Lawmakers Demand Answers as CISA Tries to Contain Data Leak

2026-05-23T19:23:29Z00ed31128f3f9cae2df2d41b362ed3430394a721b3bda409407b90edf3e3e621
awsaws govcloudbotnetcanvas breachcisacredential leakdata extortiondata leakgithub exposureincident responseiotkimwolflawmakers inquirymicrosoft office tokenspatch tuesdayrouter vulnerabilitiesrussian espionagescattered spidervulnerability managementzero-day

What happened

A CISA contractor intentionally published highly privileged AWS GovCloud credentials and numerous internal CISA secrets to a public GitHub repository, prompting lawmakers to demand answers as CISA works to contain the breach and invalidate leaked keys. The exposed archive reportedly included build/test/deploy documentation and other sensitive artifacts, representing a major government data-leak and elevated risk of account takeover, data exfiltration, or supply-chain compromise. Related high-impact stories in the feed include the arrest of the alleged Kimwolf IoT botnet operator, a large-scale

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
00ed31128f3f9cae2df2d41b362ed3430394a721b3bda409407b90edf3e3e621
Enrichment time
2026-05-23T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.