Gyazo server flaw exploited to steal 23.6 million user records
The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23.6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads. The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords.
Critical Orkes Conductor Vulnerability Exploited in Attacks
A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.8, has been under active exploitation for at least a month, letting attackers submit malicious inline workflow definitions that execute arbitrary system commands, often with root privileges. Although a fix shipped in June, proof-of-concept code published in August accelerated attacks, and one vendor blocked roughly 1,300 exploitation attempts in a single week, prompting renewed calls to patch and keep Conductor instances off the public internet.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds shipped an update for Access Rights Manager after disclosing CVE-2026-28326, an 8.8-severity flaw caused by a hard-coded static key that could let an unauthenticated attacker achieve remote code execution on all ARM versions through 2026.2. The issue, credited to a researcher at Armadin, has been fixed in ARM 2026.2.1, and the vendor said it has no evidence of in-the-wild exploitation, though the disclosure follows other recent fixes for SAML bypass and denial-of-service bugs across the company’s product line.
Job hunting? North Korean fake recruiters infected 30,000 devices
A joint advisory from Japanese, US, Australian, and German authorities details how the North Korean group WaterPlum, also known as Contagious Interview, infected more than 30,000 devices across over 100 countries by posing as recruiters and instructing job seekers to run malicious code during fake technical interviews. The campaign compromised more than 7,000 cryptocurrency wallets and funneled at least $10.71 million to North Korea, and investigators say they dismantled a laptop farm in Japan that helped operate the scheme.
Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access
Check Point patched a critical stack-based buffer overflow, CVE-2026-91843 with a CVSS score of 9.8, in its Security Management and Log Servers that lets an unauthenticated remote attacker send an oversized username during login to gain root-level code execution. The flaw affects several supported release branches, and with thousands of internet-facing instances still showing the default server identity, administrators are urged to apply the LivePatch fix issued on September 16, restrict management access to known IPs, and watch logs for oversized-username login attempts.