Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Trapdoor Android ad fraud scheme reaches 659 million bid requests per day using 455 apps

OpenAI co-founder Andrej Karpathy joins Anthropic’s pre-training team

US cyber agency CISA releases tons of passwords and cloud keys to the open web

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » US cyber agency CISA releases tons of passwords and cloud keys to the open web
Startups

US cyber agency CISA releases tons of passwords and cloud keys to the open web

By May 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

US cybersecurity agency CISA may have been spared a major security breach thanks to an honest security researcher who identified publicly exposed credentials that allowed access to government clouds and internal agency systems.

As first reported by independent security reporter Brian Krebs, GitGuardian security researcher Guillaume Valadon found a large amount of plaintext credentials listed in a spreadsheet exposed. These credentials had been published publicly in a GitHub repository by an employee working for a CISA contractor.

Valadon told Krebs that the compromised credentials were used to access systems belonging to CISA and its parent agency, the Department of Homeland Security. Valadon said the credentials included access tokens, cloud keys and other sensitive files. Mr. Valadon told Mr. Krebs that he had tested some of the keys and confirmed that they were valid.

The CISA contractor maintaining the GitHub environment then reported the revocation to Krebs after failing to respond to the alert.

The security blunder is especially embarrassing for CISA because the U.S. government agency is responsible for cybersecurity across civilian federal networks. The organization also advises on cybersecurity best practices, such as storing passwords in a secure password manager rather than in an unprotected spreadsheet.

It is not clear if anyone other than Valadon found or used this credential. In a statement to TechCrunch, CISA spokesperson Marco Di Sandro said the agency is “aware of the reported disclosure and continues to investigate the situation,” adding: “There is no indication that sensitive data was compromised as a result of this incident.”

CISA did not say whether the agency had seen evidence of a breach resulting from this disclosure. TechCrunch asked if authorities had revoked and replaced the exposed credentials following the incident.

Although this incident traces back to employees working for CISA contractors, CISA is ultimately responsible for the security of its own networks and systems, including those of contractors working for CISA.

CISA has been without a permanent director since then-CISA Director Jen Easterly resigned on January 20, 2025, ahead of the inauguration of the next Trump administration. CISA has also lost about a third of its workforce due to layoffs, furloughs, and layoffs since President Trump took office.

Updated with comment from CISA.

If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.


Source link

#Aceleradoras #CapitalRiesgo #EcosistemaStartup #Emprendimiento #InnovaciónEmpresarial #Startups
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDirtyDecrypt PoC released for Linux kernel CVE-2026-31635 LPE vulnerability
Next Article OpenAI co-founder Andrej Karpathy joins Anthropic’s pre-training team

Related Posts

OpenAI co-founder Andrej Karpathy joins Anthropic’s pre-training team

May 19, 2026

Forget about feeds: Status AI raises $17M to turn social media into interactive entertainment

May 19, 2026

Theo Baker spent four years researching Stanford. Before he left, this is what he found.

May 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Trapdoor Android ad fraud scheme reaches 659 million bid requests per day using 455 apps

OpenAI co-founder Andrej Karpathy joins Anthropic’s pre-training team

US cyber agency CISA releases tons of passwords and cloud keys to the open web

DirtyDecrypt PoC released for Linux kernel CVE-2026-31635 LPE vulnerability

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.