Tag Archives: krebsonsecurity

In stunning display of stupid, secret CISA credentials found in public GitHub repo

Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025. The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by… Read More »