Therecord.Media Senator Hassan Demands Answers on CISA Data Leak Involving Contractor
Article Content
- •A contractor for CISA reportedly leaked sensitive agency credentials on a public GitHub repository.
- •Files included AWS administrative credentials and plaintext passwords for multiple internal systems.
- •Senator Hassan has called for a classified briefing to address security policy concerns at CISA.
U.S. Senator Maggie Hassan has requested an urgent classified briefing from the Cybersecurity and Infrastructure Security Agency (CISA) regarding a significant data leak involving contractor Nightwing. Reports indicate that sensitive agency account credentials and internal operational files were found in a public GitHub repository. The exposed files included AWS administrative credentials and plaintext usernames and passwords for internal systems. This incident raises serious concerns about CISA's internal security policies, especially given the backdrop of ongoing cyber threats to U.S. critical infrastructure. Security experts have labeled this leak as one of the most egregious government data leaks in recent history. CISA has stated there is no indication that sensitive data was compromised, but questions remain about the security measures that allowed this incident to occur. The agency is under pressure to clarify its internal procedures and the implications of this breach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cybersecurity and Infrastructure Security Agency in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…