CISA Admin Leaked AWS GovCloud Keys on Github

2026-05-20T13:23:29Z631bff45aca592a29c5c1d785f4ab757599c989f5782510219a8ffdd99a21987
CISAaws-govcloudbotnetcredential-exposuredata-leakddoseducation-sectorextortiongandcrabgithubiotlegal-actionmalwarepatchingransomwarerevilscattered-spiderstate-sponsoredsupply-chainvulnerabilitieswiperzero-day

What happened

Multiple high-impact incidents and patch developments: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy documentation on GitHub; the Canvas education platform suffered a massive data extortion incident allegedly affecting ~275 million students/staff; a Brazilian anti-DDoS vendor was implicated in enabling large-scale DDoS attacks via a botnet; Russian-linked actors exploited router flaws to harvest Microsoft Office authentication tokens at scale; a new wiper ('CanisterWorm') targeted systems with Iran time/Farsi settings; U.S. and allied f

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
631bff45aca592a29c5c1d785f4ab757599c989f5782510219a8ffdd99a21987
Enrichment time
2026-05-20T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.