telexed ~ c / 6b6c097d-f29radar:40 · infra_saasLIVE
← back
NO.
#6b6c097d
Topic
INFRA & SAAS
Source
GeekNews
Published
2026-05-20 01:10:43
Importance
★ 4/10 — radar 40
CISA Contractor Leaked `AWS GovCloud` Keys on GitHub
FIG-0661:1

CISA Contractor Leaked `AWS GovCloud` Keys on GitHub

A public repo exposed high-privilege cloud and internal credentials. Treat secret scanning as a production control, not a checkbox.

[ KEY POINTS ]
  1. The public Private-CISA repo exposed high-privilege AWS GovCloud credentials, plaintext passwords, tokens, and logs.
  2. Default protections that block secret publishing appear to have been disabled; one bad repo setting can bypass the whole safety net.
  3. Immediate takeaway: enforce secret scanning, pre-commit checks, and key rotation even on private or internal repos.
Originalnews.hada.io/topic?id=29689Read original →

// related