CISA Admin Leaked AWS GovCloud Keys on Github

2026-05-20T07:23:26Z8d9efa41b496a0216f7e90fc6b97d697e24a74aa74be21c394252e6e9b4a49cf
appleawscanisterwormcanvascloud-securitycredentials-exposuredata-leakddosdoxingeducation-sectorgithubgooglegovcloudiot-botnetlaw-enforcement-takedownmicrosoftoffice-tokensoraclepatch-managementransom-extortionrouter-exploitrussiastate-sponsoredwiperzero-day

What happened

Multiple high-impact cybersecurity incidents in May 2026: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/test/deploy artifacts on a GitHub repository, constituting a major government data leak; an extortion-driven breach of Canvas threatened data on ~275 million students and faculty; large vendor patch waves (Microsoft, Google, Apple, Oracle, Mozilla, Adobe) fixed numerous vulnerabilities including several zero-days; Russian-linked actors harvested Microsoft Office authentication tokens by exploiting legacy router flaws; an anti-DDoS firm was (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
8d9efa41b496a0216f7e90fc6b97d697e24a74aa74be21c394252e6e9b4a49cf
Enrichment time
2026-05-20T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Admin Leaked AWS GovCloud Keys on Github · Baitaphish