vibe code go brrrrrrr
EDIT: wow it’s far worse, it was a single contractor that decided that his convenience was above any and all security recommendations ever written. Pure. Genius!
Only the best people
You know what’s ironic? FedRAMP rules dictate that Thou Must Scan Thy Repos for Secrets (tokens, passwords, etc)
GitHub, ButrBucket, etc all have this out of the box for enterprise customers
Contractor, eh?
How much do you wanna bet he has close personal ties to the trump family and zero cybersecurity experience?
Six months of exposure.
There is zero chance that the CISA systems have not been comprehensively breeched by every foreign adversary.
Good thing Trump cut 1/4 of their workforce last year. It’s really paying dividends for Putin.

that chain saw is not at the correct height
It’s only…what, about half a metre too high ?
It doesn’t seem to have kickback brake, so it kinda is. It just should be running on full speed and hit something on the tip.
Bye Elon!
his peepee already no worky.
Breached? But we left the keys in the ignition and the door was wide open. We could have, you know, tried.
reminds me of when i lived in nashville and there had to be news bulletins reminding people to not leave firearms in their cars, as they were getting stolen.
For a moment, I chose to imagine the danger was that your unattended firearm would steal your unattended car.
that’s a new model s&w lol.
jesus christ
This regime has caused so much damage to our national security, much of which we won’t discover for years or decades. The Russians and Chinese (and literally anyone else) are probably fully infiltrated into our entire system in every aspect. SO fucking incompetent and corrupt.
We’re barely even trying with the massive cuts to cyber security. It’s almost the exact playbook you would use if leadership were actively hostile.
Trump and co are actively hostile to the US government though. There have been entire books written about how compromised he is. He’s the perfect insider threat example: in debt to foreign powers, selfish and looking to make personal money, lies about his dealings, easily temptable with honeypot women (and Epstein girls, fucking sick), no allegiance or any form of duty to country or anything bigger than himself because he’s a massive nihilist narcissist.
Really really scary times for anyone in America.
Don’t worry, soon the folks in charge will come to the inevitable conclusion that the government systems are all compromised, so clearly the only solution is to privatise them and have thevNSA run by Palantir.
you joke… but that’s literally the plan. Thiel, Musk, Andreeson, Horowitz, and the rest of the Yarvinites are trying to consume as much of the government and state power as possible.
See, that’s the thing. I always grew up with the phrase “Don’t blame on malice what can be explained by incompetence”.
But at a certain point, IS it incompetence anymore??? At this point it’s starting to feel very very deliberate.
In this case it is both malice and incompetence acting together to create the worst possible outcomes.
They are hostile, their mission is to destroy us
We’re also creating generations of new enemies and potential “terrorists”.
And Democrats will inevitably be blamed when they attack us in the future.
I think we’re headed towards a Troubles type scenario. Like a decade or more of stochastic terrorism, some organized groups, lots of violent suppression by the government, and further corporate capture of the state. I guess that’s just the fascist end goal.
Here’s a link to the Krebs on Security article that Gizmodo used as a source: https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
GitHub gets autoscanned by thousands of malicious actors for keys and credentials on every commit, including the comments lol.
The fact that CISA themselves never saw an automated breach attempt only minutes after pushing to github is the more interesting story here.
Either the contractor is so incompetent that they didn’t have any logging set up and the breach went completely unnoticed for 6 months.
Or this really is some fat honeypot that they won’t admit is a honeypot because they’ve been using it to watch or bait APTs.
Currently, there is no indication that any sensitive data was compromised as a result of this incident
This is literally impossible unless it really was a honeypot. You can demo this yourself in real time. Make a throwaway cloud account on your favorite provider, commit the cloud auth token into a repo, and you will see an automated bot login within minutes.
Commiting any secrets to a public repo should just be considered auto compromised because of how potent it is.
That stuff ususlly gets exposed via poor CI/CD permissions where credentials are required, but straight up file commit is like publicly announcing exactly where you left your house keys lol.
Can confirm, with one of my first discord bots I accidentally committed the token and within a day someone logged in and announced in every server it was in that the token was compromised
Based greyhat
My first thought was that sounds intentional…
Straight up file committing is like making a copy of your house keys for anyone who can see you at that moment and all moments thereafter lol
“Leak”
That’s a fire hydrant strength jet of piss.
Why are people acting surprised? This is exactly what DOGE intended to do.
This is like being surprised someone died in a fatal car accident after their wheel came off on the highway because they handed a wheel and lug nuts to a 10 year old and said “put this on”
10 yr olds are allowed to work on cybertrucks?
Who knows what happens in Chinese factories?
Its dumb shit like this that reassures me that AI will definitely take over cyber security jobs and make shit even LESS secure than everything already is.
the few who will stay sharp will have endless job security
You’ll have a history of pushing back so they’ll regard you as a potential problem employee.
good luck with picking and choosing after brainrot as a service does irreparable damage
Is this the same cybersecurity agency that fired all its professionals to replace them with sycophants?
Passwords were stored as plain text in a public GitHub repository.
Governments and corporations are made up of people, and when people see other people treated like garbage, they tend to become less diligent in their own duties, and loyalty is thrown out the window. Revenge is never off the table.
Also, even if you get rid of everybody so that no witnesses of your injustice remain, you’ve filled those positions with neophytes, who are incompetent for quite some time (at least).
that’s the notorious “double whammy catch-22 fuck around find out” phenomenon, a TRIPLE THREAT
deleted by creator
Wow. Wowowowowowowowow. Wow.
It was super easy! Barely an inconvenience!
This is the only logical reaction, honestly 🤣
OMG
…but remember, everything needs to be written in memory safe languages to stop security breaches.
“I might get mugged in a dark alley, so why should I bother locking my door at home?”
Security breeches stop your phone falling out while riding a horse.















