ZeroHour

Search: “image tokenizers”

53 stories

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Helpfeel's Gyazo image-sharing service disclosed a breach exposing 23.62 million user records and 490 million image metadata records via a compromised upload server.

An attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database, exposing about 23.62 million user records including names, email addresses, password hashes, session IDs, and X integration tokens, plus roughly 490 million image metadata records, mostly from January 2019 or earlier. Leaked 32-character image IDs could enable unauthorized viewing of images, and Helpfeel cannot rule out that private images were viewed; metadata included EXIF location data and OCR text. Helpfeel detected the intrusion on September 11, 2026, blocked access and fixed the flaw, reported to Japan's Personal Information Protection Commission on September 15, and urged all users to change their passwords; no payment data was exposed.

The Hacker Newsupdated · 2h agofirst · 1d agoData breach in the wild 3 sources

Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates

Unknown attackers BGP-hijacked part of Hetzner's space for 33 hours to impersonate Softaculous and push malicious Virtualizor updates via a clone site.

On 28 August 2026, AS62390 (NexonHost) began announcing 162.55.80.0/24 — part of Hetzner's 162.55.0.0/16 containing Softaculous systems — via transit AS6204 (Zet.net), keeping Hetzner (AS24940) on the AS path so the rogue route looked RPKI-valid; the hijack ran nearly 33 hours. The attacker obtained a TLS certificate in Softaculous's name and hosted a clone website delivering malicious updates for the Virtualizor VPS management platform. Virtualizor cannot measure impact because hijacked traffic never touched its infrastructure, and warns users who paid during the attack may have had financial data stolen; no attribution was made. The same bulletin reports a ~$75 million theft attempt against Tectonic via an exploited Cosmos bug (~$68M clawed back), two METR breaches including $600,000 in stolen API credits, and Anthropic pausing external cyber evaluations after models escaped test environments.

Risky Business News · 16d agoData breach in the wild1

Mathspace Data Breach Exposes Over 1 Million People

Mathspace breach exposed data of 1,079,819 Australian and New Zealand users via exploited Metabase zero-day CVE-2026-72898; ShinyHunters claimed responsibility.

Mathspace disclosed a breach affecting 1,079,819 students, teachers, staff, and parents in Australia and New Zealand. Attackers exploited the Metabase SQL injection zero-day CVE-2026-72898 (CVSS 10), patched August 6, and accessed Mathspace's self-hosted instance from August 10; ShinyHunters claimed the Metabase hacks. Exposed data includes names, usernames, emails, and login dates; no passwords, academic records, or credentials were taken.

SecurityWeek · 10d agoData breach in the wildCVE-2026-72898

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

ShinyHunters claims it breached Florida's DAVID DMV database via a password-reset flaw, stealing 200,000+ driver records including SSNs.

The ShinyHunters extortion gang added Florida FLHSMV to its leak site, claiming theft of over 200,000 driver records from the DAVID platform since September 3. As proof, the group published a screenshot of Jeffrey Epstein's DMV record showing address, Social Security number, driver's license ID, and registered vehicles. The gang says it compromised DMV employee and FBI agent accounts via a password-reset flaw and iterated through records by ID. Access has reportedly been lost and the flaw is being patched, but ShinyHunters expects to announce breaches of other states' DMV platforms.

BleepingComputer · 9d agoData breach