kapynPolicy & Regulation

In stunning display of stupid, secret CISA credentials found in public GitHub repo

Secret CISA credentials, including SSH keys and plaintext passwords, were discovered in a public GitHub repository. The sensitive data had been exposed since November 2025, highlighting significant security vulnerabilities. This incident underscores the critical need for robust access control and vigilant monitoring of public code repositories to prevent data breaches.

Ars Technica·May 19, 2026

Opening Kapyn…