Anatomy of a Federal Secret Leak: CISA Postmortem Exposes Six-Month Credentials Slip on GitHub and Lessons for Cyber Defense
Executive Overview In an unprecedented display of public transparency, the Cybersecurity and Infrastructure Security Agency (CISA) has published an unvarnished postmortem detailing a significant internal security breach. The incident involved an agency contractor who inadvertently published a public GitHub repository containing sensitive enterprise data, administrative credentials, and cloud access keys. The repository remained publicly accessible…
