Cloud keys and system details leaked in a public GitHub repository
A CISA contractor accidentally exposed highly sensitive AWS GovCloud credentials and internal government system details in a public GitHub repository. The leak included cloud access keys, passwords and deployment information that could potentially have given attackers deep access to government infrastructure.
Researchers called it one of the most serious U.S. government credential leaks in recent years, particularly because GitHub's secret-scanning protections had been disabled. The incident highlights weaknesses in cloud security and credential management practices.
What this means for your business
What makes this case uncomfortable is not that someone made a mistake, but that the safety net had been switched off. Secret scanning is the control that catches the human error everyone knows will happen eventually. For your organisation this raises the question of who can disable a security control, and whether anyone finds out when they do. That applies to contractors exactly as it does to employees.
Berigo recommends
- Verify that secret scanning is enabled across all organisational repositories and cannot be turned off by an individual developer.
- Replace static cloud keys with short-lived federated identities wherever possible.
- Apply the same requirements to contractors as to employees, and write them into the consultancy agreement.
- Establish a rehearsed procedure for rapid rotation of cloud credentials, and measure how long it actually takes.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch