Industry News

CISA's GitHub Credential Leak: A Wake-Up Call for Secure Code Practices

Krebs on Security · 14 July 2026
Key Takeaway Regularly scan any code repositories your business or contractors use for exposed passwords, API keys, or access tokens, and revoke credentials immediately if a leak is found.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published a postmortem after a contractor inadvertently published dozens of internal credentials, including AWS Govcloud keys, in a publicly accessible GitHub repository. The exposure went unnoticed by the agency for nearly six months until it was reported by security journalist Brian Krebs.

The incident highlights a common but serious risk: developers and contractors accidentally committing sensitive credentials into code repositories, sometimes leaving them exposed for long periods without detection. Even well-resourced organisations with mature security programs can fall victim to this kind of oversight, underscoring that credential leaks are as much a process and monitoring problem as a technical one.

Security experts reviewing CISA's response say the case offers valuable lessons for organisations of all sizes: the need for automated scanning of code repositories for secrets, strict policies around what contractors can publish publicly, and faster incident response once exposures are identified. For small and medium businesses, the takeaway is not that this specific breach affects them directly, but that similar risks exist any time code, scripts, or configuration files are stored in shared or public repositories.

data leak credential exposure GitHub security cloud security incident response

Summarised by CISO AI from Krebs on Security. We link back to every original so you can read it yourself.