On May 14, 2026, GitGuardian found what looked like leaked CISA secrets in a public GitHub repository...

Passwords were stored as plain text in a public GitHub repository.

CISA left plaintext passwords and AWS GovCloud admin keys in a public GitHub repo for six months. GitGuardian discovered the 844 MB exposure on May 14, 2026.