<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential-Leak on CuraSec</title><link>https://curasec.metacog.co.kr/tags/credential-leak/</link><description>Recent content in Credential-Leak on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 14 Jul 2026 12:08:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/credential-leak/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA Postmortem: Contractor AWS Keys Leaked to Public GitHub for 6 Months</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-lessons-learned-from-cisa-s-recent-github-leak/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-lessons-learned-from-cisa-s-recent-github-leak/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> This postmortem highlights systemic gaps in detecting committed credentials and contractor offboarding. Audit your GitHub org repos and CI config files for exposed secrets, enable GitHub Advanced Security secret scanning org-wide, and verify pre-commit hooks or equivalent controls are enforced across contractor-accessible repos.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> CISA&amp;rsquo;s documented response gaps — including the near-six-month detection delay — are worth absorbing when refining your own IR playbook for credential-exposure scenarios, but no IOCs or active exploitation are present to drive immediate hunt or detection work.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A federal agency&amp;rsquo;s own postmortem on contractor-driven credential exposure is a direct governance signal: this quarter, validate that your third-party access controls, contractor off-boarding procedures, and secrets-exposure detection capabilities don&amp;rsquo;t share the same gaps CISA identified.&lt;/li>
&lt;/ul></description></item></channel></rss>