---
title: "America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames"
url: https://daily.dev/posts/america-s-top-cyber-defense-agency-left-a-github-repo-open-with-with-passwords-keys-tokens-and-i-bmprl7jsh
source_url: https://www.theregister.com/security/2026/05/19/americas-top-cyber-defense-agency-left-a-github-repo-open-with-with-passwords-keys-tokens-and-incredibly-obvious-filenames/5242915
type: article
source: "The Register"
published: 2026-05-19T17:53:21.418Z
updated: 2026-05-22T14:02:09.692Z
tags: ["cyber", "github"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames

**[The Register](https://daily.dev/sources/theregister)** · 5 min read · 0 upvotes · 0 comments

## Summary

CISA, the US government's top cybersecurity agency, left a public GitHub repository containing sensitive credentials including passwords, API keys, and tokens — with file names like 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv' making the contents immediately obvious to anyone who found them.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/security/2026/05/19/americas-top-cyber-defense-agency-left-a-github-repo-open-with-with-passwords-keys-tokens-and-incredibly-obvious-filenames/5242915>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#github](https://daily.dev/tags/github)

[View this post on daily.dev](https://daily.dev/posts/america-s-top-cyber-defense-agency-left-a-github-repo-open-with-with-passwords-keys-tokens-and-i-bmprl7jsh)
