Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

From teenage hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

Stilta raises $10.5M from a16z and YC to help companies rediscover patents they forgot they had

You can now speak in your Gmail inbox, as seen at Google IO 2026

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    You can now speak in your Gmail inbox, as seen at Google IO 2026

    20 May 2026

    Anthropic has acquired the programming tools startup used by OpenAI, Google and Cloudflare

    19 May 2026

    SandboxAQ brings drug discovery models to Claude — no computer science PhD required

    19 May 2026

    Amazon’s new Alexa+ feature can create podcast episodes

    18 May 2026

    Why trust is a big question in the Elon Musk-OpenAI test

    18 May 2026
  • Apps

    Google has just announced that it is a contender in AI design at IO 2026

    20 May 2026

    Apple announces accessibility feature updates with Apple Intelligence support

    19 May 2026

    Kin Health raises $9 million to build an AI notebook for patients

    19 May 2026

    Google brings AI and vibe-coded widgets to Android

    18 May 2026

    Google’s “Create Widget” feature will allow you to code your own widgets

    18 May 2026
  • Crypto

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025
  • Fintech

    Venmo’s biggest makeover in years comes at a very interesting time

    11 May 2026

    Fintech startup Parker files for bankruptcy

    10 May 2026

    Robinhood’s venture fund IPO attracted 150,000+ private investors, CEO says

    7 May 2026

    PayPal says it’s “becoming a tech company again” — that’s AI

    6 May 2026

    Stripe introduces Link, a digital wallet that autonomous AI agents can also use

    1 May 2026
  • Hardware

    Mach Industries just spent $50 million to solve a major defense technology problem

    20 May 2026

    South Korea’s LetinAR makes optics behind AI glasses

    18 May 2026

    Users are turning to jailbreaking their older Kindles as Amazon ends support

    17 May 2026

    Cerebras raises $5.5 billion, then shares soar to $108, first huge tech IPO of 2026

    15 May 2026

    Google unveils Googlebook, a new line of laptops with native artificial intelligence

    13 May 2026
  • Media & Entertainment

    Google’s Gemini Omni turns images, audio and text into video — and that’s just the beginning

    19 May 2026

    Theo Baker spent four years researching Stanford. Before he leaves, here’s what he found.

    19 May 2026

    YouTube viewers watch 2 billion hours of Shorts on TV every month

    14 May 2026

    Digg is trying again, this time as an AI news aggregator

    12 May 2026

    Bravo creates unscripted mini-dramas for the Peacock app

    11 May 2026
  • Security

    US cyber agency CISA has exposed bundles of passwords and cloud keys to the open web

    19 May 2026

    Open source tools maker Grafana Labs says hackers stole its code and refuses to pay ransom

    19 May 2026

    NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people

    18 May 2026

    Instructure strikes against hackers who breached it twice

    17 May 2026

    US lawmakers demand answers from Instructure after Canvas data breaches

    16 May 2026
  • Startups

    From teenage hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

    20 May 2026

    “Survivor” stars Kyle Fraser and Kamilla Karthigesu present a goal-tracking app, Paprclip

    19 May 2026

    Clio’s $500 million milestone comes just as Anthropic steps up to first stage

    15 May 2026

    Startup Battlefield 200 applications close on May 27

    14 May 2026

    Anduril Raises $5B, Doubles Valuation To $61B

    13 May 2026
  • Transportation

    OSHA is investigating the death of a worker at SpaceX’s Starbase site

    19 May 2026

    TechCrunch Mobility: The AI ​​skills arms race is coming for the automotive industry

    18 May 2026

    Tesla Reveals Two Robotaxi Accidents With Remote Controls

    16 May 2026

    RJ Scaringe has raised more than $12 billion in three startups, and investors still want more

    16 May 2026

    Indian Uber rival Rapido raises $240 million at $3 billion valuation

    15 May 2026
  • Venture

    Stilta raises $10.5M from a16z and YC to help companies rediscover patents they forgot they had

    20 May 2026

    Forget Streaming: Status AI Raises $17 Million To Turn Social Media Into Interactive Entertainment

    19 May 2026

    For Eclipse, the $2.5 billion Cerebras win is just the beginning of realizing its physical world thesis

    17 May 2026

    General Catalyst posted VC rage bait and it worked, especially on a16z

    16 May 2026

    Meridian Ventures Raises $35M Fund to Back MBA-Deferred Founders

    15 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»US cyber agency CISA has exposed bundles of passwords and cloud keys to the open web
Security

US cyber agency CISA has exposed bundles of passwords and cloud keys to the open web

techtost.comBy techtost.com19 May 202602 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Us Cyber Agency Cisa Has Exposed Bundles Of Passwords And
Share
Facebook Twitter LinkedIn Pinterest Email

The US cybersecurity agency CISA may have escaped a major security breach, thanks to a bona fide security researcher who identified publicly exposed credentials that allowed access to government cloud systems and internal services.

As first reported by freelance security reporter Brian Krebs, GitGuardian security researcher Guillaume Valadon found bundles of exposed plaintext credentials listed in spreadsheets that had been made publicly accessible in a GitHub repository by an employee working for a CISA contractor.

Valadon told Krebs that the exposed credentials were used to access systems owned by CISA and its parent agency, the Department of Homeland Security. Valadon said the credentials included access tokens, cloud keys and other sensitive files. Valadon told Krebs that he tested some of the keys to verify they were valid.

He then reported the bug to Krebs because the CISA contractor maintaining the GitHub environment didn’t respond to their notifications.

The security breach is particularly troubling for CISA because the US government agency is responsible for cyber security across the civilian federal network. The organization also advises on cyber security best practices, which include storing passwords in secure password managers rather than unprotected spreadsheets.

It is unclear whether anyone other than Valadon found or used the credentials. When reached by TechCrunch, CISA spokesman Marco Di Sandro said the agency is “aware of the reported exposure and continues to investigate the situation” and that “there is no indication that any sensitive data was compromised as a result of this incident.”

CISA won’t say whether the agency has seen evidence of a breach stemming from that report. TechCrunch asked if the service has retracted and replaced the exposed credentials since the incident.

While the incident was traced to an employee working for a CISA contractor, CISA is ultimately responsible for the security of its network and systems, including contractors working for the agency.

CISA has been without a permanent director since January 20, 2025, when then-CISA director Jen Easterly resigned before the start of the new Trump administration. CISA has also lost approx one third of its workforce after cuts, layoffs and layoffs since Trump took office.

Updated with comment from CISA.

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

agency bundles CISA cloud Cyber cyber security data report exposed keys open passwords Trump administration web
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article“Survivor” stars Kyle Fraser and Kamilla Karthigesu present a goal-tracking app, Paprclip
Next Article Google’s Gemini Omni turns images, audio and text into video — and that’s just the beginning
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Open source tools maker Grafana Labs says hackers stole its code and refuses to pay ransom

19 May 2026

NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people

18 May 2026

Instructure strikes against hackers who breached it twice

17 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

From teenage hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

20 May 2026

Stilta raises $10.5M from a16z and YC to help companies rediscover patents they forgot they had

20 May 2026

You can now speak in your Gmail inbox, as seen at Google IO 2026

20 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Venmo’s biggest makeover in years comes at a very interesting time

11 May 2026

Fintech startup Parker files for bankruptcy

10 May 2026

Robinhood’s venture fund IPO attracted 150,000+ private investors, CEO says

7 May 2026
Startups

From teenage hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

“Survivor” stars Kyle Fraser and Kamilla Karthigesu present a goal-tracking app, Paprclip

Clio’s $500 million milestone comes just as Anthropic steps up to first stage

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.