Skip to content

Checkmarx

Disclosed Apr 26, 20265 months agoConfirmed

Official notice

Checkmarx confirms LAPSUS$ leak of GitHub data after Trivy-linked compromise

Application security firm Checkmarx said attackers used credentials from the Trivy supply-chain attack to access a private GitHub repository, pushed malicious KICS Docker images and extensions, and leaked about 96 GB via LAPSUS$. It said no customer data was stored there.

What is known

People affectedNot stated in the sources we have
DisclosedApr 26, 2026
DiscoveredMar 23, 2026
AttackSupply chain
Data exposedCredentials and tokens, API keys, Source code
SectorTech · IL
StatusConfirmed
Part ofTrivy (2026)

Sources

Source
Checkmarx security update April 26checkmarx.com · Official notice
Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub datableepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalApr 26

Same campaign

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Checkmarx

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.