IT News on September 28th: Developer Helpfeel disclosed on September 16th that its image hosting platform Gyazo had been hacked, resulting in the leakage of over 23.62 million user records.
Public information shows that Gyazo allows users to upload screenshots and videos to the cloud and generate sharing links. The server that was attacked by hackers this time is Gyazo, which is responsible for image uploads. Information such as user names, email addresses, password hashes, user and device ID, login sessions, X platform integrations, Token, and Google SSO email addresses was leaked, in addition to approximately 490 million pieces of image metadata also being compromised.

Helpfeel disclosed in the announcement that hackers took advantage of a vulnerability in the Gyazo image upload server to gain system access, thereby obtaining the permission to remotely execute arbitrary commands. The company detected the abnormal situation on the evening of September 11 and subsequently blocked the access path used by the attackers and fixed the vulnerability in the early hours of September 12.
Since some of the leaked image metadata can be used to generate images URL, attackers may use this information to access and view the corresponding images. Helpfeel has temporarily disabled some image browsing functions, but it is currently impossible to rule out that some users' private images have already been viewed.
Helpfeel indicates that the company has already reported to the relevant authorities and entrusted external experts to conduct an investigation. At the same time, users are advised to change the passwords used on the Gyazo platform and other related services.












