Public GitHub repo exposed CISA secrets, enabling high-privilege access

1 min read
Source: Ars Technica
Public GitHub repo exposed CISA secrets, enabling high-privilege access
Photo: Ars Technica
TL;DR Summary

Security researchers revealed that a public GitHub repo named Private-CISA exposed plaintext passwords, SSH private keys, tokens, and other sensitive CISA assets since at least November 2025, potentially enabling high-privilege access to AWS GovCloud; the repo is now offline and reportedly managed by Nightwing, a CISA contractor, which has not publicly commented, following earlier CISA missteps including a director uploading sensitive docs to ChatGPT.

Share this article

Reading Insights

Total Reads

0

Unique Readers

13

Time Saved

9 min

vs 10 min read

Condensed

97%

1,92864 words

Want the full story? Read the original article

Read on Ars Technica