Lawmakers Demand Answers as CISA Tries to Contain Data Leak
2026-05-25T13:23:29Z•af1b647985290eebb05137dc31e7d2d66aa05c54455a678272dc3f719c2365f4
AWS GovCloudAdobeBlueHammerBrazilian ISP attacks","Scattered Spider","ransomware","REvil","CISACanvasDDoSGitHubGoogle ChromeKimwolfMicrosoftMicrosoft Office tokensPatch TuesdayRussia-linkedSharePointanti-DDoS abusearrestbotnetcongressional inquirycredentialsdata extortiondata leakeducation breachrouter vulnerabilitieszero-day
What happened
KrebsOnSecurity’s recent feed highlights multiple high-impact cyber incidents: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy secrets on GitHub, prompting congressional inquiries as CISA races to contain the leak and invalidate credentials; the alleged 23‑year‑old Kimwolf botnet operator (“Dort”) was arrested and charged in Canada and the U.S.; the Canvas education platform suffered a large extortion/defacement incident threatening data on ~275 million students and faculty; and numerous major software vendors (Microsoft, Google/Chrome,苹果
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- af1b647985290eebb05137dc31e7d2d66aa05c54455a678272dc3f719c2365f4
- Enrichment time
- 2026-05-25T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.