A secret plan by the US government's Cybersecurity and Infrastructure Security Agency (CISA) has come to light after independent cybersecurity journalist Brian Krebs reported on the matter in May. Krebs alleged that a security researcher at cyber firm GitGuardian had discovered a publicly accessible GitHub repository containing reams of exposed passwords stored by an employee of CISA contractor, Core Impact.
According to Krebs, the repository was discovered through an informal exchange with GitGuardian's team, who had been monitoring the website for suspicious activity. The incident raises concerns about the potential security risks posed by large datasets of sensitive information being publicly available. GitGuardian's researcher stated that they were not aware of the data at first and immediately reported it to Krebs.
The discovery has sparked fears among cybersecurity experts, with some expressing concern that CISA may have been using the data for its own purposes without explicit authorization. Krebs has stated that he had raised these concerns with various government officials, but was met with assurances that the data would not be used for any malicious activities. The incident highlights the importance of maintaining robust security measures to protect sensitive information from falling into the wrong hands.