Submission + - Paint is already peeling in renovated Washington Reflecting Pool after 2 weeks. (cnn.com)
Tim Auerhahn, a pool infrastructure expert and the chairman of the Aquatic Council, said it’s difficult to tell from the videos what was causing the “apparent delamination.”
“A coating system can fail for several reasons, including substrate preparation, surface contamination, application conditions, adhesion issues, product selection, mechanical damage, environmental exposure, or a combination of factors,” Auerhahn said.
The larger question, he added, is whether this represents a localized issue in that part of the pool or a larger, more systemic issue with the coating. “If the coating is losing adhesion in multiple locations, that could indicate a more significant concern,” he said.
Submission + - CISA Admin Leaked AWS GovCloud Keys on Github (krebsonsecurity.com)
On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.
The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.
Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories.
“Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”
One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those systems included one called “LZ-DSO,” which appears short for “Landing Zone DevSecOps,” the agency’s secure code development environment.
Philippe Caturegli, founder of the security consultancy Seralys, said he tested the AWS keys only to see whether they were still valid and to determine which internal systems the exposed accounts could access. Caturegli said the GitHub account that exposed the CISA secrets exhibits a pattern consistent with an individual operator using the repository as a working scratchpad or synchronization mechanism rather than a curated project repository.
“The use of both a CISA-associated email address and a personal email address suggests the repository may have been used across differently configured environments,” Caturegli observed. “The available Git metadata alone does not prove which endpoint or device was used.”
Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level. He said the archive also includes plain text credentials to CISA’s internal “artifactory” — essentially a repository of all the code packages they are using to build software — and that this would represent a juicy target for malicious attackers looking for ways to maintain a persistent foothold in CISA systems.
“That would be a prime place to move laterally,” he said. “Backdoor in some software packages, and every time they build something new they deploy your backdoor left and right.”
In response to questions, a spokesperson for CISA said the agency is aware of the reported exposure and is continuing to investigate the situation.
“Currently, there is no indication that any sensitive data was compromised as a result of this incident,” the CISA spokesperson wrote. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”
A review of the GitHub account and its exposed passwords show the “Private CISA” repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Va. Nightwing declined to comment, directing inquiries to CISA.
CISA has not responded to questions about the potential duration of the data exposure, but Caturegli said the Private CISA repository was created on November 13, 2025. The contractor’s GitHub account was created back in September 2018.
The GitHub account that included the Private CISA repo was taken offline shortly after both KrebsOnSecurity and Seralys notified CISA about the exposure. But Caturegli said the exposed AWS keys inexplicably continued to remain valid for another 48 hours.
CISA is currently operating with only a fraction of its normal budget and staffing levels. The agency has lost nearly a third of its workforce since the beginning of the second Trump administration, which forced a series of early retirements, buyouts, and resignations across the agency’s various divisions.
The now-defunct Private CISA repo showed the contractor also used easily-guessed passwords for a number of internal resources; for example, many of the credentials used a password consisting of each platform’s name followed by the current year. Caturegli said such practices would constitute a serious security threat for any organization even if those credentials were never exposed externally, noting that threat actors often use key credentials exposed on the internal network to expand their reach after establishing initial access to a targeted system.
“What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025,” Caturegli said. “This would be an embarrassing leak for any company, but it’s even more so in this case because it’s CISA.”
Comment Hybrids (Score 1) 214
TFA only mentioned EVs not hybrids. Ford can't seem to build hybrid Mavericks fast enough, based on the shopping I just did for one.
Submission + - Norwegian Consumer Council Targets 'Enshittification' (forbrukerradet.no) 1
"It should be easy for consumers to make sustainable choices every day. Consumers have the right to be protected against exploitation – both financially and digitally. To ensure this, we work to provide easy access to information, enforceable rights, and sufficient redress options when something goes wrong," says the organization.
They have also released a YouTube video making light of the matter,
Comment This will only be useful... (Score 1) 42
...to humanity if they hired John Connor.
Comment Re:When to rent and when to buy (Score 1) 126
When the company has an ongoing cost - such as they have to make new content every year, then it makes sense for you to pay an ongoing cost each month.
But when the company has no mandatory ongoing cost it makes ZERO sense to pay them rent.
.
Yep, like BMW charging to use your heated seats.
Comment Re:Cord-cutting cord-cutter (Score 1) 57
That's interesting. My LG TVs don't do that, but I have never accepted their user agreement. Have you?
Mine sit behind a pair of AppleTVs with no network access of their own so their ad BS is hidden from me, and the TVs don't keep asking for a network.
Comment Re:Before anyone asks: (Score 1) 57
McNally does work with the Lock Picking Lawyer.
The key is the last word is his nom de guerre. It's not an idle word....
Comment This is as silly.... (Score 1) 42
...as Peter Gabriel naming his first three solo albums "Peter Gabriel."
Comment I'm only adding one pic to my OneDrive (Score 2) 62
Anyone remember tub girl?
Comment Re:There's a word for this process.... (Score 1) 116
...I believe it's called "enshitification."
Yes. The article writer invented it. It's literally the second line of the TFS.
Duh.
Comment There's a word for this process.... (Score 1) 116
...I believe it's called "enshitification."
Submission + - British Transport Police Decriminalize Bicycle Theft (bbc.com) 8
Commuters leave thousands of cycles on racks outside stations every day, including in specially built bike parks with CCTV. Critics say the BTP policy means those facilities are not secure and theft has effectively been decriminalised.
Any bikes stolen worth less than £200 will not be investigated, neither will car thefts if the vehicle has been left for more than two hours.
Comment Re:Simple. (Score 1) 128
Huh. Those "brain dead dipshits" built and maintain the modern world you live in.