InfoSec News Nuggets – 09/21/2026
Brief
Gyazo server flaw exploited to steal 23.6 million user records
The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23. 6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads.
The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords.
Critical Orkes Conductor Vulnerability Exploited in Attacks
A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.
