Gyazo Data Breach Exposes 23 Million User Records
2026-09-18T20:51:36Z•ffe14524525378a9c14beab785cfeeffd224da50f082c9881ede19bcb570cfed
CVE-2026-76460CVE-2026-91843Acronis BackupAndroid malwareBambooToken voice? MQTT malwareCISA KEVCentral AsiaCheck PointChosen BrickCisco ISEDDoS-for-hireGoogle PixelGyazoHelpfeelIranian surveillanceOperation PowerOFFRatHatSilkParasiteSpiceRATaccessibility abusecredential theftcritical infrastructuredata breachmaritime cybersecurityremote code executionroot access
What happened
Security news covering a major Gyazo data breach affecting approximately 23 million user records; the Android RatHat trojan abusing accessibility services and debugging features for credential theft; a critical unauthenticated Check Point vulnerability enabling root code execution (CVE-2026-91843); cyberattacks against oil tankers; SilkParasite infrastructure targeting Central Asian governments and critical sectors; a DDoS-for-hire takedown; CISA KEV additions affecting Cisco ISE, Acronis Backup, and Google Pixel; Iranian Chosen Brick surveillance malware; and BambooToken malware using MQTT C2
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- ffe14524525378a9c14beab785cfeeffd224da50f082c9881ede19bcb570cfed
- Enrichment time
- 2026-09-18T20:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.