Lessons Learned from CISA’s Recent GitHub Leak
A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The agency’s slow response highlighted critical gaps in its incident response procedures, particularly regarding external notifications and continuous monitoring of public code repositories. CISA has since taken steps to improve its reporting channels and enhance its secret management practices, emphasizing the need for proactive scanning and simplified communication with security researchers.
A CISA contractor published a public GitHub repository containing 844 MB of sensitive CISA-related data, including AWS GovCloud keys and plaintext usernames and passwords for dozens of internal CISA systems, for nearly six months before the agency was alerted. The repository, dubbed “Private CISA,” was discovered by Guillaume Valadon, a researcher with GitGuardian, who noted that CISA ignored nine automated alerts about the exposed credentials. CISA quickly acknowledged the breach and invalidated the AWS keys, but took over 48 hours to fully address the situation.
CISA’s postmortem attributed the delay to the complexity of its systems and its reliance on federal and industry partners. It emphasized the need for clearer and more distinct reporting channels to ensure timely responses to incidents involving the agency itself, rather than just its products or customers. The report also highlighted the importance of continuous scanning of public code repositories like GitHub for exposed secrets – a practice that could have identified the “Private CISA” repository much earlier.
Despite acknowledging shortcomings, CISA gave itself passing grades on several areas of security preparedness, including enhanced logging capabilities and the adoption of zero-trust principles. These detailed logs demonstrated that no customer or mission data was exposed, and that the leaked credentials were not used outside of CISA’s environments. The contractor who exposed the secrets had their system access revoked.
CISA is now refining its reporting channels to make them easier and faster for researchers. It also plans to publish reporting instructions in multiple prominent locations, mirroring the security.txt file. The agency’s postmortem is notable as the first time a national cybersecurity agency has publicly advocated for secrets scanning and for simplifying relations with security researchers.
