CISA Admin Leaked AWS GovCloud Keys on Github

2026-05-19T01:23:27Z9320d3c482c18f7e8ffd81c516b5d78cbc1866f3583edd0e6e07aea7cc2564bc
AWS GovCloudBrazilCISACanisterWormCanvasDDoSGandCrabGitHubIoT botnetMicrosoft Office tokensPatch TuesdayREvilRussia-linked actorsScattered Spiderbotnetcredentials leakdata extortiondata leakdoxingphishingransomrouter exploitsvulnerabilitieswiper malware','DOJ disruptionzero-day

What happened

KrebsOnSecurity reported a series of high-impact cyber incidents from Mar–May 2026: a contractor leaked highly privileged AWS GovCloud credentials and internal CISA build/deploy documentation on a public GitHub repo; large-scale Patch Tuesday rounds from multiple vendors (Apple, Google, Microsoft, Mozilla, Oracle) fixed record numbers of vulnerabilities including recently exploited/zero-day issues; the Canvas edtech platform was hit by a data-extortion attack threatening ~275M student/faculty records and disrupting schools; a Brazilian anti-DDoS vendor was implicated in weaponizing a botnet to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
9320d3c482c18f7e8ffd81c516b5d78cbc1866f3583edd0e6e07aea7cc2564bc
Enrichment time
2026-05-19T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Admin Leaked AWS GovCloud Keys on Github · Baitaphish