TL;DR
🔴 The Ultimate Irony — The agency responsible for protecting America's cyber infrastructure just left their own credentials on the open internet. In a spreadsheet. On GitHub.
🤖 AI trust crisis — White House delays, NSA involvement, frontier model oversight. Nobody can agree on who watches the watchers.
🛡️ Trust is the new attack surface — Code signing abuse, VPN takedowns, credential theft at industrial scale. The theme writes itself.
💼 The MSSP moment — MSSPs filling the CISO gap is literally our pitch wrapped in a news story.
🍎 Even Mac users aren't safe anymore — And they really thought they were.
THIS WEEK’S TOP STORY
The Agency That's Supposed To Protect You Just Left Their Door Keys Under The Mat…
What Happened: Let's be very clear about what happened here.
CISA — the Cybersecurity and Infrastructure Security Agency — the organization whose entire reason for existing is to tell America how not to get hacked — just had a contractor expose AWS GovCloud credentials, plaintext passwords, internal files and cloud keys in a public GitHub repository they literally named "Private-CISA."
The irony writes itself.
This wasn't a sophisticated supply chain attack. This wasn't a nation-state zero-day. A Nightwing government contractor appears to have been using a public GitHub repo to sync files between their work laptop and home computer — since November 2025 — with the secrets management awareness of someone who just discovered the internet.
A spreadsheet containing plaintext usernames and passwords for dozens of internal CISA systems. Passwords consisting of nothing more than the platform name followed by the current year. And — the chef's kiss — the contractor manually disabled GitHub's built-in secrets detection to make it happen.
They turned off the alarm before robbing the bank.
Security researcher Guillaume Valadon of GitGuardian — who discovered the exposure — said he initially thought it was fake. "I honestly believed it was all fake before analyzing the content deeper," he wrote. "This is indeed the worst leak I've witnessed in my career."
Philippe Caturegli of Seralys, who validated the exposed credentials, confirmed they could authenticate to three AWS GovCloud accounts at high privilege level — including access to CISA's internal code repository. His assessment was chilling:
"Backdoor some software packages and every time they build something new they deploy your backdoor left and right."
The repository was taken down after KrebsOnSecurity and Seralys notified CISA. The exposed AWS keys — inexplicably — remained valid for another 48 hours after takedown.
Congress wants answers. House Homeland Democrats are requesting a full briefing. CISA says there's "no indication that any sensitive data was compromised."
Which is exactly what you say when you don't yet know what you don't know.
Oh — and one more thing. CISA is currently operating with nearly a third less staff than it had at the start of 2025 following rounds of buyouts, early retirements and forced resignations.
You get what you pay for.
Source
Editorial Note: The researcher who found this thought it was a honeypot. That's how bad it was. The agency that publishes guidance on secrets management had plaintext passwords in a public spreadsheet and manually disabled the tool designed to prevent exactly that. This isn't a funding problem or a staffing problem — though both are real. This is a culture problem. And culture problems don't get fixed with a briefing.
If the people guarding the castle can't guard their own keys — who's guarding yours?
Headlines
May 22, 2026
Microsoft dismantled Fox Tempest — a service that abused legitimate Azure code-signing certificates to make ransomware look like trusted software. This wasn't brute force. This was identity theft at the infrastructure level.
May 22, 2026
If your users aren't protected by more than a password right now, this headline is about you.
May 22, 2026
A new macOS infostealer called SHub Reaper is spoofing Apple, Google and Microsoft prompts to steal passwords, crypto wallets and business files from endpoints that have spent years assuming they were untouchable. The era of "Macs don't get viruses" didn't just end — it's being actively exploited.
Editorial
What happens when the lifeguard can’t swim?

Giphy
This week's theme isn't complicated.
The agency responsible for America's cyber defenses left plaintext passwords in a public GitHub repository — in a file called "importantAWStokens" — while operating with a third less staff than it had eighteen months ago. Microsoft had to dismantle a service that was laundering malware through legitimate code-signing certificates. Thirty five thousand users across twenty six countries had their credentials stolen while the White House delayed the executive order designed to address exactly that kind of escalating threat.
The pattern is the same one we saw last week. And the week before that.
Attackers aren't just breaking your locks anymore. They're using your keys.
Trusted update mechanisms. Legitimate certificates. Real credentials from real accounts. The infrastructure of trust itself has become the attack surface — and the institutions responsible for defending it are underfunded, understaffed and apparently syncing sensitive government files to personal GitHub repositories like it's 2012.
Here's the uncomfortable truth nobody in a government briefing room wants to say out loud:
You cannot defend what you don't respect.
The organizations winning this fight aren't waiting for a CISA advisory or a White House executive order. They're building security cultures where secrets management is non-negotiable, where trust is continuously verified — not assumed — and where professional, dedicated people are responsible for staying one step ahead so the business doesn't have to find out the hard way.
The lifeguard can’t swim.
The editorial opinions expressed here are those of the author and represent the view from the cheap seats — which, it turns out, have an excellent view of the dumpster fire.
Other News From Around The Web
This Week in Tech, AI & Cybersecurity
Curated highlights • May 22, 2026
🚨 Top Story: The Cyber Agency Had a Credential Leak
CISA contractor exposes sensitive credentials in public GitHub repository
CISA is investigating after a contractor reportedly exposed AWS GovCloud credentials, internal files, passwords, and cloud keys in a publicly accessible GitHub repository. For an agency responsible for national cyber defense, the incident is a sharp reminder that secrets management failures remain one of the most preventable—and damaging—security risks.
Source: TechRepublic | Thu, May 21
House Homeland Democrats request CISA briefing after credential exposure report
Lawmakers are seeking answers after reporting indicated that CISA-related credentials and data were publicly exposed through a contractor-linked GitHub repository.
Source: Nextgov | Wed, May 20
TechCrunch: CISA exposed passwords and cloud keys to the open web
Additional reporting says plaintext passwords were left in a spreadsheet uploaded to a public GitHub repository, highlighting the risk of basic operational lapses in sensitive environments.
Source: TechCrunch | Tue, May 19
Cybercrime Crackdowns & Disrupted Infrastructure
Microsoft disrupts malware-signing service used by ransomware gangs
Microsoft took action against Fox Tempest, a service accused of abusing Azure certificates to make ransomware and malware appear like trusted software. This matters because code-signing abuse erodes one of the core trust signals defenders rely on.
Source: TechRepublic | Thu, May 21
Microsoft disrupts cybercrime service disguising malware as legitimate software
The operation reportedly affected multiple industry sectors in the U.S. and abroad, showing how “trust laundering” services can enable broad downstream attacks.
Source: Nextgov | Tue, May 19
Law enforcement shuts down VPN service used by ransomware gangs
Authorities dismantled First VPN, a service allegedly used by more than two dozen ransomware gangs to hide their operations. Europol reportedly notified users that they had been identified—turning an anonymity service into a law enforcement intelligence win.
Source: TechCrunch | Thu, May 21
Breaches, Extortion & Credential Theft
Grafana rejects ransom demand after GitHub breach
Grafana refused to pay after attackers allegedly stole codebase data through a GitHub breach. The group reportedly relied on stolen credentials, phishing, and social engineering rather than traditional encryption-based ransomware.
Source: TechRepublic | Tue, May 19
Breach roundup: credential theft hits 35,000 users across 26 countries
This week’s breach news highlights a Microsoft-warning credential theft campaign targeting 35,000 users across 13,000 organizations in 26 countries.
Source: Kaseya | Wed, May 20
Mac users targeted by SHub Reaper infostealer
A new macOS malware campaign spoofs Apple, Google, and Microsoft prompts to steal passwords, crypto data, and business files—another sign that Mac endpoints are increasingly in scope for enterprise attackers.
Source: TechRepublic | Tue, May 19
AI Policy: National Security Reviews Delayed
White House postpones AI executive order on model testing
The expected order would establish a voluntary framework for government review of AI models before release, but signing was delayed.
Source: Nextgov | Thu, May 21
Trump delays AI security executive order over language concerns
The delayed order would have required pre-release government security reviews of AI models. The delay underscores tension between security oversight and fears of slowing AI development.
Source: TechCrunch | Thu, May 21
NSA may receive role in voluntary AI model testing
The anticipated executive order could give the NSA a role in reviewing advanced AI models, particularly cyber-focused systems such as Anthropic’s Mythos.
Source: Nextgov | Wed, May 20
Endpoint Defense, MSSPs & the CISO Gap
Managed EDR: what businesses and MSPs need to know
Kaseya breaks down managed endpoint detection and response as a service model for businesses that need expert monitoring but lack internal security capacity.
Source: Kaseya | Thu, May 21
MSSPs filling the CISO gap for underserved SMBs
Cybercrime Magazine’s 2026 CISO report coverage highlights how managed security providers are stepping in where small and midsize businesses cannot justify or afford a full-time CISO.
Source: Cybercrime Magazine | Wed, May 20
Hardware & Workplace Tech
Surface Laptop adds built-in privacy filter for shoulder-surfing protection
Microsoft’s newest Surface for Business includes a built-in privacy filter to reduce over-the-shoulder screen peeking—an old physical security problem getting a modern hardware response.
Source: ExtremeTech | Thu, May 21
The Bottom Line
This week's story isn't about sophisticated hackers. It's about basic trust — who has it, who abuses it, and who's asleep at the wheel while it quietly collapses.
CISA left the keys on the internet. Microsoft caught criminals wearing legitimate disguises. Thirty five thousand people lost their credentials while Washington debated paperwork.
The attackers don't need to be smarter than you.
They just need you to keep assuming someone else is handling it.
Are you sure someone is?




