Independent journalist Brian Krebs reported Monday that researchers found a publicly accessible GitHub repository connected to a government contractor that exposed CISA data.

SSH keys, plaintext passwords, other sensitive data had been up since November 2025.

Researchers uncovered an exposed GitHub repository that included internal credentials and files.