CISA Admin Leaked AWS GovCloud Keys on Github

2026-05-20T01:23:28Za2e725635e4c3bfc867aa1bb2e1f319d3583f62e8c5a217d6353f53cc2cb6d8a
adobe-readeranti-ddos-abuseaws-govcloudbotnetcanisterwormcanvaschrome-zero-daycredential-leakdata-extortionddosdoxing-revil-gandcrab-unkn','law-enforcement-takedowngithub-exposuregovernment-incidentiot-botnetoffice-token-theftpatch-tuesdayphishingransomwarerouter-vulnerabilitiesscattered-spidersharepoint-zero-daysocial-engineeringwindows-defender-bluehammerwiperzero-day

What happened

Collection of security incidents and patch activity May 2026: a contractor for CISA publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy artifacts on GitHub; the Canvas education platform suffered a large data-extortion attack claiming data on ~275M students/faculty; vendors (Microsoft, Google, Apple, Mozilla, Oracle, Adobe) issued unusually large/urgent patch sets including a SharePoint Server zero-day and a publicly disclosed Windows Defender flaw (“BlueHammer”); Russian-linked actors harvested Microsoft Office authentication tokens via exploited/legacy home/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
a2e725635e4c3bfc867aa1bb2e1f319d3583f62e8c5a217d6353f53cc2cb6d8a
Enrichment time
2026-05-20T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.