CISA Exposed Its Own Cloud Storage Credentials in Plain Text on Public GitHub Repository
By
neogodless
12d ago· 4 min readenNews
85/100
Golden Brown
Bagelometer↗
Fresh out the oven, still warm. Top of the tray.
Score85TypenewsSentimentvery negative
Summary
CISA, the U.S. Cybersecurity and Infrastructure Security Agency, left its own cloud storage digital keys (passwords) exposed in plain text on a public GitHub repository named "Private-CISA" for an unknown period of time. The security lapse was reported by Krebs on Security and was finally fixed over the weekend. The incident is described as one of the worst security leaks witnessed, highlighting a major irony given CISA's mission to protect U.S. cybersecurity.
Key quotes
· 3 pulled'The Worst Leak That I've Witnessed': U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
The repository was reportedly named 'Private-CISA.'
The problem finally got fixed over the weekend, the report says.
Passwords were stored as plain text in a public GitHub repository.
