惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
博客园 - 司徒正美
A
About on SuperTechFans
Vercel News
Vercel News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
爱范儿
爱范儿
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
Google DeepMind News
Google DeepMind News
T
Tailwind CSS Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
F
Fortinet All Blogs
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
D
Docker
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence
Jina AI
Jina AI
H
Help Net Security
量子位
IT之家
IT之家

Economic news

News.az - Latest news from Azerbaijan US-Iran naval confrontation in Hormuz looms over failed Islamabad talks | News.az Russia readies first Yak-130M batch to intercept Ukrainian long-range drones | News.az Moscow and Kyiv trade blame over fresh wave of mutual strikes | News.az Nvidia-backed SiFive hits $3.65 billion valuation for open AI chips | News.az BYD sets Guinness Records, previews new EVs at MIAS 2026 | News.az Russian listed by Memorial as political prisoner goes on hunger strike | News.az US gas prices slide 2 cents to $4.14 a gallon | News.az Pilots' union calls strikes at Lufthansa on April 13, 14 | News.az US military says two of its ships transited the Strait of Hormuz | News.az US has agreed to unfreeze Iranian assets | News.az Malaysia warns of supply shortages as global tensions push up costs | News.az China hospital helps stroke patient walk using mind controlled rehab system | News.az How will Barcelona line up against Espanyol? | News.az China successfully launches test satellite for satellite internet technology support | News.az Iraqi parliament elects Nizar Amedi as country's new president | News.az India raises export duties on diesel, aviation turbine fuel | News.az Lebanese PM delays Washington trip | News.az Sources: Iran's new Supreme Leader has disfiguring injuries | News.az Iraq's Parliament convenes to elect new president | News.az Iran denies U.S. vessel crossed Strait of Hormuz | News.az Microsoft halts all carbon removal purchases | News.az BYD to install 6,000 flash chargers globally | News.az Sirens alert of drone attack from Lebanon in Western Galilee | News.az U.S. warships cross Strait of Hormuz for first time since Iran war started | News.az World Bank and IMF to host 2029 Annual Meetings in Abu Dhabi | News.az Pakistani and Iranian delegations meet for talks in Islamabad | News.az Ships sail through Strait of Hormuz as peace talks begin | News.az Israeli air attacks kill 10 in southern Lebanon | News.az US-Iran negotiations for permanent ceasefire start in Islamabad | News.az
Massive Cisa data leak exposes internal systems and AWS k...
2026-05-19 · via Economic news

Massive Cisa data leak exposes internal systems and AWS keys

A redacted screenshot of the now-defunct “Private CISA” repository maintained by a CISA contractor.

The Cybersecurity and Infrastructure Security Agency (CISA) is facing one of the most embarrassing data security blunders in recent government history. A contractor for the federal cyber defense agency accidentally maintained a public GitHub repository that exposed highly privileged AWS GovCloud credentials and access tokens to numerous internal CISA systems.

Security experts discovered the public archive, appropriately titled “Private-CISA,” which contained a treasure trove of sensitive assets including plaintext passwords, cloud keys, logs, and internal blueprints detailing how the agency builds and deploys software. According to GitGuardian researcher Guillaume Valadon, who flagged the issue, the leak represents an egregious failure of basic security hygiene. The contractor’s commit logs even revealed they had explicitly disabled GitHub's default safety feature designed to block users from accidentally publishing secret cryptographic keys, News.Az reports, citing Krebson Security.

Among the exposed files was a document titled “importantAWStokens,” which granted administrative access to three Amazon AWS GovCloud servers, and a spreadsheet containing plaintext usernames and passwords for internal networks. This included credentials for "LZ-DSO," CISA's secure code development environment. Security analysts warned that the repository also exposed passwords to CISA’s internal software package manager, a prime target that hackers could exploit to inject backdoors into government software.

The compromise appears to stem from a Nightwing contractor using the public GitHub repository as a personal scratchpad to sync files between a work laptop and a home computer since November 2025. Compounding the issue, the contractor relied on incredibly weak, easily guessed passwords for critical infrastructure, often using the platform's name followed by the current year.

While the GitHub account was quickly pulled offline after CISA was alerted, investigators noted that the exposed AWS keys shockingly remained active for another 48 hours. CISA, which has seen its workforce shrink by nearly a third following recent administrative budget cuts and forced retirements, stated that it is investigating the incident. The agency claims there is currently no indication that malicious actors compromised any sensitive data before the repository was secured.

News.Az 

By Aysel Mammadzada