INTEL_REPORT
Ars Technica — Security · published 5/19/2026, 6:27:08 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
In stunning display of stupid, secret CISA credentials found in public GitHub repo SSH keys, plaintext passwords, other sensitive data had been up since November 2025. Security researcher Brian Krebs brings us the news that America's Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and "other sensitive CISA assets" exposed in a public GitHub repo since at least November 2025. The now-offline public repo…
https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo
sha256:ed96dea5781be29203bdf41bd0ab49cf0a3dd379bddec93fd591b364235dc579
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.