Skip to main content
LiveListen now5 listening
Live

aired speech / station archive

CISA GitHub Leak Lessons and the FSB Router Threat [Prime Cyber Insights]

Spoken by Neural Newscast on Neural Newscast. Aired Jul 14, 01:49 PM / 270s / music_show / audio on file.

CISA GitHub Leak Lessons and the FSB Router Threat [Prime Cyber Insights]

I'm Aaron Cole. This is Prime Cyber Insights: professional analysis for the security practitioner. <br/><i>acting_description:</i> professional, steady, composed <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 We're starting today with CISA's blunt postmortem on its own internal security failure. Yesterday, the agency detailed how a contractor published 844 M-B of sensitive data to a public GitHub repository titled 'Private CISA.' The leak included administrative keys for three AWS GovCloud servers and a CSV file containing plaintext passwords for dozens of internal systems. Lauren, the timeline on this is what really bothers me. <br/><i>acting_description:</i> analytical, informative, direct <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.4 It should, Aaron. That repository was public for nearly six months before Krebs on Security flagged it. Even after the alert on May 15th, CISA admitted it took more than 48 hours to invalidate the AWS keys. Their explanation cites complexities and interconnections with federal partners that slowed the rotation. For a practitioner, the takeaway is clear: if your key rotation playbook isn't well-tested for cloud services, the rotation will fail under the pressure of a live incident. <br/><i>acting_description:</i> engaged, measured, attentive <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 And it wasn't just a technical lag. CISA ignored nine automated alerts from GitGuardian prior to the manual notification. Acting CI-O Preston Werntz and Acting CISO Brad Libbey noted that reporting channels were poorly defined, causing the researcher to cycle through multiple avenues before involving the media. They’re now advocating for better use of the security.txt standard, but the internal friction suggests CISA's vulnerability disclosure platform wasn't ready to handle its own infrastructure leaks. <br/><i>acting_description:</i> clinical, serious, focused <i>speed:</i> 0.97 <i>trailing_silence:</i> 0.5 Exactly. Moving from internal leaks to external state-sponsored threats, the United States government alongside international allies issued a massive advisory this week regarding Russia’s F-S-B Center 16. Groups like Berserk Bear and Ghost Blizzard are aggressively targeting home and small office routers. They aren't looking for data on those devices

Read disclosure