Gyazo, the cloud-based screenshot and screen-recording platform operated by Helpfeel, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026. The attackers accessed Gyazo’s database and stole approximately 23.62 million user records. The exposed information varies by user and may include names or nicknames, email addresses, password hashes, user and device IDs, session IDs, X integration tokens, Google SSO email addresses, profile and subscription details, billing status, and usage statistics. The breach also exposed approximately 490 million image metadata records, most linked to images uploaded before January 2019. The metadata may contain image IDs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Because image IDs can potentially be used to access associated content, Gyazo temporarily disabled access to affected files. Attackers also obtained a list identifying private, and temporarily took the service offline for maintenance. Helpfeel said it found no evidence of data deletion or compromise of its other Helpfeel and Cos images, and the company said it could not rule out that some were viewed. Gyazo detected the suspicious activity on September 12, fixed the exploited vulnerability, and temporarily took the service offline for maintenance. Helpfeel said it found no evidence of data deletion or compromise of its other Helpfeel and Cosense services. The company is notifying affected users, working with external experts and authorities, and advises users to change their Gyazo passwords and any reused passwords while remaining alert for suspicious communications.
Plugin4Shell is a high-severity supply-chain vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. T...
A newly identified Windows malware framework dubbed MovieReaper is being distributed through compromised torrent infrastructure and fake downloads of popular movies. Security resea...
WordPress 7.1.1 is a security and maintenance release addressing 11 security vulnerabilities across WordPress Core, themes, REST API functionality, XML-RPC, comments, and plugin ma...