Data Breaches

US Cybersecurity Agency Contractor Exposes Sensitive AWS Credentials

via RSS: Schneier on Security
US Cybersecurity Agency Contractor Exposes Sensitive AWS Credentials

A contractor working with the US Cybersecurity & Infrastructure Security Agency (CISA) inadvertently exposed privileged AWS GovCloud account credentials through a publicly accessible GitHub repository until recently. The leaked data included internal documentation revealing CISA's software development, testing, and deployment processes across multiple systems. Security researchers have characterized this as one of the most significant government data breaches in recent memory. The exposure compromised highly sensitive infrastructure security information that could potentially be exploited by malicious actors to compromise critical systems. Source: Cybersecurity News.

Read the full story

Original reporting by RSS: Schneier on Security. We only summarise โ€” never republish.

Open source