CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-19T19:23:32Z•5eb898201d95953820256441cba6b7beddafc761aeab017cc4ea721db46ce362
anti-ddos-abuseaws-govcloudcanisterwormcanvascisacredential-leakdata-extortiondata-leakddosdoxinggithub-exposureiot-botnetlaw-enforcement-takedownmicrosoft-office-tokenspatchingransomwarerouter-exploitscattered-spidersupply-chainwiperzero-day
What happened
Multiple high-impact incidents and broad threat trends were reported: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy documentation on GitHub, representing a severe government data/credential leak; Instructure’s Canvas suffered a large data‑extortion incident threatening data from ~275M students and staff and disrupting classes; Russian-linked actors exploited known router flaws to harvest Microsoft Office authentication tokens at scale; law enforcement disrupted several IoT botnets responsible for massive DDoS campaigns, while a Brazil‑f
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 5eb898201d95953820256441cba6b7beddafc761aeab017cc4ea721db46ce362
- Enrichment time
- 2026-05-19T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.