ADVERTISEMENT

How the world’s top cyber authority left its door wide open on GitHub: CISA shares lessons from major blunder

CISA promises no customer or mission data was compromised, even though exposed keys remained valid for days.

CISA

Image by jackpress | Shutterstock

Ernestas Naprys
Ernestas Naprys Senior Journalist
July 10, 2026 Updated: July 10, 2026 5 min read
Key takeaways:

It took a journalist to get CISA's attention

This is indeed the worst leak that I’ve witnessed in my career.
Valadon wrote in an email to Brian Krebs.
ADVERTISEMENT
US Cybersecurity and Infrastructure Security Agency
Thomas Fuller/SOPA Images/LightRocket via Getty Images

So what were the actual lessons learned?

No secrets in any repos

github data breach

A direct line for researchers

Tighter controls and replacement-ready keys

Ernestas Naprys
Senior Journalist
ADVERTISEMENT