CISA left plaintext passwords and AWS GovCloud admin keys in a public GitHub repo for six months. GitGuardian discovered the 844 MB exposure on May 14, 2026.

Passwords were stored as plain text in a public GitHub repository.

Credenziali GovCloud e password in chiaro: il caso CISA mostra i rischi colossali dei segreti esposti su GitHub.