Gyazo server flaw exploited to steal 23.6 million user records

2026-09-19T07:23:20Z•b25fe30811c7dbee0b4e4a4e600f9f6215763827aaf000fb2ba974a525e74e66
AI securityAndroid malwareCheck PointClickFixDDoSGitHub impersonationMicrosoftWindows 11credential theftcritical vulnerabilitycyber espionagedata breachidentity securityinfostealermalwareremote code executionroot privilegessupply-chain attack

What happened

A BleepingComputer security news feed covering a major Gyazo data breach affecting 23.6 million records, malware campaigns including Rapuncel, RatHat, and SparroWocky, critical vulnerabilities in Check Point products, a Brevo supply-chain compromise, Microsoft security and product updates, DDoS infrastructure disruption, and emerging risks involving AI agents and identity security.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b25fe30811c7dbee0b4e4a4e600f9f6215763827aaf000fb2ba974a525e74e66
Enrichment time
2026-09-19T07:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.