
CISA Had No Playbook When Government Credentials Leaked to GitHub
CISA's July post-mortem revealed the agency lacked a prepared incident response plan when a contractor uploaded sensitive government credentials to a public GitHub repository in May 2026. Staff improvised their playbook during the response itself. The agency only discovered the exposure after cybersecurity journalist Brian Krebs alerted them directly. No data compromise resulted from the leak.
Published