
CISA GitHub Leak Exposed AWS GovCloud Keys for 180 Days Due to Undefined Reporting Channels
CISA's six-month GitHub credential exposure highlights failures in continuous secret monitoring and internal reporting triage. The postmortem reveals playbook gaps for cloud repositories and partner interconnections that delayed key revocation. Agencies handling sensitive data must embed real-time scanning and clear leak channels into contracts and operations.
The exposure originated from a contractor account that uploaded files titled importantAWStokens and AWS-Workspace-Firefox-Passwords.csv containing live credentials. CISA received nine automated alerts from GitGuardian prior to the Krebs notification but failed to act. Key rotation required more than 48 hours once notified, with the agency citing complex interconnections to federal and industry partners as the cause of delay. CISA's postmortem authored by acting CIO Preston Werntz and acting CISO Brad Libbey reveals the agency's incident playbook contained no procedures for GitHub or similar cloud code repositories. External researcher Guillaume Valadon noted that reports routed through the vulnerability disclosure platform landed in product-bug queues rather than infrastructure teams, turning a one-day incident into a 180-day exposure. This incident fits a documented pattern across federal agencies where secrets management remains tied to quarterly scans instead of continuous monitoring of public repositories. Contractual language in CISA's developer agreements evidently lacked mandatory secret-scanning requirements or real-time alerting obligations, allowing the same credential sprawl seen in prior contractor incidents at other DHS components. CISA has since rotated all identified secrets and initiated an action plan for developer secret management plus expanded reporting channels beyond security.txt. Similar exposures are probable in other agencies until procurement clauses mandate continuous scanning and distinct internal-leak triage paths.
CISA: Will publish revised incident response playbook covering cloud repositories and internal-leak triage by December 2026 with measurable reduction in mean time to revoke secrets.
Sources (3)
- [1]KrebsOnSecurity Report(https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/)
- [2]CISA Postmortem Analysis(https://cisa.gov/postmortem-github-leak-2026)
- [3]GitGuardian Notification Review(https://blog.gitguardian.com/cisa-credentials-exposure-2026/)