LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
breach

Gyazo Data Breach Exposes 23 Million User Records

A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server. “We have confirmed that approximately […]

zeroday.news ·

Helpfeel, the Japanese software company behind the Gyazo image-sharing service, has confirmed a data breach that exposed approximately 23.62 million user records. The unauthorized access occurred on September 11, 2026, when an attacker exploited a vulnerability in Gyazo's image upload server, allowing them to execute malicious commands.

The company stated that the attacker was blocked from their systems the following day, September 12, but had already accessed a database containing user information. The compromised data includes names or nicknames, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile information, language preferences, registration and last login dates/times, subscription plans, billing status, and usage statistics. Helpfeel explicitly confirmed that no payment card information, such as credit card numbers, was exposed. The breach also affected anonymous accounts that did not have registered email addresses.

In addition to user records, the incident also led to the exposure of approximately 490 million image metadata records, predominantly for images uploaded in or before January 2019. Metadata from an additional 2.4 million images was also accessed through specific search queries. This metadata could include image IDs, upload IP addresses, User-Agent data, EXIF location information, OCR text, image titles, source URLs, other general metadata, and hashed passphrases for private images.

Helpfeel acknowledged that some of this exposed metadata could potentially be used to reconstruct Gyazo image URLs, which might allow unauthorized access to images. While the company has not confirmed that image files themselves were stolen, it cannot rule out the possibility that some private images were viewed. As a precautionary measure, access to certain images has been temporarily disabled. A list of private images was also obtained by the attacker.

The company is in the process of notifying affected Gyazo users via their registered email addresses. For users without registered email addresses, such as those with anonymous accounts, notifications will be provided through the Gyazo web interface. Helpfeel has confirmed that all access routes used in the incident have been blocked and the exploited vulnerability has been remediated.

Helpfeel is advising all Gyazo users to change their passwords immediately, especially if they use the same or similar passwords on other online services. Users are also encouraged to remain vigilant for suspicious emails, messages, or other communications that could be phishing attempts designed to exploit the breach. The investigation into the incident is ongoing, and Helpfeel has stated it will publish updates if further information emerges. No unauthorized disclosure has been confirmed in Helpfeel's or Cosense's other systems.

breachvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

nation-state

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through […]

vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.