Congress Demands Answers as CISA Struggles to Contain Contractor-Linked Data Leak

1 min read
Source: Krebs on Security
TL;DR Summary

Lawmakers from both parties pressed CISA for answers after KrebsOnSecurity reported a contractor publicly posted plaintext credentials and AWS GovCloud keys to a GitHub account, triggering ongoing credential rotation and breach containment. Experts warn that exposed keys could enable access to code, CI/CD pipelines, and sensitive systems. CISA says it is rotating leaked credentials and coordinating with vendors, while lawmakers demand answers about internal policies amid leadership turnover and broader concerns about the agency’s security culture.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

5 min

vs 6 min read

Condensed

93%

1,11976 words

Want the full story? Read the original article

Read on Krebs on Security