CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-19T13:23:29Z•5268c0d49bd897037e5437e92ef67586a39036a5536ce5a0173a58d6c55a0a04
AWS GovCloudBlueHammerCISACanisterWormCanvasDDoSGitHubIoT botnetMicrosoft Office tokensScattered Spiderbotnetcredentials exposeddata extortiondata leakdoxinglaw enforcementnational securitypatch Tuesdayransomrouter exploitationwiperzero-day
What happened
A series of high-impact cyber incidents and remediation efforts: a CISA contractor accidentally published highly privileged AWS GovCloud credentials and internal build/deploy documentation on a public GitHub repo, creating a major national-security exposure; Instructure’s Canvas suffered a large data-extortion campaign threatening data on ~275M students/faculty and disrupting classes; major vendors (Microsoft, Google, Apple, Mozilla, Oracle, Adobe) pushed unusually large Patch Tuesday updates — including fixes for zero-days and a disclosed Windows Defender issue dubbed “BlueHammer”; Russia-alg
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 5268c0d49bd897037e5437e92ef67586a39036a5536ce5a0173a58d6c55a0a04
- Enrichment time
- 2026-05-19T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.