Gyazo server flaw exploited to steal 23.6 million user records

2026-09-19T01:23:22Z•fdbad8f9e3dbbfb05657040404bda0a81917d52e8a3812d0cd673730a5f2ed01
AI securityAndroid malwareBrevoCheck PointChinese threat actorsClickFixDDoSMicrosoftNightmareStresserRapuncelRatHatSparroWockyWindows 11cyber espionagedata breachinfostealermalwareroot privilege escalationsupply-chain attackvulnerability

What happened

BleepingComputer security news roundup covering a major Gyazo data breach affecting 23.6 million records, a critical Check Point vulnerability enabling root-level code execution, malware campaigns involving Rapuncel, RatHat, and SparroWocky, a Brevo supply-chain compromise distributing ClickFix scripts, and law-enforcement disruption of the NightmareStresser DDoS service. It also includes Microsoft security and product updates, AI-agent security concerns, and end-of-support information.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fdbad8f9e3dbbfb05657040404bda0a81917d52e8a3812d0cd673730a5f2ed01
Enrichment time
2026-09-19T01:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Gyazo server flaw exploited to steal 23.6 million user records · Baitaphish