Lawmakers Demand Answers as CISA Tries to Contain Data Leak

2026-05-25T07:23:26Z998514f106ac28dc959c06b6a12e0a4d3b6e4133822df8cc3e464f5093eba021
AWS GovCloudCISACanvasDDoSGitHub leakIoT botnetKimwolfMicrosoft Office tokensPatch TuesdayScattered Spiderarrestcongressional inquirycredential exposuredata extortiondata leakeducation platformnation-state espionageransomware gangsrouter compromisezero-day

What happened

KrebsOnSecurity (May 2026) covers multiple high-impact cybersecurity incidents: a CISA contractor publicly exposed AWS GovCloud credentials and sensitive internal build/deploy artifacts on a GitHub repository, prompting congressional inquiries; a large data‑extortion attack against the Canvas education platform threatening data from ~275 million students and staff; the arrest and charging of an alleged Kimwolf IoT botnet operator; reports of Russian-linked actors harvesting Microsoft Office authentication tokens via compromised routers; and numerous vendor patches addressing actively exploited

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
998514f106ac28dc959c06b6a12e0a4d3b6e4133822df8cc3e464f5093eba021
Enrichment time
2026-05-25T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Lawmakers Demand Answers as CISA Tries to Contain Data Leak · Baitaphish