GitHub has been ordered by a court to reveal the identity of the individual who leaked the Twitter source code. This leak was made last year in July, and the court has been investigating the matter since then.
The leaker uploaded a file to GitHub containing the source code for the Twitter app, and it was available for download for several hours before it was removed. The file was then spread across various social media platforms.
Twitter immediately began an investigation into the matter, and it was discovered that the code had been accessed by an employee who had worked at Twitter previously. The former employee had then shared the code with the leaker.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the AI risk, regulation, abuse, and enterprise security changes this article could not cover.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Twitter filed a lawsuit against the leaker, and the court issued an order for GitHub to reveal the identity of the person responsible for uploading the file. GitHub initially refused to comply with the order, arguing that it would violate user privacy, but eventually relented after the court threatened to hold them in contempt.
The identity of the leaker has not been revealed yet, and it is unclear what consequences they will face for their actions. Twitter has stated that it takes the protection of its users’ data seriously and will continue to take legal action against anyone who tries to compromise its security.
This case serves as a reminder of the importance of protecting sensitive information and the consequences of unauthorized disclosures. Companies should take all necessary measures to secure their data and ensure employees know the risks of mishandling confidential information.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
JFrog Artifactory CVE-2026-82329: Empty Join Key, Full Admin Token, Busy Scanners
CVE-2026-82329 lets attackers forge Artifactory admin tokens via a deterministic empty join key. Mass scanning peaked near 406,000 attempts; patch fixed builds...
The 5-Minute Cyber Brief: September 14, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.