Plan
archived
CISA Postmortem: Contractor AWS Keys Leaked to Public GitHub for 6 Months
- Engineer — Plan: This postmortem highlights systemic gaps in detecting committed credentials and contractor offboarding. Audit your GitHub org repos and CI config files for exposed secrets, enable GitHub Advanced Security secret scanning org-wide, and verify pre-commit hooks or equivalent controls are enforced across contractor-accessible repos.
- SOC/IR — Learn: CISA’s documented response gaps — including the near-six-month detection delay — are worth absorbing when refining your own IR playbook for credential-exposure scenarios, but no IOCs or active exploitation are present to drive immediate hunt or detection work.
- Leader — Plan: A federal agency’s own postmortem on contractor-driven credential exposure is a direct governance signal: this quarter, validate that your third-party access controls, contractor off-boarding procedures, and secrets-exposure detection capabilities don’t share the same gaps CISA identified.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.