HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

CISA Contractor Exposes AWS GovCloud Keys and Internal Passwords in Public GitHub Repository

A CISA contractor accidentally published a public GitHub repository containing AWS GovCloud administrative keys and plaintext system passwords, leaving the data exposed for nearly six months. The leak highlights gaps in secret‑management and incident‑response that SOC 2 access‑control controls are built to mitigate.

LiveThreat™ Intelligence · 📅 July 13, 2026· 📰 krebsonsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
krebsonsecurity.com

CISA Contractor Exposes AWS GovCloud Keys and Internal Passwords in Public GitHub Repo

What Happened — A CISA contractor inadvertently published a public GitHub repository containing 844 MB of internal data, including administrative AWS GovCloud keys and plaintext usernames/passwords for dozens of CISA systems. The repository remained exposed for almost six months before GitGuardian alerted CISA on May 15 2026.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic failure of access‑control and secret‑management processes that SOC 2 Trust Services Criteria (CC6.1, CC6.2) are designed to address.
  • Continuous evidence of key‑rotation, secret‑scanning, and incident‑response workflows is essential to demonstrate due diligence during a SOC 2 audit.
  • Verisq’s SOC2 Access Controls capability provides automated monitoring of credential exposure and audit‑ready evidence of remediation actions.

Who Is Affected — Federal government agencies, contractors handling federal data, and any organization that integrates with AWS GovCloud or similar high‑value cloud environments.

Recommended Actions

  • Map secret‑management and key‑rotation procedures to SOC 2 CC6 controls; capture rotation logs as audit evidence.
  • Deploy continuous secret‑scanning across all code repositories and enforce automated revocation of exposed keys.
  • Formalize separate reporting channels for external disclosures versus internal incidents to meet SOC 2 CC7 incident‑response requirements. Source: Krebs on Security

Technical Notes

  • Attack vector: public GitHub repository (misconfiguration / credential leak).
  • Exposed data: AWS GovCloud access keys, CSV of usernames/passwords, other internal configuration files.
  • No known CVEs; the root cause is inadequate secret‑management and delayed key rotation. Source: Krebs on Security
📰 Original Source
https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →