Robin’s Newsletter #414

24 May 2026. Volume 9, Issue 21
CISA credentials exposed in public repo. GitHub source code stolen. Iran wants to charge for Hormuz internet cables.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

A shorter edition this week. I hope you’re enjoying your Bank Holiday or Memorial Day, and don’t forget your towel!

Coming up

You can catch me at a few events over the coming fortnight. Come say hi if you’re around Oxford Tech Week, InfoSecurity Europe or Pulse Cyber 100 Club:

  • 28th May: Securing the AI Era: Defending Against Next‑Gen Cyber Threats, Westgate, Oxford, info/reg.
  • 2nd—4th June: InfoSecurity Europe 2026, including some Communicating Cyber: Live recordings, ExCel, London, meet for coffee.
  • 2nd June: Breakfast: The AI Cyber Threat Landscape: Why Quantifying Risk is Your Best Defence (with Tim Orchard), Canary Wharf, London, info/reg.
  • 3rd June: Breakfast: Business Cannot Take the Cyber Heat(Map) - Is it Time for Quantitative Risk Analysis? (with Niall McElroy), Canary Wharf, London, info/reg.

This week

Need to Know, 27th May 2026

  • CISA embarrassment after plaintext creds found in public repo
  • GitHub source code stolen by TeamPCP
  • Iran says it wants to charge tech companies for Hormuz data cables

Interesting stats

4x increase in bug reports to Bugcrowd over three weeks in March, with ‘most proving to be false’, as bug bounty programmes struggle to come to terms with the rise of spurious AI slop submissions LINK (HackerOne has slashed payouts by around 75% too LINK).

23-minute window between turning off a Google API key and it being rejected by all servers across its infrastructure, according to Aikido Security researchers, who were told by Google they would not fix the issue and that ”the delay due to propagation of the deletion of these keys is working as intended” LINK.

$388 million lost by US residents through cryptocurrency ‘ATM’ kiosks in 2025 LINK.

Three things

  1. CISA’s internal security posture came under the microscope this week, after the discovery of a decidedly public GitHub repository called “Private-CISA” containing a bunch of plaintext credentials, tokens, and other system information. The repository had been open for six months. A CISA spokesperson told The Register that “Currently, there is no indication that any sensitive data was compromised as a result of this incident.” The trove of sensitive secrets was maintained by an employee of government contractor Nightwing, and appeared to be used by the individual to synchronise credentials between devices. Notably, both their work and personal email addresses had access. It took CISA 24 hours to remove the repository, and some tokens continued working for 48 hours. Internal system passwords sometimes used the platform name and year, hardly keeping up with their own guidance. It’ll be embarrassing for America’s top cyber agency, where morale is already low following months of staff and budget cuts under the current government administration.

  2. GitHub also suffered a breach this week, with cybercrime gang TeamPCP claiming responsibility for stealing data from around 3,800 repositories. GitHub says the claims were “directionally consistent” with their own investigation into the unauthorised access. It seems to be limited to platform source code and tooling. GitHub, which is owner by Microsoft, says that no customer data was affected, and that the breach started when an employee’s device was infected with a compromised VS Code extension. While I appreciate that number of repos is not the best metric to measure the scale by, I do think it’s interesting that a single employee had access to 3,800 different repos. If you’re going to slide things up, apply some boundaries to those slides.

  3. Iran says that it wants tech companies to pay for the subsea Internet cables running through the Straight of Hormuz. The cables mainly connect Gulf nations with the rest of the world. Plans appear to revolve around a licence fee and asserting the right to repair and maintain the cables. The majority of routes pass through Omani territorial waters. Still, with shipping through the Strait at a standstill, new cable-laying projects and maintenance work have been halted since the US and Israel launched airstrikes on Iran in February 2026, leading to the closure of the important waterway.

Plus…

And finally

  • Google accidentally published details, including proof-of-concept code, of a vulnerability in the Chromium browser codebase. The unfixed issue has been bouncing around the developer teams for a staggering 42 months. It’s an issue in the Browser Fetch API, used by sites to download large files in the background, but which can be used to “visit malicious sites, provide anonymous proxy browsing by others, enable proxied DDoS attacks, and monitor user activity,” per Ars Technica’s Dan Goodin. Discussion on the Chromium bug tracker site shows the devs don’t believe the issue is being exploited. I can’t see it staying that way for long. The issue can persist across browser restarts, and the user just needs to visit a compromised website.
Robin
  Cybersecurity and Infrastructure Agency (CISA) GitHub TeamPCP Iran Subsea Cables Geopolitics