Lawmakers Demand Answers as CISA Tries to Contain Data Leak
2026-05-23T13:23:26Z•f668d4c68be25569905a793bd11719f6804122fe9140abbfb9902a74e704550c
anti-ddos abuseaws govcloudbluehammercanvaschrome zero-daycisacongressional inquirycredentials exposuredata breachdata extortionddosdoxingeducation breachgithub leakincident responseiot botnetkimwolflaw enforcementmicrosoft office tokenspatch tuesdayransomware gangs','revil','gandcrabrouter exploitscattered spiderswattingzero-day
What happened
KrebsOnSecurity reports a string of high-impact incidents: a CISA contractor intentionally published highly privileged AWS GovCloud credentials and extensive internal documentation to a public GitHub repository, triggering an ongoing containment effort, credential invalidation challenges and bipartisan Congressional inquiries. Related coverage in the feed includes the arrest of the alleged Kimwolf botmaster (IoT botnet used for massive DDoS, doxing and swatting), a large-scale Canvas data-extortion/defacement incident threatening ~275 million student and faculty records, a Russian campaign hij
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- f668d4c68be25569905a793bd11719f6804122fe9140abbfb9902a74e704550c
- Enrichment time
- 2026-05-23T13:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.