The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb. According to Krebs on Security, the cybersecurity and infrastructure security agency (cisa) has issued a postmortem on a data leak in which a contractor published dozens of internal cisa credentials — including aws govcloud keys — in a public github repository for almost six months before being notified by krebsonsecurity. experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.. The development comes amid ongoing regulatory scrutiny in the sector. Krebs on Security reports that this marks a significant milestone for the industry. The Krebs on Security report provides additional context on the implications for market participants and regulatory frameworks moving forward.
