‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) inadvertently exposed sensitive digital keys on GitHub for an extended period. The repository contained passwords and tokens in plain text, raising concerns about potential data compromise. CISA has since addressed the issue and stated that there is currently no evidence of any sensitive data being compromised.
- ▪CISA left digital keys to its cloud storage accounts exposed on GitHub for an unknown duration.
- ▪The repository included plaintext passwords and tokens, raising cybersecurity concerns.
- ▪CISA has implemented measures to prevent future occurrences and stated that no sensitive data appears to have been compromised.
2 outlets in our directory ran this story, first to last over 1 hour. All of the coverage we found sits in one bucket: centre. That one-sidedness is itself worth noticing.
Gizmodo files mainly under tech. We currently carry 644 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Gizmodo |
| Canonical URL | https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330 |
| Publication time | Tue, 19 May 2026 01:31:35 +0000 |
| Retrieval time | 2026-05-19T01:34:57.096Z |
| Last seen | 2026-05-19T01:34:57.096Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | nQenKgVxsexl · 2 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been leaving the digital keys to its own cloud storage accounts sitting out in the open, in plain text form, for some unknown amount of time, according to a report from Krebs on Security. The problem finally got fixed over the weekend, the report says.cnx.cmd.push(function(){cnx({"playerId":"92b7b46b-43ed-4e0e-b21b-2c999302d9d7","settings":{"advertising":{"macros":{"AD_UNIT":"/23178111854/od.gizmodo.com/article","CHILD_UNIT":"article","POST_ID":"2000760330","POST_TYPE":"post","CHANNEL":"tech","SECTION":"privacy-and-security","SUBSECTION":"","CATEGORIES":"privacy-and-security","TAGS":"cisa,github,leaks","NOP":"0"},"timeBeforeFirstAd":0}}}).render("cnx-player-main")}); Surely the secret information was buried in some…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Gizmodo.