Lessons Learned from CISA’s Recent GitHub Leak

2026-07-13T19:23:27Z392434862c329db98f12688aabe56bb23d78930b54cf4448868ae76750059541
AI support botAWS GovCloudAlarum TechnologiesCISAFBI seizureGitHubInstagramMetaMicrosoft Patch TuesdayNetNutNetherlands arrests and server seizuresPopa botnetScattered SpiderThe Gentlemenaccount takeovercredentialsdata leakexploit codeinsider risklawmakerspostmortemransomwareresidential proxyvulnerabilitieszero-day

What happened

KrebsOnSecurity coverage from May–July 2026 highlights multiple high-impact security incidents: a CISA contractor accidentally/intentionaly published dozens of internal CISA credentials (including AWS GovCloud keys) on a public GitHub repo for nearly six months, prompting Congressional inquiries and a CISA postmortem; researchers linked the large Android-based “Popa” botnet to NetNut/Alarum Technologies, and the FBI seized hundreds of domains tied to NetNut and the Popa botnet; two alleged Scattered Spider members pleaded guilty for the 2024 Transport for London attack; Microsoft shipped a “re

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
392434862c329db98f12688aabe56bb23d78930b54cf4448868ae76750059541
Enrichment time
2026-07-13T19:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.