CISA's Own Credentials Were Sitting on GitHub for Six Months episode artwork

EPISODE · Jun 9, 2026 · 4 MIN

CISA's Own Credentials Were Sitting on GitHub for Six Months

from The 229 Podcast

CISA -- the federal agency whose job it is to protect America's critical infrastructure -- had its own internal credentials sitting in a public GitHub repository for six months. Plain text passwords. AWS GovCloud keys. SSH access tokens. Visible to anyone on the internet with a browser.What makes this worse: the contractor who created the repository didn't slip up accidentally. They actively disabled the default GitHub protections designed to prevent exactly this from happening. And when the repository finally came down, those AWS keys stayed valid for another 48 hours before anyone thought to revoke them.Drex brings this back to the question every health system CISO should be sitting with: How many contractors have access to your most sensitive systems right now -- and if one of them made this choice six months ago, would you even know today?Remember, Stay a Little Paranoid Linkedin: https://www.linkedin.com/company/ThisWeekHealth Twitter: https://twitter.com/thisweekhealth Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer - https://www.alexslemonade.org/mypage/3173454

Episode metadata supplied by the publisher feed · Published Jun 9, 2026

Embed this episode

NOW PLAYING

CISA's Own Credentials Were Sitting on GitHub for Six Months

0:00 4:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The 229 Podcast?

This episode is 4 minutes long.

When was this The 229 Podcast episode published?

This episode was published on June 9, 2026.

Can I download this The 229 Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!