CTIPilot

Gyazo

product · product:gyazo single-source-victim

Coverage timeline
1
first 2026-09-18 → last 2026-09-18
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Gyazo
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-18/gyazo-helpfeel-data-breach-image-upload-rce · ATT&CK page ↗

Story timeline

  1. 2026-09-18Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records
    active-threatsHelpfeel's 'unguessable link' privacy model for Gyazo collapsed once the image IDs themselves leaked from the backend

Where this entity is cited

  • active-threats1

Source distribution

  • corp.helpfeel.com1 (50%)
  • thehackernews.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Gyazo (1)

2026-09-18 · view entry permalink →

NOTABLENATOB2

Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records

Helpfeel Inc. (Kyoto, Japan) disclosed on 2026-09-16 that a third party exploited a vulnerability in the image-upload server of Gyazo, its screenshot-sharing service, on 2026-09-11, gaining unauthorized system access and the ability to execute arbitrary commands, then reaching Gyazo's database (Helpfeel Inc., 2026-09-16); Helpfeel has not named the flaw class or assigned a CVE. Roughly 23.62 million user records were exposed (name, email, password hash, user ID, device ID, login-session ID, X/Google SSO tokens, profile data, language preference, registration and last-login timestamps, subscription plan and billing status, excluding payment-card numbers) plus roughly 490 million image-metadata records, mostly pre-2019, and metadata for a further 2.4 million images, including a link built from a 32-character image ID used to construct the access URL (The Hacker News, 2026-09-17), plus upload IP, User-Agent, EXIF location data, OCR-extracted text, and a hashed passphrase for password-protected private images (Helpfeel Inc., 2026-09-16). Gyazo's default privacy setting for an image relies entirely on the image ID in its URL staying secret, distinct from the stricter "Only me" or password-protected settings (The Hacker News, 2026-09-17); the leaked IDs directly defeat the default setting, and Helpfeel confirms the attacker also obtained a list identifying which images were marked private, so it "cannot rule out" unauthorized viewing of private content (Helpfeel Inc., 2026-09-16). Helpfeel's own public status page described the outage only as "emergency maintenance" on September 14 and 15 and did not disclose a breach until the September 16 notice, filing a report with Japan's Personal Information Protection Commission the day before (The Hacker News, 2026-09-17). Helpfeel's other two products, Helpfeel and Cosense, run on separate infrastructure and were not found to have any unauthorized data disclosure (Helpfeel Inc., 2026-09-16).

On September 11, 2026, a third party exploited a vulnerability in Gyazo's image upload server to gain unauthorized access to our systems and execute arbitrary commands.

We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.

Helpfeel Inc. 2026-09-16
incident18 Sep 05:00Zsingle-source · victim disclosureOpen finding ↗