// AWSHIGH
CISA disclosed an internal security incident in which AWS GovCloud administrator credentials were exposed in a public GitHub repository maintained by a Nightwing contractor since November 2025. The repository contained Infrastructure as Code, build automation scripts, and plaintext admin credentials for three AWS GovCloud servers and internal CISA systems. Discovery occurred May 15, 2026 via external reporting; forensic analysis found no evidence the leaked credentials were used outside CISA environments, and no customer or mission data was compromised. CISA remediated by taking the repository offline, rotating credentials across all affected environments, and implementing repository upload controls and secrets management safeguards.
- AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber (opens in a new tab)
- CISA details lessons from damaging cloud credential leak — Arabi(opens in a new tab)
- CISA Details “Lessons from a Cyber Incident” After AWS GovCloud(opens in a new tab)
// Get alerts for AWS