NewsAnarchist
The stories buried, spiked, or spun.
BREAKING
Independent investigative news — unfiltered, unspiked. The Buried Week publishes every Friday. Subscribe free for the daily briefing. Tips: zeno@newsanarchist.com or Signal. Independent investigative news — unfiltered, unspiked. The Buried Week publishes every Friday. Subscribe free for the daily briefing. Tips: zeno@newsanarchist.com or Signal.
Government Secrets

CISA Admin Leaked AWS GovCloud Keys on GitHub

Share

What the Documents Show

CISA's official position, as relayed through standard agency channels, frames this as a singular contractor error—a mistake by an individual who failed to follow protocol. This framing collapses under the weight of the actual evidence. The contractor didn't accidentally commit secrets to GitHub. The commit logs show explicit commands disabling GitHub's default secret-detection feature. Valadon documented the specificity of this sabotage: "Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature." This wasn't negligence.

🔎 Mainstream angle: The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.

Follow the Money

This was deliberate circumvention of security controls. The repository remained publicly accessible long enough for any adversary—Chinese intelligence, Russian SVR operatives, Iranian IRGC units, or freelance criminals—to clone the entire archive and extract credentials. No public statement from CISA has identified the contractor by name or provided even basic accountability details: How long had this repository been public? Who approved the contractor's to GovCloud credentials? What systems have been audited for unauthorized access since the exposure was discovered? How many other CISA contractors maintain similar repositories?

What Else We Know

The scope of exposure extends beyond embarrassment. Valadon noted that the files detailed "how CISA builds, tests and deploys software internally"—meaning adversaries didn't just gain temporary access to systems, they gained architectural blueprints to CISA's operational security posture. They learned which tools CISA uses, where they store code, how they verify deployments, and which personnel have which access levels. This is the kind of intelligence that doesn't depreciate. It compounds in value for hostile state actors planning future intrusions into other federal agencies. CISA exists specifically to prevent this kind of exposure.

Jordan Calloway
The Jordan Calloway Take
Government Secrets & FOIA

What strikes me about this story is how perfectly it exposes the gap between CISA's mandate and its actual security culture. The agency preaches zero-trust architecture and secrets management best practices to every financial institution and electric utility in America while its own contractors are committing plaintext passwords to public repositories.

The pattern here is institutional capture through bureaucratic diffusion. When the agency responsible for defending critical infrastructure gets caught sabotaging its own security infrastructure, accountability vanishes into inter-agency investigations that produce no public findings. CISA benefits from this silence because acknowledging systemic security failure would undermine its credibility to regulate others. Congress benefits because oversight of intelligence agencies is performative theater. The contractor benefits because federal employment law shields them from prosecution in ways private-sector employees would never enjoy.

Watch whether CISA ever publicly identifies this contractor or discloses what access was actually compromised. That answer will tell you whether you can trust anything this agency says about your own security.

Primary Sources

What are they not saying? Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.

Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.

Share
Part of our Government Secrets coverage
See the full picture on our Government Secrets hub — including our ongoing coverage of declassification, whistleblowers, and government transparency.
How We Report Government Secrets

This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a declassified document, a FOIA release, an inspector general or congressional report, or a named whistleblower disclosure reported by outlets we cite) and reports what that source states, attributed to it — it reports what the document or disclosure states and does not speculate about what remains classified beyond that. Part of our Government Secrets hub. Found an error? Tell us.