27 March 2023

Parts of Twitter’s source code reportedly leaked online


Parts of Twitter’s source code reportedly leaked online

Some portions of Twitter’s source code have been leaked on GitHub, according to court filings published on Friday.

Twitter asked GitHub, a collaborative programming network, to take down the offending code citing copyright infringement. GitHub complied and took down the code that day. It was unclear how long the leaked code had been online, but it appeared to have been public for at least several months, The New York Times notes.

The company also asked the court to identify the alleged infringer who posted Twitter’s source code GitHub without Twitter’s authorization and any individuals who downloaded it.

Citing sources within the company familiar with the matter, the NYT reported that Twitter executives suspect that the leak was the work of an employee who left the company within last year.

According to the sources, the executives were only recently made aware of the source code leak, and one concern is that the code contains security vulnerabilities that hackers could abuse to steal user data or take down the social media site.

Earlier this month, Elon Musk, who bought Twitter last October for $44 billion, announced that he would make the code that Twitter uses to recommend tweets publicly available on March 31, so that it could be reviewed by anyone and scrutinized for possible security issues.


Back to the list

Latest Posts

Cyber Security Week in Review: August 30, 2024

Cyber Security Week in Review: August 30, 2024

Google addresses yet another Chrome zero-day, Russian hackers caught using commercial spyware to compromise victims, and more.
30 August 2024
US offers $2.5M reward for information on hacker linked to Angler exploit kit

US offers $2.5M reward for information on hacker linked to Angler exploit kit

Volodymyr Kadariya is believed to be a key player in a major international hacking operation.
29 August 2024
South Korean cyber espionage group exploits zero-day in WPS Office to install SpyGlace backdoor

South Korean cyber espionage group exploits zero-day in WPS Office to install SpyGlace backdoor

The vulnerability, tracked as CVE-2024-7262, has been exploited since at least February 2024.
29 August 2024