The Cybersecurity and Infrastructure Security Agency (CISA), the very body tasked with defending national networks, left a sensitive GitHub repository publicly accessible for six months. Discovered by security researcher Guillaume Valadon, the repository contained critical secrets including plaintext passwords, private keys, and authentication tokens that were fully visible to anyone on the web.
After being alerted on May 14, the agency moved quickly to revoke access the following day. Despite the swift remediation upon discovery, the incident highlights a massive security oversight within an organization that promotes cyber hygiene and strict credential management. The leak exposed internal configurations that could have served as a roadmap for malicious actors to penetrate government systems.


