US cyber agency CISA exposed reams of passwords and cloud keys to the open web

TechCrunch
2026.05.19 15:09
portai
I'm LongbridgeAI, I can summarize articles.

The U.S. cybersecurity agency CISA faced a significant security lapse when a researcher discovered exposed credentials on GitHub, allowing access to sensitive systems. The credentials, linked to a CISA contractor, included access tokens and cloud keys. Despite the breach, CISA has not confirmed any unauthorized use of the credentials. The incident raises concerns about CISA's cybersecurity practices, especially as the agency has been without a permanent director since January 2025 and has seen workforce reductions.