CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-21T01:23:32Z•8ecc97806077cc77524aa0133851cb9434172a8fef68643ed11a1ce344c3f36c
aws-govcloudbotnetcanisterwormcanvascisacredential-leakdata-breachddosgithub-exposureiot-botnetmicrosoft-office-token-theftransomware-extortionrouter-exploitationscattered-spiderthreat-actorvulnerability-patchingwiper-malware
What happened
Multiple high-impact cybersecurity incidents reported: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy documentation on GitHub; a large-scale data extortion attack against Canvas disrupted classes and threatened data on ~275 million students and faculty; Russia-linked actors exploited router flaws to harvest Microsoft Office authentication tokens at scale; and law enforcement disrupted multiple IoT botnets responsible for massive DDoS campaigns. Other notable items include an anti-DDoS vendor implicated in enabling attacks on Brazilian IS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 8ecc97806077cc77524aa0133851cb9434172a8fef68643ed11a1ce344c3f36c
- Enrichment time
- 2026-05-21T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.