[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
9/10A CISA contractor inadvertently left AWS GovCloud admin keys, plaintext passwords, SAML certificates, and Kubernetes configurations exposed on a public GitHub repository for 183 days with secret scanning deliberately disabled, raising serious national security risks as reported in May 2026.
