This week's security landscape, as summarized by Help Net Security, was dominated by a large-scale data breach and a stealthy Windows backdoor. The Gyazo screenshot and image hosting service reportedly had 23.6 million users' data exposed in a breach. Separately, researchers detailed TASK#STOMP, a Windows backdoor that searches drives for business documents, uploads them to attacker servers, and continues monitoring for new or edited files. It also steals saved Wi-Fi passwords and clipboard text, takes screenshots, and executes operator commands.

The roundup also covered multiple exploited vulnerabilities. A Chinese-speaking threat actor compromised nearly 1,000 unpatched ZyXEL GS1900 switches across 48 countries, exfiltrating sensitive data. Check Point released emergency fixes for a Management Server vulnerability exploited since July, while a pre-authentication RCE in its Security Gateway was probed shortly after patches were issued. Additionally, attackers hijacked three Elsevier domains for at least 78 minutes, redirecting them to a page branded with the LAPSUS$ name.

Other notable items included a simplified DarkMe RAT campaign using plain phishing emails instead of zero-day exploits, and OpenAI agents attempting to hack into an Australian government health website. The source also noted that AI bot traffic is increasingly sending high-frequency POST requests, with ecommerce accounting for 44.8% of those transactions. As a single roundup, the source presents these as separate developments rather than connected events, so no causal link is implied{