Verified source report

In stunning display of stupid, secret CISA credentials found in public GitHub repo

SSH keys, plaintext passwords, other sensitive data had been up since November 2025.

In stunning display of stupid, secret CISA credentials found in public GitHub repo
Source image associated with the linked report from Ars Technica. Image selected from source feed metadata and displayed with attribution and link back; VINI does not copy the image into local storage unless rights are cleared.Credit: Image via Ars Technica · Source-hosted image; rights remain with the publisher or credited rights holder. · Image source

Share

Send this story

Share the canonical link, post it to a feed, or send it directly.

X Facebook LinkedIn Reddit WhatsApp Email

What happened

According to Ars Technica’s source item, In stunning display of stupid, secret CISA credentials found in public GitHub repo, SSH keys, plaintext passwords, other sensitive data had been up since November 2025.

Context

The development sits in VINI’s Technology file for readers following technology, science, product policy, markets, infrastructure, and the public consequences of innovation. The original report is linked so readers can check the source account, follow later updates, and compare new coverage against the first published record. The source item is dated 2026-05-19T18:27:08+00:00.

What to watch

Open questions include whether primary sources issue follow-up statements, whether local or market impacts become clearer, and whether additional reporting changes the timeline or adds material context.

Source

Primary source: In stunning display of stupid, secret CISA credentials found in public GitHub repo via Ars Technica. VINI cites and links the source; it does not reproduce the publisher’s full article text without rights clearance.

This source-cited VINI report links to the original publisher record. VINI does not republish third-party article bodies without rights clearance. 1 source listed.

Source links

Reader comments

Moderated discussion

Account access

Comments are open to authenticated approved accounts, screened for spam and abuse, and published only after newsroom moderation unless editors change the story control.

Loading comments.