Gyazo just exposed 23.6 million user records. Treat that as an incident with a body count: accounts, emails, and the metadata a screenshot service keeps so your people can paste pictures into tickets, chats, and war rooms. If your cybersecurity program still treats capture tools as harmless utilities, update the model. Capture tools store identity.
23.6 million user records walked out of a screenshot service most security teams never put on an asset list.
You already know the path. Someone needed a fast way to share a cropped error dialog. They installed a consumer grabber, signed in with work mail, and kept using it for years. Nobody billed it as production. The data still left.

The Screenshot Left. The Records Followed.
Screenshot services sit in a blind spot you built on purpose. They feel smaller than email. They feel friendlier than a file share. They also keep a durable copy of whatever was on the glass: passwords in a setup wizard, customer PII in a ticket, an MFA QR code, a kubeconfig opened “just for a second.”
Gyazo is the name in this week’s reporting. The pattern is older than that brand. Engineers, helpdesks, and contractors grab a rectangle, drop it on a public-ish host, and move on. Your asset inventory lists laptops and the edge firewall. It rarely lists the GIF-and-paste SaaS that has been holding cropped secrets since 2019.
Collaboration servers are the same class of risk with a louder clock. CISA added Microsoft SharePoint flaw CVE-2026-65660 to its Known Exploited Vulnerabilities catalog and set a federal patch deadline of September 28. That’s tomorrow if you’re reading this on the day the advisory hit the wires. Agencies get a date. You get attackers who already have a working exploit and no interest in your change window.
If you can name your firewall vendor, you should also be able to name the last screenshot app that touched a production secret. Same for the SharePoint farm that still answers on the internet because “the vendors need it.” Both are places people put files so other people can look. Both outlive the chat thread that created them.
Threat detection that only watches brute-force noise against VPN will miss this. The Gyazo-class failure is an account on a consumer host, a reused password, and a pile of images that were never classified. The SharePoint-class failure is an unpatched collab stack that already sits inside your trust boundaries. Different vendors. Same operational sin: you didn’t treat the viewing layer as a data store.
Ignore Capture Tools, and Cybersecurity Misses the Leak
Stop waiting for a tidy vendor list. You need a capture-path inventory you can finish this week, then a habit that keeps it honest. Defense in depth here means the image host, the collab server, and the analyst PC each get controls, not a single edge box doing all the work.
Do this immediately:
- Pull SSO, browser-extension, and expense data for screenshot, GIF, paste, and “quick share” services. Include personal accounts that accept work email. If Gyazo (or a cousin) shows up, treat it as a live incident response case: session kill, password and token rotate, and a hunt for production images that landed there.
- Internet-expose every SharePoint, file-preview, and similar collab host. Patch CVE-2026-65660 before you debate the maintenance window. If you cannot patch by the CISA date, take the path off the network and put a ticket on the outage, not on the risk register.
- Upgrade Wireshark on every packet-capture box to 4.6.9. That release fixes 19 vulnerabilities and 16 bugs. Capture files are credential caches. The sniffer is part of cyber security whether your CMDB agrees or not.
- Turn on MFA and lock unused tenants on every remaining approved capture tool. Kill local-password logins that invite brute-force spraying. Log admin access. If you have no owner, you have no app.
Keep going after the fire drill. Put screenshot and paste domains on your egress watchlist and alert when a subnet that handles tickets or production jumps to a consumer image host. Fold those tools into security hardening baselines the same way you already handle browsers: extension allowlists, no standing admin, disk encryption, short session lifetime.
Write a one-page incident response card: who revokes the SaaS tenant, who searches mail and chat for share links, who tells legal if customer images were in the dump. Practice it once. Threat-protection catalogs will not page you for “someone uploaded a cropped VPN password.” Your process has to.
None of this requires a new platform. It requires you to stop classifying capture as a convenience feature.
Nineteen Vulnerabilities Still Land on the Analyst Desk
While Gyazo burned a consumer identity pile, SANS ISC noted Wireshark 4.6.9. Nineteen vulnerabilities in the tool your people use to inspect other people’s traffic. Read that again. The workstation that opens .pcap files often runs privileged, holds ticket access, and sits next to production admin jump paths.

Packet captures pick up tokens, cookies, and basic-auth leftovers. A bug in the dissector is a bug in a data store. Teams that patch the data center and leave the SOC laptop on an old Wireshark build have a hole with a familiar name and a quiet owner.
Pair that with SharePoint under active exploitation and you get a clean operational picture. Files and frames go where humans look. Attackers follow the lookers. Your Monday is patch the collab farm, lift the sniffer, and assume at least one screenshot service in the Gyazo dump matches a mailbox you issue.
This is a bad look for programs that measure health in blocked inbound sessions. Blocked inbound is table stakes. The leak in this week’s news lived in sharing habits, unpatched document servers, and analyst tooling that never made the vuln SLA. Put those three on the same board. Then staff them like you staff the edge.
Sources
- Week in review: Gyazo breach exposes 23.6M user data
- Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
- Wireshark 4.6.9 Released, (Sun, Sep 27th)
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
