CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-19T01:23:27Z•9320d3c482c18f7e8ffd81c516b5d78cbc1866f3583edd0e6e07aea7cc2564bc
AWS GovCloudBrazilCISACanisterWormCanvasDDoSGandCrabGitHubIoT botnetMicrosoft Office tokensPatch TuesdayREvilRussia-linked actorsScattered Spiderbotnetcredentials leakdata extortiondata leakdoxingphishingransomrouter exploitsvulnerabilitieswiper malware','DOJ disruptionzero-day
What happened
KrebsOnSecurity reported a series of high-impact cyber incidents from Mar–May 2026: a contractor leaked highly privileged AWS GovCloud credentials and internal CISA build/deploy documentation on a public GitHub repo; large-scale Patch Tuesday rounds from multiple vendors (Apple, Google, Microsoft, Mozilla, Oracle) fixed record numbers of vulnerabilities including recently exploited/zero-day issues; the Canvas edtech platform was hit by a data-extortion attack threatening ~275M student/faculty records and disrupting schools; a Brazilian anti-DDoS vendor was implicated in weaponizing a botnet to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 9320d3c482c18f7e8ffd81c516b5d78cbc1866f3583edd0e6e07aea7cc2564bc
- Enrichment time
- 2026-05-19T01:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.