GitHub Leak Exposes CISA and DHS Credentials, Raises Security Concerns

GitHub Leak Exposes CISA and DHS Credentials, Raises Security Concerns

First seen 21 May 2026, 01:12 UTC Biometricupdatewww.justice.gov 73% similarity 70.0

Article Content

Browse articles
ThreatCluster

A GitHub repository linked to Nightwing, a contractor for CISA, leaked credentials for AWS GovCloud accounts and internal systems of CISA and DHS. The exposure, attributed to a significant operational security failure, has prompted urgent requests for briefings from congressional leaders. Nightwing, previously part of Raytheon, has a history of cybersecurity compliance issues, including a recent $8.4 million settlement related to the False Claims Act. The incident raises questions about contractor oversight and the security of government software development processes. CISA's credibility is at stake as it advocates for stronger cybersecurity practices across federal and state agencies. The leak occurred amidst internal disruptions at CISA, which has seen a workforce reduction during the Trump administration.

Key Points: • A GitHub leak exposed sensitive credentials for CISA and DHS systems. • Nightwing, the contractor involved, has a history of cybersecurity compliance failures. • Congressional leaders have requested urgent briefings regarding the incident.

ThreatCluster AI

Timeline

2026-05-20
GitHub repository leak reported
Credentials for AWS GovCloud and internal CISA/DHS systems were exposed, linked to Nightwing contractor.
Biometricupdate
2026-05-20
Congressional briefings requested
Sen. Maggie Hassan and House Democrats demanded urgent briefings from CISA regarding the leak.
Biometricupdate
2026-05-21
Raytheon and Nightwing settlement announced
Raytheon and Nightwing agreed to pay $8.4 million to resolve False Claims Act allegations related to cybersecurity compliance.
www.justice.gov

Community

Browse all →

Tracked Entities in This Story