Filtered by tag: secret scanning × Clear
Lessons Learned from CISA’s Recent GitHub Leak
CISA released a postmortem after a contractor accidentally exposed dozens of internal credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months. The leak went undetected until KrebsOnSecurity notified the agency. Security experts say the incident highlights critical gaps in credential monitoring and third-party contractor oversight that all security teams should learn from.