Thursday , June 18 2026

CISA Admin Leaked AWS GovCloud Keys on Github Repository

One of the most egregious government data leaks in recent history might be the recent leak of Cybersecurity & Infrastructure Security Agency (CISA) public GitHub repository maintained by a contractor that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.

Security experts said the public archive had files about how CISA makes, tests, and uses software inside the organization.

FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries....
Read More
FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

New Rokarolla Android malware hits 217 banking and crypto apps

A new Android banking trojan called Rokarolla is hitting 217 banking and cryptocurrency apps with a wide range of 137...
Read More
New Rokarolla Android malware hits 217 banking and crypto apps

Phishing Campaign Exploits Legitimate Microsoft Login Flow

Attackers are using Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow in a campaign to take control of Microsoft...
Read More
Phishing Campaign Exploits Legitimate Microsoft Login Flow

ALERT
Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

Cisco on Monday told customers about a new SD-WAN product flaw used in attacks. The flaw, called CVE-2026-20262, is a...
Read More
ALERT  Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

“Panthalassa” builds floating AI data centers powered by ocean waves

Every American data center story these days follows almost the same pattern. Someone has the chips, someone has the cash,...
Read More
“Panthalassa” builds floating AI data centers powered by ocean waves

Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

A critical security flaw has affected the open-source security community. Recently, complete details and working exploit code were shared online....
Read More
Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

CVE-2026-0257
Palo Alto Warns of GlobalProtect VPN Vuln Actively Exploited

Palo Alto Networks Unit 42 has given an urgent alert about the active use of CVE-2026-0257. This is a serious...
Read More
CVE-2026-0257  Palo Alto Warns of GlobalProtect VPN Vuln Actively Exploited

BD Gov.t to set up Tk192.66cr AI hub with support from Koica

Bangladesh plans to spend Tk192.66 crore to make a national hub for artificial intelligence (AI) to train new AI experts....
Read More
BD Gov.t to set up Tk192.66cr AI hub with support from Koica

Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases With Zero Authentication

A serious pre-authentication remote code execution (RCE) flaw in Splunk Enterprise has been revealed, earning a very high CVSS score...
Read More
Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases With Zero Authentication

Anthropic disables Fable 5 and Mythos 5 Access after US order limiting foreign access

Anthropic said on Friday it will quickly turn off its best AI models for everyone. This comes after the U.S....
Read More
Anthropic disables Fable 5 and Mythos 5 Access after US order limiting foreign access

On May 15, KrebsOnSecurity got a message from Guillaume Valadon, a researcher at GitGuardian. His company always checks public code sites like GitHub for exposed secrets and alerts the accounts if they find sensitive data. Valadon contacted KrebsOnSecurity because the owner wasn’t replying and the exposed information was very sensitive.

The “Private-CISA” repository was open to the public until mid-May 2026. It held a lot of sensitive information like AWS GovCloud login info, plain passwords, API keys, and internal system details.

                           screenshot of the deleted “Private CISA” GitHub repository( source :krebsonsecurity)

A file called “AWS-Workspace-Firefox-Passwords.csv” showed many usernames and passwords in plain text linked to CISA systems. This includes a DevSecOps area known as “LZ-DSO.”

Philippe Caturegli, founder of security consultancy Seralys said, some of the exposed AWS credentials were still valid at the time of discovery and provided high-level access. He noted that the repository also contained credentials for CISA’s internal “artifactory,” a centralized system for storing and distributing software components.

This type of access could allow attackers to insert malicious code into software pipelines.

KrebsOnSecurity said that the exposed data was connected to a contractor from Nightwing, a government services company in the U.S. The account had been open since 2018, and the “Private-CISA” folder was set up in November 2025.

CISA acknowledged saying that:

“Currently, there is no indication that any sensitive data was compromised as a result of this incident[…] While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”

Check Also

coupang

South Korea fines Coupang Record $409 mln fine for data leak

South Korea’s privacy regulator said on Thursday (June 11) that the country will fine e-commerce …