://freerepublic.com/focus/f-news/4380144/posts</link>
<description>The US Cybersecurity and Infrastructure Security Agency (CISA) left open a GitHub repository named &#x26;#x201C;Private-CISA&#x26;#x201D; containing plain-text passwords, private keys, tokens, and secrets &#x26;#x2013; with obvious file names like &#x26;#x201C;external-secret-repo-creds.yaml&#x26;#x201D; and &#x26;#x201C;AWS-Workspace-Firefox-Passwords.csv&#x26;#x201D; &#x26;#x2013; for six months. GitGuardian researcher Guillaume Valadon, fresh off a recent talk on Kubernetes secret leaks, found the public repository on May 14, and told The Register that he &#x26;#x201C;quickly understood that the leak was bad and that time was running out. A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak...</description>
<author>The Register (UK)</author>
<comments>https://freerepublic.com/focus/f-news/4380144/posts#comment</comments>
<pubDate>Wed, 20 May 2026 12:15:42 GMT</pubDate>
</item>
</channel>
</rss>