Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Weekly roundup leads with a Gyazo breach of 23.6 million users and the TASK#STOMP document-stealing backdoor.
Helpfeel confirmed that hackers exploited a Gyazo server flaw and stole 23.6 million user records. The same weekly digest details TASK#STOMP, a Windows backdoor that uploads business documents and also takes Wi-Fi passwords, clipboard text, and screenshots. A Chinese-speaking actor exploited CVE-2026-7273 on 996 unpatched Zyxel GS1900 switches in 48 countries, and Check Point said CVE-2026-93616 has been exploited since July 23, 2026. Elsevier domains were briefly redirected to a LAPSUS$ page, while DarkMe is now spread by ordinary phishing email.