home.social

#cisa — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cisa, aggregated by home.social.

  1. CISA Mandates Patching of Exploited Drupal Vulnerability

    The US Cybersecurity and Infrastructure Security Agency has issued a directive requiring federal agencies to patch a critical Drupal vulnerability, known as CVE-2026-9082, by May 27 to prevent devastating SQL injection attacks. This highly critical flaw allows hackers to exploit PostgreSQL-powered Drupal sites and gain unauthorized access to…

    osintsights.com/cisa-mandates-

    #DrupalVulnerability #Cve20269082 #SqlInjection #PatchManagement #Cisa

  2. 📢 CVE-2026-9082 : Injection SQL dans Drupal JSON:API ajoutée au catalogue KEV de la CISA
    📝 ## 🗓️ Contexte

    Source : CrowdSec VulnTracking, publié le 25 mai 2026.
    📖 cyberveille : cyberveille.ch/posts/2026-05-2
    🌐 source : crowdsec.net/vulntracking-repo?
    #CISA #CMS #Cyberveille

  3. 📰 CISA Contractor Leaks AWS GovCloud Keys and Internal System Credentials on Public GitHub Repo

    ‼️ MAJOR LAPSE: A CISA contractor leaked plaintext AWS GovCloud keys & internal system credentials on a public GitHub repo for months. The incident has sparked a congressional inquiry into the agency's security practices. #CISA #DataBreach #GovCloud

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  4. "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets."

    krebsonsecurity.com/2026/05/la

    #CISA #pwn

  5. "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets."

    krebsonsecurity.com/2026/05/la

    #CISA #pwn

  6. "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets."

    krebsonsecurity.com/2026/05/la

    #CISA #pwn

  7. "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets."

    krebsonsecurity.com/2026/05/la

    #CISA #pwn

  8. "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets."

    krebsonsecurity.com/2026/05/la

    #CISA #pwn

  9. CISA exposed plaintext passwords, cloud keys, and access tokens in a public GitHub repository tied to a government contractor account. 🔓
    A researcher confirmed some credentials were valid, raising concerns over federal cloud security and contractor oversight at the US cyber agency. ☁️

    🔗 techcrunch.com/2026/05/19/us-c

    #TechNews #CISA #Cybersecurity #GitHub #CloudSecurity #Passwords #Infosec #Privacy #Security #DataBreach #OpenSource #GovTech #Cloud #USA #US #Tech #Government #Federal

  10. CISA exposed plaintext passwords, cloud keys, and access tokens in a public GitHub repository tied to a government contractor account. 🔓
    A researcher confirmed some credentials were valid, raising concerns over federal cloud security and contractor oversight at the US cyber agency. ☁️

    🔗 techcrunch.com/2026/05/19/us-c

    #TechNews #CISA #Cybersecurity #GitHub #CloudSecurity #Passwords #Infosec #Privacy #Security #DataBreach #OpenSource #GovTech #Cloud #USA #US #Tech #Government #Federal

  11. CISA exposed plaintext passwords, cloud keys, and access tokens in a public GitHub repository tied to a government contractor account. 🔓
    A researcher confirmed some credentials were valid, raising concerns over federal cloud security and contractor oversight at the US cyber agency. ☁️

    🔗 techcrunch.com/2026/05/19/us-c

    #TechNews #CISA #Cybersecurity #GitHub #CloudSecurity #Passwords #Infosec #Privacy #Security #DataBreach #OpenSource #GovTech #Cloud #USA #US #Tech #Government #Federal

  12. CISA exposed plaintext passwords, cloud keys, and access tokens in a public GitHub repository tied to a government contractor account. 🔓
    A researcher confirmed some credentials were valid, raising concerns over federal cloud security and contractor oversight at the US cyber agency. ☁️

    🔗 techcrunch.com/2026/05/19/us-c

    #TechNews #CISA #Cybersecurity #GitHub #CloudSecurity #Passwords #Infosec #Privacy #Security #DataBreach #OpenSource #GovTech #Cloud #USA #US #Tech #Government #Federal

  13. CISA exposed plaintext passwords, cloud keys, and access tokens in a public GitHub repository tied to a government contractor account. 🔓
    A researcher confirmed some credentials were valid, raising concerns over federal cloud security and contractor oversight at the US cyber agency. ☁️

    🔗 techcrunch.com/2026/05/19/us-c

    #TechNews #CISA #Cybersecurity #GitHub #CloudSecurity #Passwords #Infosec #Privacy #Security #DataBreach #OpenSource #GovTech #Cloud #USA #US #Tech #Government #Federal

  14. CISA Faces Scrutiny Over Leaked Credentials

    The US Cybersecurity and Infrastructure Security Agency (CISA) is under fire after dozens of its internal credentials were accidentally exposed on a public GitHub account, sparking concerns over potential security breaches. Despite the agency's assurance that no sensitive data was compromised, lawmakers and experts are demanding answers on how this incident…

    osintsights.com/cisa-faces-scr

    #Cisa #CredentialLeak #Github #EmergingThreats #GovernmentAgencies

  15. مُفاجأة أمنية: وكالة CISA علنت عن تسريب بيانات اعتماد AWS GovCloud داخل مستودع على GitHub عام.
    ⚠️ الخبر يوضح كيف يمكن للخطأ البشري أن يفضح معلومات حساسة مخصصة للجهات الحكومية. 🔐 ضرورة مراجعة الصلاحيات وإغلاق الوصول غير الضروري.
    #CISA #AWS #GitHub #الأمن_السبرانتي #خصوصية_البيانات

    🔗 news.google.com/rss/articles/C

  16. "CISA Admin Leaked AWS GovCloud Keys on Github
    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

    The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

    Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories."

    krebsonsecurity.com/2026/05/ci

    #CyberSecurity #CISA #GitHub #AWS #CloudComputing #DHS #GovCloud

  17. "CISA Admin Leaked AWS GovCloud Keys on Github
    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

    The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

    Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories."

    krebsonsecurity.com/2026/05/ci

    #CyberSecurity #CISA #GitHub #AWS #CloudComputing #DHS #GovCloud

  18. "CISA Admin Leaked AWS GovCloud Keys on Github
    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

    The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

    Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories."

    krebsonsecurity.com/2026/05/ci

    #CyberSecurity #CISA #GitHub #AWS #CloudComputing #DHS #GovCloud

  19. "CISA Admin Leaked AWS GovCloud Keys on Github
    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

    The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

    Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories."

    krebsonsecurity.com/2026/05/ci

    #CyberSecurity #CISA #GitHub #AWS #CloudComputing #DHS #GovCloud

  20. "CISA Admin Leaked AWS GovCloud Keys on Github
    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

    The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

    Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories."

    krebsonsecurity.com/2026/05/ci

    #CyberSecurity #CISA #GitHub #AWS #CloudComputing #DHS #GovCloud

  21. 🤦‍♂️ Ah, the classic government strategy: wait for a massive #data #breach and then demand answers in a bewildered frenzy. Meanwhile, CISA's strategy of posting sensitive keys on a public GitHub is a bold new frontier in cloud storage solutions. 🚀🌐
    krebsonsecurity.com/2026/05/la #governmentstrategy #CISA #cloudstorage #cybersecurity #HackerNews #ngated

  22. 🤦‍♂️ Ah, the classic government strategy: wait for a massive #data #breach and then demand answers in a bewildered frenzy. Meanwhile, CISA's strategy of posting sensitive keys on a public GitHub is a bold new frontier in cloud storage solutions. 🚀🌐
    krebsonsecurity.com/2026/05/la #governmentstrategy #CISA #cloudstorage #cybersecurity #HackerNews #ngated

  23. 🤦‍♂️ Ah, the classic government strategy: wait for a massive #data #breach and then demand answers in a bewildered frenzy. Meanwhile, CISA's strategy of posting sensitive keys on a public GitHub is a bold new frontier in cloud storage solutions. 🚀🌐
    krebsonsecurity.com/2026/05/la #governmentstrategy #CISA #cloudstorage #cybersecurity #HackerNews #ngated

  24. 🤦‍♂️ Ah, the classic government strategy: wait for a massive #data #breach and then demand answers in a bewildered frenzy. Meanwhile, CISA's strategy of posting sensitive keys on a public GitHub is a bold new frontier in cloud storage solutions. 🚀🌐
    krebsonsecurity.com/2026/05/la #governmentstrategy #CISA #cloudstorage #cybersecurity #HackerNews #ngated

  25. 🤦‍♂️ Ah, the classic government strategy: wait for a massive #data #breach and then demand answers in a bewildered frenzy. Meanwhile, CISA's strategy of posting sensitive keys on a public GitHub is a bold new frontier in cloud storage solutions. 🚀🌐
    krebsonsecurity.com/2026/05/la #governmentstrategy #CISA #cloudstorage #cybersecurity #HackerNews #ngated

  26. CISA Opens KEV Nominations to Bolster Vulnerability Intelligence

    CISA is now accepting nominations for its Known Exploited Vulnerabilities catalog, empowering public reporting to strengthen the nation's cybersecurity posture by quickly identifying and mitigating exploited vulnerabilities. By submitting through the new KEV nomination form, you're helping to keep federal,…

    osintsights.com/cisa-opens-kev

    #VulnerabilityDisclosure #KnownExploitedVulnerabilities #Kev #Cisa #VulnerabilityIntelligence