GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

A PDF of a letter frm Sen. Hassan to Nick Andersen, the acting director of CISA: I write to request an urgent classified briefing regarding public reporting that a contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained lists of agency accounts and passwords on a public database.1 This reported incident raises serious questions about how such a security lapse could occur at the very agency charged with helping to prevent cyber breaches. According to a recent report from Krebs on Security, this leak included files that detailed how CISA builds, tests, and deploys software internally in a folder called “PrivateCISA.”2 Exposed files reportedly included a file named “importantAWStokens,” with the administrative credentials to three Amazon Web Services (AWS) servers, and one named “AWS-Workspace-Firefox-Passwords.csv,” with plaintext usernames and passwords for multiple internal systems.3 Security experts cited in recent reporting have described this security lapse as “one of the most egregious government data leaks in recent history.”4 This reporting raises serious concerns regarding CISA’s internal policies and procedures at a time of significant cybersecurity threats against U.S. critical infrastructure. 1 Brian Krebs, CISA Admin Leaked AWS GovCloud Keys on Github, Krebs on Security (blog) (May 18, 2026) (krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-ongithub/).

Download link

https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/608/357/179/484/950/original/1acdf7241bf633c1.png

Notices where this attachment appears

  1. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Thursday, 21-May-2026 04:25:04 JST BrianKrebs BrianKrebs

    Check it: Sen. Maggie Hassan (D-NH) is demanding answers from CISA and DHS over my reporting this week that a CISA contractor had published on GitHub a number of CISA AWS GovCloud keys and a ton of plaintext passwords, SSH keys, etc. for internal CISA resources.

    ICYMI:

    https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/

    https://www.hassan.senate.gov/news/press-releases/senator-hassan-presses-for-answers-on-major-reported-data-leak-at-leading-cybersecurity-agency

    #cisa #cybersecurity #databreach

    In conversation about 8 days ago from infosec.exchange permalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.