Categories: Tech & Ai

US cyber agency CISA exposed reams of passwords and cloud keys to the open web


U.S. cybersecurity agency CISA may have escaped a sizable security breach, thanks to a good-faith security researcher who identified publicly exposed credentials that allowed access to government cloud and internal agency systems.

As first reported by independent security reporter Brian Krebs, GitGuardian security researcher Guillaume Valadon found reams of exposed plaintext credentials listed in spreadsheets, which had been made publicly accessible in a GitHub repository by an employee working for a CISA contractor.

Valadon told Krebs that the exposed credentials were used for accessing systems belonging to CISA and its parent agency, the Department of Homeland Security. Valadon said the credentials included access tokens, cloud keys, and other sensitive files. Valadon told Krebs that he tested some of the keys to verify that they were valid. 

He then reported the lapse to Krebs because the CISA contractor who maintained the GitHub environment did not respond to their alerts.

The security lapse is particularly embarrassing for CISA because the U.S. government agency is responsible for cybersecurity across the civilian federal network. The organization also advises on best cybersecurity practices, which includes storing passwords in secured password managers and not in unprotected spreadsheets.

It’s not clear if anyone found or used the credentials other than Valadon. When reached by TechCrunch, a CISA spokesperson did not immediately comment or say if the agency has any evidence of a breach stemming from this exposure. TechCrunch asked if the agency has revoked and replaced the exposed credentials following the incident.

While the incident was traced back to an employee working for a CISA contractor, CISA is ultimately responsible for the security of its own network and systems, including contractors who work for the agency.

CISA has been without a permanent director since January 20, 2025, when then-CISA director Jen Easterly stepped down ahead of the start of the incoming Trump administration. CISA has also lost about a third of its workforce following cuts, furloughs, and layoffs since Trump took office.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Mark Zuckerberg New META AI Predicts PI Coin Price by End of 2026

55 million people are sitting on Pi Coin right now, unable to fully spend it,…

42 minutes ago

Former OpenAI Staffers Warn That xAI’s Poor Safety Record Could Complicate SpaceX’s IPO

Two former OpenAI employees and a group of AI safety nonprofits are warning that Elon…

51 minutes ago

Bitcoin Prediction Markets Show $84K Ceiling as Traders Stack Bets on Polymarket, Kalshi, and Myriad

Key TakeawaysPolymarket’s bitcoin May price market hit $21.4M in volume, with 79% odds BTC stays…

54 minutes ago

Final Dip Before Pump or a Slide Into Freefall?

"If Bitcoin keeps dropping we may see ADA do the same as well," one…

2 hours ago

Ouinex raises $3.5m from users to back ‘No‑CLOB’ crypto trading model

Crypto exchange Ouinex has raised $3.5m from its own traders, lifting total funding to $9m…

3 hours ago

Anthropic Denies EU Access to Claude Mythos, ChatGPT 5.5 Comes to Rescue

Anthropic still hasn’t granted the EU access to Claude Mythos, but OpenAI’s ChatGPT 5.5-Cyber could…

3 hours ago