Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gyazo hit by network compromise

Incident
First reported
Last updated
Happening score
H score 69
1 unique sources, 1 articles

Summary

Hide ▲

Gyazo suffered a security breach that exposed 23.62 million user records and 490 million image metadata records, creating risk of unauthorized image access and credential abuse. The compromise came through a vulnerability in Gyazo's image upload server, and the attacker used that foothold to run arbitrary commands on Helpfeel's systems. Exposed records included email addresses, password hashes, session-related data, and image-link IDs that could let outsiders view captures without permission. Helpfeel disabled viewing for some images, told users to change passwords, and said the flaw was fixed after suspicious activity was noticed on September 11.

Related Happenings

GSS VPN device access security flaw

Vulnerability
H score54 First: 14.09.2026 23:36 Last: 14.09.2026 23:36 Sources 1

About this happening: Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system...

Timeline

  1. 16.09.2026 03:00 2 articles · 1d ago

    Helpfeel confirms Gyazo data exposure and restricts image viewing

    Initial Disclosure

    Helpfeel confirmed on September 14 that Gyazo data had been exposed, reported the incident to Japan's Personal Information Protection Commission on September 15, and published its notice on September 16. The company said some image viewing had been temporarily disabled, warned users to change their passwords, and stated that about 23.62 million user records and about 490 million image metadata records were exposed.

    Show sources