Checkmarx Security Update: April 26
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要仔细阅读这篇文章。看起来这是Checkmarx公司关于供应链安全事件的最新更新。他们提到,经过第三方取证公司的调查,发现一个网络犯罪团伙将与Checkmarx相关的数据发布到了暗网上。数据可能来自他们的GitHub仓库,而这个仓库的访问权限是通过3月23日的供应链攻击获得的。 接下来,文章提到GitHub仓库和客户生产环境是分开维护的,他们通常不会在GitHub里存储客户数据。目前调查还在进行中,他们已经锁定了受影响的GitHub仓库,并承诺如果发现客户信息受到影响,会立即通知相关方。预计24小时内会有更详细的更新。 好的,现在要总结这些内容。控制在100字以内,所以需要提炼关键点:供应链安全事件、数据泄露、GitHub仓库、第三方调查、锁定了仓库、正在调查影响范围。 可能的结构:Checkmarx报告一起供应链安全事件,涉及数据泄露到暗网。调查发现数据来自其GitHub仓库,该仓库因3月23日的攻击被入侵。虽然客户数据未存放在该仓库,但已锁定访问并继续调查影响范围。 检查一下字数:大约70字左右,符合要求。 </think> Checkmarx报告一起供应链安全事件,涉及数据泄露到暗网。调查发现数据来自其GitHub仓库,该仓库因3月23日的攻击被入侵。虽然客户数据未存放在该仓库,但已锁定访问并继续调查影响范围。 2026-4-26 23:58:21 Author: checkmarx.com(查看原文) 阅读量:22 收藏

Last Updated: April 26, 2026 

New Development: GitHub Repository 
We are writing to inform you of a new development in the ongoing Checkmarx supply chain security incident. 

Our investigation, conducted with support from a leading third-party forensic firm, indicates that a cybercriminal group has published data related to Checkmarx to the dark web. Based on current evidence, we believe this data originated from Checkmarx’s GitHub repository, and that access to that repository was facilitated through the initial supply chain attack of March 23, 2026. 

Checkmarx’s GitHub repository is maintained separately from our customer production environment. As standard practice, we do not store customer data in our GitHub repository. Our forensic investigation is ongoing and we are actively working to verify the nature and scope of the posted data. 

As part of our immediate response, we have locked down access to the affected GitHub repository while the investigation continues. 

If we determine that customer information was involved in this incident, we will notify customers and all relevant parties immediately. 

We expect to share a more detailed update within 24 hours. 
 
Previous Updates 
April 23, 2026 
https://checkmarx.com/blog/checkmarx-security-update-april-22/  
March 24, 2026 
https://checkmarx.com/blog/checkmarx-security-update/ 
 
Questions and Support 
If you have questions about this incident or need assistance assessing your environment, please open a case via the Support Portal


文章来源: https://checkmarx.com/blog/checkmarx-security-update-april-26/
如有侵权请联系:admin#unsafe.sh