# CISA secrets left sitting on GitHub. Page: https://stenobird.com/podcast/cyberwire-daily-454880/cisa-secrets-left-sitting-on-github Text version: https://stenobird.com/podcast/cyberwire-daily-454880/cisa-secrets-left-sitting-on-github.md Podcast: [CyberWire Daily](https://stenobird.com/podcast/cyberwire-daily-454880) Published: 2026-05-19T20:30:00+00:00 Episode link: https://www.thecyberwire.com/podcasts/daily-podcast/2555/notes Audio file: https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW6098411602.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/cisa-secrets-left-sitting-on-github Duration seconds: 1582 ## Resource A CISA contractor leaks GovCloud credentials on GitHub. INTERPOL cracks down on phishing infrastructure across the Middle East and North Africa. Microsoft patches a critical Authenticator flaw, while Poland moves officials off Signal after targeted phishing campaigns. A stealthier SHub macOS infostealer emerges. Universal Robots fixes a critical vulnerability. A Dark Web marketplace dumps millions of stolen payment cards. Echo Protocol loses $76 million in a synthetic Bitcoin breach. Our guest is Chris Cochran, Field CISO & Vice President of AI Security at SANS, discussing their AI maturity model. Nathan Detroit rolls malware snake eyes. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Chris Cochran, Field CISO & Vice President of AI Security at SANS, discussing their SANS AI Security Maturity Model™. Selected Reading CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) INTERPOL Operation Ramz: 201 Apprehended in MENA Cybercrime Disruption (TechNadu) Microsoft Patches Critical Token Theft Vulnerability in Authenticator App (Beyond Machines) Poland shifts away from Signal following cyberattacks on officials’ accounts (Security Affairs) SHub macOS infostealer variant spoofs Apple security updates (Bleeping Computer) Critical Vulnerability Exposes Industrial Robot Fleets to Hacking (SecurityWeek) B1ack's Stash Releases 4.6 Million Stolen Credit Cards for Free (SOC Radar) Echo Protocol Hit by $76M eBTC Minting Exploit (SOC Radar) Chanhassen Dinner Theatres cancels more Guys and Dolls performances due to illness and cyberattack (KARE11) Sh… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/cisa-secrets-left-sitting-on-github/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberwire-daily-454880/cisa-secrets-left-sitting-on-github.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.