US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals | TechCrunch
… Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent any potential future abuse. CISA said that no customer or mission data was exposed in the incident and thanked the researcher and reporter for their help. …