:

CHECKMARX CONFIRMS LAPSUS$ LEAKED STOLEN GITHUB DATA

DEV DESK1 MIN READ
TUE, APR 28, 2026

■ AI-SUMMARIZED FROM 2 SOURCES BELOW

Application security firm Checkmarx has confirmed that the LAPSUS$ threat group leaked sensitive data stolen from its private GitHub repository. The breach exposes internal code and development assets.

Checkmarx disclosed the data leak after LAPSUS$ published stolen materials online. The threat group, known for high-profile breaches targeting major tech and financial firms, accessed the company's private GitHub repositories containing proprietary source code and security tools. The incident marks another successful attack against a cybersecurity vendor, a pattern LAPSUS$ has demonstrated repeatedly. The group typically combines theft with extortion, threatening to release data unless ransom demands are met. Checkmarx has not disclosed the full scope of compromised data or confirmed ransom demands. The company has begun notifying affected customers and partners. Separately, GitHub announced it will begin charging Copilot users based on actual AI usage rather than flat-rate subscriptions, citing escalating inference costs from heavy users. The pricing shift reflects growing demand for AI coding tools and the computational expenses required to support them at scale.

■ SOURCES

Bleeping ComputerArs Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A popular period tracking application has been transmitting user menstrual data to Meta, raising fresh concerns about reproductive health privacy and third-party data sharing practices.

JUST NOWIndustry Desk

Security researchers at AISLE discovered 38 vulnerabilities in OpenEMR, widely-used healthcare software serving approximately 100,000 medical providers. The flaws range from critical to moderate severity and could expose patient data and system integrity.

JUST NOWAI Desk

The FTC reported that Americans lost $2.1 billion to social media scams in 2025, with Facebook accounting for $794 million—more than any other platform.

JUST NOWIndustry Desk

Greg Hogan, affiliated with Elon Musk's Department of Government Efficiency, now oversees Login.gov, the federal government's identity verification service. The move comes as officials plan to integrate driver's license and passport data into the platform.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.