threat-intel
CISA Exposes Secrets, Credentials in 'Private' Repo
High
Summary
A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infrastructure details. The repository, named "Private-CISA," had been publicly accessible since November 2025, highlighting a concerning trend of government agencies exposing secrets online. CISA swiftly removed the repository after being alerted, but the incident underscores risky practices like storing secrets in Git and disabling security controls.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
