Inside the CISA GitHub leak at Shard
A public GitHub repository called "Private-CISA" sat online from November 2025 to May 2026. 844 MB of plain-text passwords, AWS tokens and Entra ID SAML certificates. Some were still valid when we found them.
Guillaume Valadon found it, reported it, and it was offline 26 hours later. He wrote it up here: How we got a CISA GitHub leak taken down in under a day.
On 28 October he walks through it in person, at the top of The Shard, over a gourmet lunch.
This is a working session, not a pitch
Two hours, three short talks, a nice gourmet lunch and a room capped at 30. You come for the breakdown of a real incident and leave with things you can check in your own estate on Thursday morning.
Introduction talk on the State of secret security from Billy Michael - Head of DevOps and Developer Experience UKI at Global Logic
Why one repository is the small version of the problem
Supply chain attackers stopped going after your code. They go after your credentials.
The Shai-Hulud 2.0 campaign harvested 33,185 unique secrets into 20,649 exfiltration repositories. 3,760 were still valid on analysis. GitHub tokens, package publishing keys, SSH keys, cloud credentials. Not taken from production servers. Taken from developer machines and CI runners, where years of access quietly accumulate.
That is the credential layer. It runs underneath your repositories, your pipelines, your container images and your developers' laptops, and almost nobody has a map of it.
Who this is for
CISOs, AppSec leads and DevSecOps leaders at UK organisations running 200 or more developers.
If you own the answer to "how many valid credentials are loose in our estate right now", this is your room. We cap it at 30 and approve registrations one by one, so the discussion stays useful.
Agenda
To come
What you take back to your team
The places credentials hide that most AppSec programmes never scan, container images included
A supply chain risk story you can take to your board without using the word "posture"
Two or three peers in the same seat as you, with their numbers in your phone
Practical
Cost: Free Gourmet Lunch included.
Dress: Whatever you wore to work.
Registration is approved manually. Add your work email and a mobile number so we can send you the room details on the morning.
About GitGuardian
GitGuardian secures the credential layer. We find hardcoded credentials wherever they end up, in source code, CI/CD pipelines, container images, internal wikis and developer machines, then help teams revoke and rotate them before an attacker uses them.
We are the number one security app on the GitHub Marketplace, we scan more than 2 billion commits a year, and over 600,000 developers use us. Around 10% of our customers are Fortune 500 companies.
We work with security and platform teams at organisations where the developer count runs into the hundreds or thousands, and where credentials are spread across more systems than anyone can track by hand.