Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Legacy of the Dark Knight release in your time zone?

    May 20, 2026

    20 Years Later, Grey’s Anatomy Is Still Expanding — But Should It Be?

    May 20, 2026

    Volkswagen Golf GTI Edition 50: No birthday party for iconic hot hatch nameplate in Australia

    May 20, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Secret CISA credentials found in public GitHub repo
    Secret CISA credentials found in public GitHub repo
    Tech Reviews

    Secret CISA credentials found in public GitHub repo

    gvfx00@gmail.comBy gvfx00@gmail.comMay 20, 2026No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025.

    The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by GitGuardian’s Guillaume Valadon, who was alerted to the repo’s presence by GitGuardian’s public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo’s owner.

    In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator.

    Testing by Seralys founder Philippe Caturegli showed that this was not a joke or hoax and that he was able to use the credentials in the Private-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level.”

    Krebs notes that the repo appeared to be managed by Virginia-based Nightwing, a CISA contractor. Nightwing has so far not commented publicly, instead referring questions back to CISA.

    This isn’t the first time CISA has screwed up—in fact, it’s not even the first time this year. In January, polygraph-failing acting CISA Director Madhu Gottumukkala uploaded sensitive government documents to ChatGPT after demanding and receiving an exemption to the agency policy that prohibited ChatGPT’s use by CISA personnel. Gottumukkala was removed from his role in February.

    Table of Contents

    Toggle
      • Related posts:
    • Artificial Intelligence, Explained: The AI Novelty and How It Might Spell Our Doom
    • Want to Avoid Microplastics in Food? We Found the 8 Most Common Foods That Contain Microplastics
    • How to watch London Marathon 2026: Free Streams & TV Channels

    Related posts:

    The Spaceballs sequel will be released in April next year

    Nvidia's $100 billion OpenAI deal has seemingly vanished

    Apple is reportedly looking into 3D printing aluminum iPhones and Apple Watches

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleStar Wars Jedi Veteran's Dungeons & Dragons Game Has Been Canceled
    Next Article Automating Browsers with Local AI Agents
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Everything Announced At Google I/O 2026

    May 19, 2026
    Tech Reviews

    How to Watch Google I/O 2026 and What to Expect

    May 19, 2026
    Tech Reviews

    Meta to receive over $3 billion in tax breaks for its 2,250 acre Louisiana data center – enough to fund the state’s police budget for seven years

    May 19, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025159 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 202597 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202582 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025159 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 202597 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202582 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.