CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-19T07:23:27Z•e56e0c9d7cb625e81194aba847087f1af775c1e9a8660c341fda3c083cf2a792
aws-govcloudbluehammerbotnet-takedowncanisterwormcanvascisacontractor-misconfigdata-extortiondata-leakddoseducation-sectorgandcrabgithub-credential-leakiot-botnetsmicrosoft-office-token-theftpatch-tuesdayransomwarerevilrouter-vulnerabilitiesscattered-spidersecrets-exposuresharepoint-serversupply-chain-riskwiper-malwarezero-day
What happened
Multiple high-impact incidents reported: a CISA contractor left highly privileged AWS GovCloud credentials and detailed internal build/test/deploy documentation in a public GitHub repo, exposing critical government cloud accounts and internal systems. Separately, a broad extortion/data-leak incident against the Canvas education platform disrupted schools and threatens data for ~275 million users. Other notable items include mass harvesting of Microsoft Office authentication tokens via compromised/legacy routers, disruption of four large IoT botnets by international law enforcement, a wiper ("C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- e56e0c9d7cb625e81194aba847087f1af775c1e9a8660c341fda3c083cf2a792
- Enrichment time
- 2026-05-19T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.