Inside CISA’s Six-Month Credential Exposure: Lessons from the Cyber Agency’s Landmark Postmortem
Executive Overview In an unprecedented display of public accountability, the Cybersecurity and Infrastructure Security Agency (CISA)—the United States’ lead federal authority on cybersecurity and critical infrastructure protection—has released a comprehensive postmortem detailing a significant internal security lapse. For nearly six months, an unencrypted public GitHub repository maintained by a third-party contractor exposed administrative credentials, internal…
