Tag
This article covers a security podcast discussion on the risks of open-weight AI models like GLM 5.2, which attackers can modify and exploit, and introduces CISA's new BOD 26-04 directive that replaces the CVSS scoring system with a four-variable dynamic prioritization model for federal agencies.
The US government warns that Russian state hackers are targeting poorly configured home and small office routers to build botnets for cyber attacks against critical infrastructure, with CISA issuing a joint advisory.
CISA's postmortem on a GitHub leak of internal credentials highlights critical incident response failures, including delayed key rotation and ignored automated alerts, offering key lessons for security teams.
A tweet sharing links to free certification resources for AWS, CISSP, CISA, CISM, and Digital Marketing.
CISA issued a new binding operational directive requiring US federal agencies to patch critical security bugs within three days, citing increased AI-driven vulnerability discovery and exploitation.
Lawmakers demand answers after a CISA contractor intentionally exposed AWS GovCloud keys and other secrets on a public GitHub repository, raising concerns about the agency's security culture amid staffing disruptions.
A public GitHub repository named 'Private-CISA' exposed plaintext passwords, SSH keys, and tokens belonging to CISA, allowing high-privilege access to AWS GovCloud accounts. The breach was discovered by GitGuardian and reported by Brian Krebs, following a previous incident where the acting CISA director leaked government documents via ChatGPT.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) exposed its cloud storage credentials in plain text on a public GitHub repository named 'Private-CISA' for about six months, until the leak was fixed over the weekend. No evidence of compromise has been found, but the incident underscores ongoing turmoil within the agency.
A CISA contractor leaked highly privileged AWS GovCloud credentials and internal system passwords on a public GitHub repository, representing one of the most egregious government data leaks in recent history.