Skip to content

Incidents

When the Door Is Left Open

A recent law enforcement announcement out of Central Florida carries a headline designed to shock: a former government employee now faces the possibility of spending the rest of her life in prison after allegedly warning a fentanyl trafficking organization about active arrest warrants. The perp walk has happened. The charges have been filed.

But there is a second story here — one that no press conference addressed. And from a Zero Trust perspective, it may be the more important one.

Accidents Happen. Even at CISA.

Last weekend, a security researcher discovered that a CISA contractor had pushed a public GitHub repository containing AWS GovCloud administrative credentials, plaintext passwords for dozens of internal systems, and access to CISA's internal artifact registry. The contractor had also manually disabled GitHub's built-in secret scanning.

Brian Krebs has the full story: CISA Admin Leaked AWS GovCloud Keys on Github →