Lessons Learned from CISA’s Recent GitHub Leak
2026-07-14T19:23:35Z•440cbc479a3aaab6da2d1a432f32e59c014721434505adcd63462d9699b8d1d1
AI-support-botAWS GovCloudAlarum TechnologiesCISAFBIGitHubInstagramMetaMicrosoft Patch TuesdayNetNutNetherlands takedownPopa botnetScattered SpiderThe Gentlemenaccount-takeoveradvertising-fraudbotnetcongressional-inquirycredential-leakdata-scrapingexploit-codeincident-responseransomwareresidential-proxyzero-day
What happened
A series of high-impact security incidents and research findings: CISA issued a postmortem after a contractor accidentally published dozens of internal credentials (including AWS GovCloud keys) on a public GitHub repo for nearly six months, prompting congressional inquiries and lessons about credential hygiene and incident response. The FBI seized hundreds of domains tied to NetNut (Alarum Technologies) after research linked the Popa Android-based botnet (millions of devices) to the company; Popa has been used for advertising fraud, account takeovers and large-scale data scraping. Microsoft’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 440cbc479a3aaab6da2d1a432f32e59c014721434505adcd63462d9699b8d1d1
- Enrichment time
- 2026-07-14T19:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.