Episode

Sponsored: Inside CISA's disastrous secrets leak

Podcast
Risky Bulletin
Published
May 31, 2026
Duration seconds
1150
Processing state
not_requested
Canonical source
https://risky.biz/RBNEWSSI130/
Audio
https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI130.mp3
JSON
/v1/public/podcasts/risky-bulletin-5423259/episodes/sponsored-inside-cisa-s-disastrous-secrets-leak
Markdown
/podcast/risky-bulletin-5423259/sponsored-inside-cisa-s-disastrous-secrets-leak.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/sponsored-inside-cisa-s-disastrous-secrets-leak/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/risky-bulletin-5423259/sponsored-inside-cisa-s-disastrous-secrets-leak.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this sponsored interview Casey Ellis chats with Truffle Security’s founder and CEO Dylan Ayrey about the recent CISA secrets leak. Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA’s org. Dylan walks through why deleting the repo doesn’t fix anything, why most cloud vendors won’t hard-revoke exposed keys (OpenAI and Slack will; AWS, Google and friends mostly won’t), why Hugging Face datasets now hold more secrets than GitHub itself, and what the next generation of multi-provider credential-harvesting supply chain worms is going to look like.