惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
月光博客
月光博客
博客园 - 聂微东
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
A
About on SuperTechFans
Microsoft Azure Blog
Microsoft Azure Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
T
Tailwind CSS Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
S
SegmentFault 最新的问题
F
Fortinet All Blogs
H
Help Net Security
J
Java Code Geeks
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 叶小钗
L
LangChain Blog
Martin Fowler
Martin Fowler
N
Netflix TechBlog - Medium

Economic news

News.az - Latest news from Azerbaijan US-Iran naval confrontation in Hormuz looms over failed Islamabad talks | News.az Russia readies first Yak-130M batch to intercept Ukrainian long-range drones | News.az Moscow and Kyiv trade blame over fresh wave of mutual strikes | News.az Nvidia-backed SiFive hits $3.65 billion valuation for open AI chips | News.az BYD sets Guinness Records, previews new EVs at MIAS 2026 | News.az Russian listed by Memorial as political prisoner goes on hunger strike | News.az US gas prices slide 2 cents to $4.14 a gallon | News.az Pilots' union calls strikes at Lufthansa on April 13, 14 | News.az US military says two of its ships transited the Strait of Hormuz | News.az US has agreed to unfreeze Iranian assets | News.az Malaysia warns of supply shortages as global tensions push up costs | News.az China hospital helps stroke patient walk using mind controlled rehab system | News.az How will Barcelona line up against Espanyol? | News.az China successfully launches test satellite for satellite internet technology support | News.az Iraqi parliament elects Nizar Amedi as country's new president | News.az India raises export duties on diesel, aviation turbine fuel | News.az Lebanese PM delays Washington trip | News.az Sources: Iran's new Supreme Leader has disfiguring injuries | News.az Iraq's Parliament convenes to elect new president | News.az Iran denies U.S. vessel crossed Strait of Hormuz | News.az Microsoft halts all carbon removal purchases | News.az BYD to install 6,000 flash chargers globally | News.az Sirens alert of drone attack from Lebanon in Western Galilee | News.az U.S. warships cross Strait of Hormuz for first time since Iran war started | News.az World Bank and IMF to host 2029 Annual Meetings in Abu Dhabi | News.az Pakistani and Iranian delegations meet for talks in Islamabad | News.az Ships sail through Strait of Hormuz as peace talks begin | News.az Israeli air attacks kill 10 in southern Lebanon | News.az US-Iran negotiations for permanent ceasefire start in Islamabad | News.az
Massive Cisa data leak exposes internal systems and AWS k...
2026-05-19 · via Economic news

Massive Cisa data leak exposes internal systems and AWS keys

A redacted screenshot of the now-defunct “Private CISA” repository maintained by a CISA contractor.

The Cybersecurity and Infrastructure Security Agency (CISA) is facing one of the most embarrassing data security blunders in recent government history. A contractor for the federal cyber defense agency accidentally maintained a public GitHub repository that exposed highly privileged AWS GovCloud credentials and access tokens to numerous internal CISA systems.

Security experts discovered the public archive, appropriately titled “Private-CISA,” which contained a treasure trove of sensitive assets including plaintext passwords, cloud keys, logs, and internal blueprints detailing how the agency builds and deploys software. According to GitGuardian researcher Guillaume Valadon, who flagged the issue, the leak represents an egregious failure of basic security hygiene. The contractor’s commit logs even revealed they had explicitly disabled GitHub's default safety feature designed to block users from accidentally publishing secret cryptographic keys, News.Az reports, citing Krebson Security.

Among the exposed files was a document titled “importantAWStokens,” which granted administrative access to three Amazon AWS GovCloud servers, and a spreadsheet containing plaintext usernames and passwords for internal networks. This included credentials for "LZ-DSO," CISA's secure code development environment. Security analysts warned that the repository also exposed passwords to CISA’s internal software package manager, a prime target that hackers could exploit to inject backdoors into government software.

The compromise appears to stem from a Nightwing contractor using the public GitHub repository as a personal scratchpad to sync files between a work laptop and a home computer since November 2025. Compounding the issue, the contractor relied on incredibly weak, easily guessed passwords for critical infrastructure, often using the platform's name followed by the current year.

While the GitHub account was quickly pulled offline after CISA was alerted, investigators noted that the exposed AWS keys shockingly remained active for another 48 hours. CISA, which has seen its workforce shrink by nearly a third following recent administrative budget cuts and forced retirements, stated that it is investigating the incident. The agency claims there is currently no indication that malicious actors compromised any sensitive data before the repository was secured.

News.Az 

By Aysel Mammadzada