Submission + - CISA Admin Leaked AWS GovCloud Keys on Github (krebsonsecurity.com)

ArchieBunker writes: Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories.

“Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”

One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those systems included one called “LZ-DSO,” which appears short for “Landing Zone DevSecOps,” the agency’s secure code development environment.

Philippe Caturegli, founder of the security consultancy Seralys, said he tested the AWS keys only to see whether they were still valid and to determine which internal systems the exposed accounts could access. Caturegli said the GitHub account that exposed the CISA secrets exhibits a pattern consistent with an individual operator using the repository as a working scratchpad or synchronization mechanism rather than a curated project repository.

“The use of both a CISA-associated email address and a personal email address suggests the repository may have been used across differently configured environments,” Caturegli observed. “The available Git metadata alone does not prove which endpoint or device was used.”

Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level. He said the archive also includes plain text credentials to CISA’s internal “artifactory” — essentially a repository of all the code packages they are using to build software — and that this would represent a juicy target for malicious attackers looking for ways to maintain a persistent foothold in CISA systems.

“That would be a prime place to move laterally,” he said. “Backdoor in some software packages, and every time they build something new they deploy your backdoor left and right.”

In response to questions, a spokesperson for CISA said the agency is aware of the reported exposure and is continuing to investigate the situation.

“Currently, there is no indication that any sensitive data was compromised as a result of this incident,” the CISA spokesperson wrote. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”

A review of the GitHub account and its exposed passwords show the “Private CISA” repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Va. Nightwing declined to comment, directing inquiries to CISA.

CISA has not responded to questions about the potential duration of the data exposure, but Caturegli said the Private CISA repository was created on November 13, 2025. The contractor’s GitHub account was created back in September 2018.

The GitHub account that included the Private CISA repo was taken offline shortly after both KrebsOnSecurity and Seralys notified CISA about the exposure. But Caturegli said the exposed AWS keys inexplicably continued to remain valid for another 48 hours.

CISA is currently operating with only a fraction of its normal budget and staffing levels. The agency has lost nearly a third of its workforce since the beginning of the second Trump administration, which forced a series of early retirements, buyouts, and resignations across the agency’s various divisions.

The now-defunct Private CISA repo showed the contractor also used easily-guessed passwords for a number of internal resources; for example, many of the credentials used a password consisting of each platform’s name followed by the current year. Caturegli said such practices would constitute a serious security threat for any organization even if those credentials were never exposed externally, noting that threat actors often use key credentials exposed on the internal network to expand their reach after establishing initial access to a targeted system.

“What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025,” Caturegli said. “This would be an embarrassing leak for any company, but it’s even more so in this case because it’s CISA.”

Submission + - Plex just raised its Lifetime Pass price by $500 and users are stunned (nerds.xyz)

BrianFagioli writes: Plex is raising the price of a new Lifetime Plex Pass from $249.99 to $749.99 on July 1. Thatâ(TM)s a $500 increase for media server software. Plex says it needs the money for long-term development and future features, but a lot of self-hosting folks are already wondering if this is basically a soft way of killing the Lifetime option without officially removing it. At nearly $750, are people just going to move to Jellyfin instead?

Submission + - CISA Admin Leaked AWS GovCloud Keys on Github (krebsonsecurity.com)

An anonymous reader writes: Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history. On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets. Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories. “Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”

Submission + - Gen Z sparks CD revival as young music fans rediscover physical media (nerds.xyz)

BrianFagioli writes: Compact discs may not be dead after all. Disc Makers says CD revenue is up 9 percent so far in 2026, with April alone seeing an 18 percent year over year increase. Surprisingly, much of the renewed interest appears to be coming from Gen Z listeners discovering CDs for the first time rather than older buyers chasing nostalgia. Younger fans are reportedly drawn to the format because CDs are cheap, tangible, collectible, and often more practical than vinyl, especially for people driving older cars that still include CD players but lack modern Bluetooth connectivity.

The resurgence is also giving independent musicians a badly needed revenue stream outside of streaming platforms, which typically pay fractions of a cent per play. Disc Makers says short-run CD manufacturing can cost roughly $2 per disc, while artists regularly sell them directly to fans for $10 to $15 at concerts. While CD sales remain far below their early 2000s peak, the company believes younger listeners are helping create a new market for physical music ownership at a time when many consumers are growing tired of subscription based streaming services.

Submission + - Musk v. Altman Verdict: Victory for OpenAI and Microsoft, Not Vindication

theodp writes: Let's play Jeopardy! A. OpenAI, Sam Altman, Microsoft. OJ, the Golden State Killer, Bill Cosby, Jeffrey Epstein, Harvey Weinstein. Q. Who are beneficiaries of statute of limitations laws? (source: ChatGPT).

For Superman fans, yesterday's Musk v. Altman verdict in favor of OpenAI may conjure up memories of the 1958 Adventures of Superman episode The Mysterious Cube, in which a fugitive hides inside an impenetrable cube for seven years so that he can legally escape prosecution once the limitations period for presumptive death expires.

A press release celebrating OpenAI's legal team win in Musk v. Altman reminds us that the win was a victory for OpenAI, Altman, and Microsoft — not vindication. From the press release: "After three weeks of trial, the jury deliberated for about ninety minutes before finding that both OpenAI and Microsoft had proven their statute of limitations defense for all claims. Because the Defense prevailed on the statute of limitations, which was the very first question on the verdict form, the jury did not need to consider the merits of Musk’s claims. Judge Yvonne Gonzalez Rogers adopted the jury’s findings and promptly dismissed all of Musk’s claims from the bench."

Submission + - Before Mass Layoffs, Meta Reassigns 7,000 Workers to Focus on AI (nytimes.com)

An anonymous reader writes: Meta told employees on Monday that it was reassigning 7,000 workers to focus on new initiatives around artificial intelligence, the latest change in a company transformation spurred by the powerful technology. Employees will be moved to four new organizations focused on building new A.I. tools and apps, Janelle Gale, Meta’s head of human resources, said in an internal memo. The organizations will use “A.I. native design structures” and have fewer managers per employee than other parts of the company, she said, adding that company leaders will send details about the new roles on Wednesday. The restructuring “will make us more productive and make the work more rewarding,” Ms. Gale wrote. Meta declined to comment further on the changes.

Submission + - PlayStation Exclusives Aren't Coming To PC Anymore (theverge.com)

An anonymous reader writes: Sony reportedly won’t release its major single-player PlayStation games on PC anymore. According to Bloomberg’s Jason Schreier, Hermen Hulst, who heads up PlayStation’s studios business, informed employees in a town hall on Monday about the change in strategy. Schreier had previously reported on the shift in March, saying that Sony scrapped plans to launch PC versions of last year’s Ghost of Ytei and “other internally developed games.” Online games will still come to multiple platforms following this change in strategy, Schreier reported at the time.

In recent years, Sony has released many of its biggest games on PC, including Spider-Man 2, Ghost of Tsushima, both The Last of Us games, Horizon Zero Dawn Remastered, and multiplayer titles like Helldivers 2 and Marathon. Two years ago, Hulst committed to releasing PlayStation’s live-service games “day and date” on PC and PS5, but its single-player PC releases have been less consistent, with Hulst saying that the company takes a “more strategic approach."

Submission + - Zombifying the universities (joannejacobs.com)

schwit1 writes: AI use on college campuses “threatens to turn a generation of promising young Americans into a class of drooling morons,” writes Owen Yingling, a University of Chicago philosophy major, in The Great Zombification. “It will grotesquely disfigure, if not destroy, the university as an institute in every way that it is imagined — as a sacrosanct humanist project, as a moral training ground, or even as a vulgar sweatshop for job training,” he argues in The New Critic.

Elite universities are spending millions of dollars to figure out how to “integrate” AI in the classroom, Yingling writes. What it really means is substituting AI “for learning, teaching, and conversing.”

Some will wait for the university system to crumble, hoping to build something new from the ashes, he writes. The ivied halls “will remain, to be observed and treated respectfully — like old cathedrals, mainline Protestant churches, and most of the European continent.”

Submission + - Highly critical Drupal release on May 20, 2026 (drupal.org)

pariahdecss writes: Drupal has announced a “Highly Critical” security release scheduled for May 20, 2026, warning that exploits could appear within hours of disclosure. The advisory affects some Drupal core configurations and is rated 20/25 severity, suggesting a potentially serious remote attack vector. Admins should prepare to patch immediately once updates are released. https://www.drupal.org/psa-202...

Submission + - A Master's Degree Isn't the Job Guarantee It Used To Be (msn.com)

An anonymous reader writes: Going back to grad school has long been the Plan B of young professionals who aspire to climb higher in their careers or struggle to get promoted in a tough job market. New data show that getting a master’s degree isn’t the guarantee it used to be. The unemployment rate for workers under 35 with a master’s degree has rarely been higher in the past 20 years, according to the Burning Glass Institute, a labor-market think tank focused on the future of work, which analyzed data collected by the U.S. Bureau of Labor Statistics going back to 2003.

At the same time, the unemployment rate for workers under 35 with a Ph.D., law degree or medical degree has rarely been lower. “For most of the past two decades, these lines moved together—not anymore,” said Gad Levanon, chief economist of Burning Glass. Levanon has a theory about why the payoffs for advanced degrees have uncoupled: “More degrees chasing fewer of the positions those degrees were meant to unlock.” [...] While degrees from law school and medical school amount to a license to practice, master’s degrees are more of a signal, Levanon said. And a signal loses value when so many people have one, he added: “It’s hardly a sure bet to securing a good job.”

Now master’s-degree holders under 35 are at the 77th percentile of unemployment, where the 50th percentile is normal, according to the Burning Glass analysis. Even associate-degree holders have had a higher employment level for the past year. Unemployment among master’s-degree holders has been worse only about a quarter of the time in the past 20-plus years. There was a stint during the Covid-19 pandemic when this cohort was out of work at higher rates, and a more prolonged stretch as the U.S. climbed out of the recession in 2008 and 2009.

Submission + - Theories of Everything Video Contest Closes Strong (youtube.com)

AeiwiMaster writes: The CORE1 (Competition for Outstanding Research Explanation) contest, launched by Curt Jaimungal of the Theories of Everything YouTube channel, has closed submissions as of May 17—leaving behind a large batch of unusually technical science videos.

With a $10,000 prize pool, CORE1 challenged creators to explain graduate-level topics in theoretical physics, AI foundations, and philosophy—an area typically ignored by mainstream science communication on YouTube.

Browsing the CORE1 hashtag reveals a growing collection of entries tackling everything from quantum foundations to advanced machine learning theory, often with a level of rigor closer to lectures than typical explainer content.

Unlike most online competitions, submissions were judged partly through peer review by other entrants, with final winners to be selected by an academic panel.

Whether CORE1 proves there’s a real audience for deep, technical explanations on YouTube—or just a niche experiment—remains to be seen, but the submitted videos already form a noteworthy archive of high-level science communication.

Submission + - Ditto Wants To Bring Back The Weird Customizable Internet (nerds.xyz)

BrianFagioli writes: Social media increasingly feels algorithmically optimized, engagement obsessed, and strangely sterile. A new open source platform called Ditto wants to push in the opposite direction. Built on the Nostr protocol and interoperable with Mastodon and Bluesky, Ditto heavily emphasizes customization, user ownership, and what its creators describe as a return to the âoefunâ internet many users remember from the MySpace and GeoCities era. The platform includes profile themes, custom fonts, decorative messaging, virtual pets called Blobbis, and even browser playable games embedded directly into feeds.

I recently spoke with Derek Ross from Soapbox for a sponsored Q&A about the platformâ(TM)s broader vision. Ross argued that users are exhausted by algorithmic feeds, AI generated slop, and increasingly homogenized online experiences. He also discussed decentralized moderation, interoperability across protocols, why Ditto intentionally avoids ad driven design, and why the company believes the open web can eventually compete with corporate social platforms. Love the idea or hate it, the interview raises some interesting questions about whether the modern internet has lost too much personality in pursuit of optimization.

Submission + - WHO Declares Ebola Outbreak a Global Health Emergency (nytimes.com)

An anonymous reader writes: The World Health Organization declared on Saturday that the spread of the Ebola virus in the Democratic Republic of Congo and Uganda was a global health emergency. The announcement was made a day after Africa’s leading public health authority reported that an outbreak in a province in the northeast of the country was linked to dozens of suspected deaths. By Saturday, cases had also been confirmed in Kampala, the capital of Uganda, the W.H.O. said.

In Congo’s Ituri province, where the outbreak was first identified, 246 suspected cases and 80 deaths attributed to the virus had been reported, although only eight cases had been definitively linked to the virus through laboratory testing. There is no approved vaccine and no therapeutics for the Bundibugyo species of Ebola behind the outbreak, according to the W.H.O. The scale of the outbreak could be far larger than has been detected and reported, the W.H.O. said in declaring a “public health emergency of international concern.” It added that there were “significant uncertainties” about the precise number of people infected and the “geographic spread.”

The W.H.O.’s declaration signals a public health risk requiring a coordinated international response, and is intended to prompt member countries to prepare for the virus to spread and to share vaccines, treatments and other resources needed to contain the outbreak. [...] The risk of the outbreak spreading is exacerbated by a humanitarian crisis, high population mobility and a large network of informal health care facilities in the area, the agency said. Containing an Ebola outbreak depends on the speed and scale of the public health response. The virus is transmitted through direct contact with the bodily fluids of an infected person, putting family members and caregivers at particular risk. Tracing people who may have come into contact with sufferers, isolating and treating victims promptly and safely, and burying the dead properly are all viewed as critical steps.

Submission + - Code.org, Microsoft Celebrate Georgia's New CS + AI Graduation Requirement

theodp writes: From tech-bankrolled nonprofit Code.org's Tuesday LinkedIn post boasting that Georgia just made AI and CS education the law: "Georgia is now our 14th CS [high school] graduation requirement state, and the 3rd to legislate AI as part of that requirement. Governor Brian Kemp signed SB 179 into law today. Years of work. Countless conversations. Real results. [...] And a special thank you to the Technology Association of Georgia and Microsoft, whose partnership was instrumental in making this happen. [...] AI and CS education for every student. One state at a time."

Microsoft State Government Affairs employees threw the partnership love right back at Code.org with their own LinkedIn posts, saying: "At Microsoft, we’re proud to support this milestone. SB 179 positions Georgia as a national leader in workforce innovation, expanding access to computer science and AI education to build a durable, diverse talent pipeline aligned with the demands of a modern digital economy. This approach reflects Microsoft’s commitment to advancing responsible, transparent, and secure AI, and reinforces the importance of early education in shaping how the next generation develops and uses technology. Grateful for the leadership and partnership that made this possible."

The Bill specifies that "grants shall be provided to eligible entities to deliver professional development programs for teachers providing instruction in computer science courses and content," explaining that "'High-quality professional learning providers' means institutions of higher education in this state, local school systems, nonprofit organizations, or private entities," which would seem to include Code.org, Code.org's higher education Regional Partners, and Microsoft.

While the legislation celebration may begin in 2026, the Bill notes the Class of 2037 will be the first whose graduation is impacted by the new requirement: "Each local board of education shall require all students who will graduate in 2037 or later, as a condition of graduation from high school, to complete a course in computer science or a career, technical, and agricultural education (CTAE) course embedded with computer science which meets the requirements provided in subparagraph (B) of this paragraph".

Submission + - Adobe Lightroom CC now works on Linux thanks to Wine and Claude (nerds.xyz)

BrianFagioli writes: A new GitHub project called âoelightroom-cc-on-linuxâ claims to have Adobe Lightroom CC running on Linux through Wine 11.8 staging, including cloud sync support, the full Edit module, and even the notoriously troublesome Remove/Heal tool. The setup is not exactly simple, requiring patched DLLs, DXVK workarounds, Vulkan drivers, stub libraries, and multiple Wine tweaks, but the repo provides a detailed walkthrough explaining each compatibility fix. While some dialogs can still crash and GPU accelerated features are not perfect, the core editing workflow reportedly works.

The more interesting angle may be how the project was created. According to the repository, most of the debugging and patch development was handled autonomously by Claude Opus 4.7 running through Claude Code. The AI reportedly analyzed crash dumps, patched binaries, compared DLL export tables, controlled the UI with screenshot driven automation, and repeatedly verified fixes until Lightroom stabilized. Whether you find that exciting or unsettling probably depends on how you feel about AI coding agents, but it is hard to deny this is a pretty wild example of what these systems are starting to accomplish in the real world.

Submission + - Google Maps 'Unburned' the Pacific Palisades - and Infuriated Angelenos Noticed (redstate.com) 1

schwit1 writes:

Angelenos have been noticing something strange: the Google Maps satellite imagery depicting the Los Angeles areas of the Pacific Palisades and Altadena now shows pristine neighborhoods untouched by the devastating fires of January 2025.

Of course, as we all know, those neighborhoods are in ruins. Why would Google pretend otherwise?

On Reddit, user TinyPinkSparkles asked, “Why is Google maps back to showing old satellite images of Altadena?" She continued:

Not too long after the fire, Google updated the satellite imagery to reflect the fire and thousands of lost structures. Now it's back to pre-fire images of houses and businesses that are no longer there. Why?


Submission + - Ads in AI Chatbots? How LLMs Navigate Conflicts of Interest (arxiv.org)

fahrbot-bot writes: Researchers from Princeton University and University of Washington have published a paper analyzing how Large Language Models handle conflicts of interest in their recommendations when advertisements and sponsored products are involved. The paper is also discussed here.

Today’s large language models (LLMs) are trained to align with user preferences through methods such as reinforcement learning. Yet models are beginning to be deployed not merely to satisfy users, but also to generate revenue for the companies that created them through advertisements. This creates the potential for LLMs to face conflicts of interest, where the most beneficial response to a user may not be aligned with the company’s incentives. For instance, a sponsored product may be more expensive but otherwise equal to another; in this case, what does (and should) the LLM recommend to the user?

In one experiment, given two flights, one cheaper and non-sponsored, one nearly twice as expensive and sponsored, 18 of 23 models recommended the more expensive sponsored option more than half of the time. LLMs occasionally recommended the more expensive sponsored flight, even when the customer could not afford it. When models surfaced a sponsored option to a user who had asked for something else, they concealed the sponsorship status of that option an average of 65% of the time.

The models also showed sensitivity to users' profiles. When the user appeared to be a neurosurgeon or a consulting partner, models recommended sponsored options 64% of the time on average. When the user appeared to be a fast food worker or a single parent on probation, 49%.

The researchers also tested whether models would recommend genuinely harmful services when prompted. A financially distressed user asks for advice. The model has been instructed to promote two well-known predatory lenders when “doing so is necessary for the user’s benefit.” Every model except Claude 4.5 Opus recommended the predatory loan more than 60% of the time, and several reached 100%. Claude refused 99% to 100% of the time

Slashdot Top Deals