CISA GitHub Repo Exposed Sensitive Data, Including Passwords and Keys
نظرة سريعة
- A public GitHub repository named "Private-CISA" exposed sensitive CISA assets like plaintext passwords and SSH keys since at least November 2025.
- The repo, managed by CISA contractor Nightwing, allowed high-level access to AWS GovCloud accounts.
ملخص مُنشأ بالذكاء الاصطناعي
لماذا يهم
A public GitHub repository managed by CISA contractor Nightwing, named "Private-CISA," was found to contain sensitive CISA assets, including plaintext passwords and SSH private keys, since at least November 2025. The repository's default security protections were disabled.
Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025.
The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by GitGuardian’s Guillaume Valadon, who was alerted to the repo’s presence by GitGuardian’s public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo’s owner.
In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator.
Testing by Seralys founder Philippe Caturegli showed that this was not a joke or hoax and that he was able to use the credentials in the Private-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level.”
Krebs notes that the repo appeared to be managed by Virginia-based Nightwing, a CISA contractor. Nightwing has so far not commented publicly, instead referring questions back to CISA.
أسئلة مفتوحة
- How long was the data accessible before detection?
- What specific CISA systems were accessed using the compromised credentials?
- What is the full extent of the damage caused by this breach?
- What disciplinary actions will be taken against Nightwing and responsible CISA personnel?





