news.mlab.sh
Back to the feed
threat-intel

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

High
Image: Krebs on Security
Summary

A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public GitHub repository, posed a serious risk of unauthorized access to CISA systems and potentially provided a roadmap for adversaries like China, Russia, and Iran. While CISA claims no data was compromised, concerns remain regarding internal policies, security culture, and the agency’s ability to manage its contractor support, particularly given recent internal workforce changes.

Read the full article at Krebs on Security

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.