CISA Admin Leaked AWS GovCloud Keys on Github

2026-05-20T19:23:28Ze7ac7e33828303cb094334f0a0feb6f48ba146d9e349faefa6fcfeb98db8ec43
awsbotnetcanisterwormcanvascredentials-leakdata-exposureddosdoxingeducation-platformgithubgovcloudincident-responseiotlaw-enforcementmicrosoft-officepatch-tuesdayransom-extortionrouter-exploitrussiastate-sponsoredsupply-chaintoken-theftvulnerability-managementwiperzero-day

What happened

Collection of KrebsOnSecurity reports (Mar–May 2026) covering multiple high-impact incidents: a CISA contractor publicly exposed AWS GovCloud credentials and internal build/deploy artifacts on GitHub; a nation-scale extortion/defacement of the Canvas education platform threatening data from ~275M students and staff; Russian-linked actors exploiting router vulnerabilities to harvest Microsoft Office authentication tokens; emergence of the CanisterWorm wiper targeting Iranian systems; an anti-DDoS vendor implicated in enabling large DDoS campaigns against Brazilian ISPs; law-enforcement takedown

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
e7ac7e33828303cb094334f0a0feb6f48ba146d9e349faefa6fcfeb98db8ec43
Enrichment time
2026-05-20T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Admin Leaked AWS GovCloud Keys on Github · Baitaphish