CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-20T01:23:28Z•a2e725635e4c3bfc867aa1bb2e1f319d3583f62e8c5a217d6353f53cc2cb6d8a
adobe-readeranti-ddos-abuseaws-govcloudbotnetcanisterwormcanvaschrome-zero-daycredential-leakdata-extortionddosdoxing-revil-gandcrab-unkn','law-enforcement-takedowngithub-exposuregovernment-incidentiot-botnetoffice-token-theftpatch-tuesdayphishingransomwarerouter-vulnerabilitiesscattered-spidersharepoint-zero-daysocial-engineeringwindows-defender-bluehammerwiperzero-day
What happened
Collection of security incidents and patch activity May 2026: a contractor for CISA publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy artifacts on GitHub; the Canvas education platform suffered a large data-extortion attack claiming data on ~275M students/faculty; vendors (Microsoft, Google, Apple, Mozilla, Oracle, Adobe) issued unusually large/urgent patch sets including a SharePoint Server zero-day and a publicly disclosed Windows Defender flaw (“BlueHammer”); Russian-linked actors harvested Microsoft Office authentication tokens via exploited/legacy home/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- a2e725635e4c3bfc867aa1bb2e1f319d3583f62e8c5a217d6353f53cc2cb6d8a
- Enrichment time
- 2026-05-20T01:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.