Wall Street Giants Partner With Nvidia On $500 Billion AI Financing Deal
Read more of this story at Slashdot.
Read more of this story at Slashdot.
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.
The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
Read more of this story at Slashdot.
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.
The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.
The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
Read more of this story at Slashdot.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems.
CISA quickly acknowledged our initial alert, but took more than 48 hours to invalidate the AWS keys and many other important secrets leaked in the GitHub repo. In its report on the data leak, CISA said the complexities of the agency’s systems and interconnections with federal and industry partners caused its key rotation to take longer than anticipated.
“Drawing on this experience, CISA encourages others to maintain mature and well-tested key management capabilities,” the report notes.
CISA also admitted it can do better when it comes to responding to security incident notifications from external parties. The postmortem stresses that clear and distinct reporting channels are essential to ensure that incidents affecting the organization itself are handled differently from those involving its products or customers.
“In CISA’s case, these channels were not well defined, leading the security researcher to try multiple avenues – including emailing the contractor, submitting through CISA’s vulnerability disclosure platform (which is intended for vulnerabilities impacting the broader cybersecurity community), and ultimately involving a reporter,” reads the analysis written by Preston Werntz and Brad Libbey, the acting chief information officer and acting chief information security officer at CISA, respectively.
CISA said it is refining its reporting channels to make them easier and faster for researchers. “Additionally, while many researchers rely on the security.txt file, organizations can ensure clarity by publishing reporting instructions in multiple prominent locations,” the CISA authors wrote.
Guillaume Valadon, the GitGuardian researcher who first contacted KrebsOnSecurity about the exposed CISA credentials, said CISA ignored nine automated alerts about the exposed credentials prior to our notification on May 15. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.
“Letting nine notification emails go unanswered is how a one-day incident becomes a six-month exposure,” Valadon wrote in an analysis of CISA’s report. “Make it trivial to report a leak about you, not just about your products. The person reporting a leak to you is not the threat. Publish a security.txt, but do not stop there. Put reporting instructions in several prominent places, and make sure a report about your own infrastructure does not land in a product-bug queue.”
The report’s authors also emphasized the importance of continuously scanning public code repositories like GitHub for exposed secrets, and said CISA has since rotated all secrets and created an action plan to improve management of developer secrets and to better monitor for them going forward.
The report notes that while CISA had developed a playbook for responding to cybersecurity incidents, that playbook somehow didn’t include what to do in situations involving GitHub or other cloud services. Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.
“The Private-CISA repository sat public for six months,” Valadon wrote. “Continuous monitoring of public GitHub surfaced it. Comprehensive internal scanning could have caught the plaintext passwords and committed backups long before they left the building.”
CISA gave itself passing grades on several areas of security preparedness that it said helped the agency gauge the scope and impact of the exposed secrets, including enhanced logging capabilities, and the adoption of zero-trust principles in both its production and development systems. CISA said those detailed logs allowed it to show that no customer or mission data was exposed, and that the leaked credentials were not used outside of CISA’s environments. The agency said the contractor who exposed the secrets had their system access revoked.
Valadon reckons the biggest takeaway is the CISA postmortem itself, and praised the agency for being transparent about what worked and what didn’t.
“To my knowledge, it is also the first time a national cybersecurity agency has publicly advocated for secrets scanning and for simplifying relations with security researchers,” Valadon wrote. “That is exactly the incident communication we should expect from every organization.”
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Trump administration budget chief Russell Vought told lawmakers Tuesday that he’s willing to work with Department of Homeland Security Secretary Markwayne Mullin on re-staffing up the Cybersecurity and Infrastructure Security Agency, following deep personnel cuts and further proposed reductions in the fiscal 2027 budget blueprint.
Mullin said last week at a House Appropriations Subcommittee on Homeland Security hearing that he would like to hire 600 more people at CISA, similar to remarks he made earlier this month at another House hearing. President Donald Trump has cut or lost more than 1,000 from an agency that stood around 3,400-strong at the end of the Biden administration — cuts criticized by lawmakers in both parties.
At a House Appropriations Subcommittee on Financial Services and General Government hearing Tuesday, Rep. Mark Amodei, R-Nev., asked Vought about Mullin’s CISA remarks.
“You don’t just flip a light switch on, and you got 600 folks over in CISA now. What’s the plan for getting CISA fully operational?” Amodei, who chairs the panel’s Subcommittee on Homeland Security, asked. “How do we make sure we have a robust, effective, cost-effective CISA force? Because I don’t think anybody thinks we have it now.”
Vought, director of the Office of Management and Budget, said he hasn’t received a formal request from Mullin to increase CISA’s number of full-time employees, but knows that hiring isn’t instantaneous.
“He was not here when we developed this budget, so if he feels the need to have additional resources, we will work through that internally, and at the appropriate time, come up and brief you,” he answered Amodei. “I do think he’s in the process still of getting his arms wrapped around the department,” he said. Mullen became DHS secretary in late March.
“This is probably one of those things, particularly in the cyber world, you now have a year and a half of a new administration,” Vought continued, and referred to conservative complaints about how CISA handled election security and disinformation under Biden. “We saw this agency had major concerns with it in our four years outside of government and with new management, I think it’s now an agency, or could be an agency, that plays a very valuable part for DHS’s portfolio.”
Bringing hundreds of new CISA personnel on board could prove challenging for reasons beyond the usual bureaucratic hurdles and security clearance processes that slow any federal hires in the national security space. Past CISA employees and agency observers have said the way the Trump administration has purged personnel and treated those who have stayed could prove a further disincentive to future hires.
Acting CISA director Nick Andersen recently said that the agency has begun the process of hiring new CISA staffers, and expected to have nearly 200 job offers out by the end of this month.
The post Trump budget boss Russell Vought open to re-staffing CISA appeared first on CyberScoop.
Read more of this story at Slashdot.