No attacker needed to break through CISA’s defenses. The reported exposure began with an authorized user, an approved exception, and an ordinary work task.

Between mid-July and early August 2025, acting CISA Director Madhu Gottumukkala reportedly uploaded at least four sensitive government documents to the public version of ChatGPT, including contracting material marked for official use only. DHS cybersecurity systems flagged the activity in early August, prompting an internal review. CISA later said Gottumukkala had permission to use ChatGPT with DHS controls in place and described that use as short-term and limited.

The episode exposes a…

Read the full article at TECHREPUBLIC.COM