Gyazo Breach Exposes 23.6M User Records and 490M Metadata Entries
A server flaw in the Gyazo image-sharing platform let attackers steal millions of user records and hundreds of millions of metadata entries.
Gyazo's operator, Helpfeel, confirmed that attackers gained unauthorized access by exploiting a vulnerability in the platform's image upload server. The company said the flaw allowed the theft of user records, according to BleepingComputer and SecurityWeek.
The exposed data includes roughly 23.6 million user records. The Hacker News gives a more precise count of 23.62 million and says the records contained email addresses and password hashes; SecurityWeek rounds the figure to 23 million. The three reports agree on the root cause but differ on the exact numbers.
The Hacker News also reports that about 490 million image metadata records were exposed, a detail not mentioned by the other two outlets. That discrepancy means the full scope of the breach may be broader than initially reported.
Sources · 4
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.