September showed how quickly vulnerabilities can become large-scale incidents. Major disclosures exposed identity records and sensitive image metadata, a compromised cloud credential turned trusted website components into a malware-delivery channel, and ransomware disrupted a diversified transport group. The month also provided unusually concrete evidence that AI agents are compressing the time required to develop exploits, identify targets, and move through compromised networks.
At a Glance
- Gyazo disclosed a breach involving 23.62 million user records and hundreds of millions of image-metadata records.
- Times Car confirmed the theft of information from approximately 6.6 million current and former accounts.
- A compromised Brevo Cloudflare key enabled malicious code injection into Brevo pages and customer-embedded scripts.
- Keio Corporation detected ransomware across group servers, disrupting some business systems.
- A reusable exploit chain dubbed BlueMoon spread rapidly among several cyber-espionage groups.
- AI-assisted attacks compromised hundreds of PaperCut servers and exploited two zero-days at cybersecurity nonprofit DIVD.
Cybercrime Breaking News
Gyazo breach exposes user data and image metadata
Helpfeel confirmed that an attacker exploited a vulnerability in Gyazo’s image-upload server on September 11, gaining command-execution access and reaching the service’s database. Approximately 23.62 million user records were disclosed, although 18.01 million related to anonymous accounts without registered email addresses.
Times Car confirms theft from 6.6 million accounts
Japanese car-sharing provider Times Car detected unauthorized access on September 25 and confirmed that information from approximately 6.6 million current, former, corporate, and incomplete-registration accounts had been acquired. Depending on the user, the data included names, addresses, birth dates, telephone numbers, email addresses, driving-licence information, identity-document images, password data, and identifiers linked to partner services.
Brevo cloud credential turns embedded scripts into an attack channel
On September 14, an attacker used a stolen Brevo Cloudflare API key to deploy a malicious Cloudflare Worker. For approximately five and a half hours, the Worker altered responses from Brevo websites and three JavaScript files embedded on customer sites, displaying a fake Cloudflare verification page that instructed Windows users to run a malware-downloading command.
Ransomware disrupts parts of the Keio group
Keio Corporation, a major Japanese railway and hospitality group, detected a ransomware attack against group servers in the early hours of September 26. Some group-company business systems were disrupted, and affected entities restricted external connectivity while working with police and outside specialists.
BlueMoon exploit kit spreads among espionage groups
Researchers disclosed that several espionage-focused threat clusters had adopted a shared exploit framework named BlueMoon. The kit chained vulnerabilities in Chromium’s V8 engine with a Windows privilege-escalation flaw, allowing a malicious webpage to progress from browser exploitation to higher-privilege code execution and payload delivery.
North Korean fake-recruitment campaign quantified
A joint advisory from authorities in the United States, Japan, Australia, and Germany attributed a large fake-recruitment campaign to the North Korean group WaterPlum, also associated with Contagious Interview. The actors posed as recruiters and directed developers and other technology professionals to execute malicious coding projects or packages.
Cybersecurity and AI
AI agents scale PaperCut exploitation across 48 countries
GreyNoise reported that a likely Russian-speaking actor used hundreds of AI agents to develop, test, and deploy exploits for two PaperCut NG/MF vulnerabilities. The campaign compromised at least 440 installations associated with 395 identified organizations in 48 countries; education accounted for 204 affected systems.
AI-driven intrusion uses two Zammad zero-days against DIVD
The Dutch Institute for Vulnerability Disclosure detected malicious access to its systems on September 21. DIVD’s investigation found that attackers chained two previously unknown vulnerabilities in the Zammad ticketing platform to hijack a session, execute code, and elevate privileges to root.
What Organizations Should Watch
- Shorten patch decisions for exposed systems. PaperCut and BlueMoon both showed that exploitation can scale within hours or days, particularly for authentication-bypass, browser, remote-code-execution, and privilege-escalation flaws.
- Reduce the reach of cloud credentials. Long-lived, broadly privileged API keys should not be embedded in source code. Use narrowly scoped tokens, automated rotation, secret scanning, and alerts for unexpected DNS, CDN, or edge-worker changes.
- Treat embedded third-party code as supply-chain exposure. Maintain an inventory of externally hosted scripts and widgets, apply restrictive content-security policies where possible, and prepare a way to disable integrations quickly.
- Minimize retained identity data and metadata. Driver’s-licence images, OCR text, location information, session identifiers, and records associated with deleted content can remain valuable to attackers long after collection.
- Isolate recruiting and code-evaluation workflows. Untrusted coding assignments should run in disposable sandboxes without access to production credentials, cryptocurrency wallets, source repositories, or corporate cloud sessions.
AMATAS will continue to monitor this space and deliver salient information regularly.
Stay tuned for our next report and if you are interested in any of our privacy and cybersecurity services, please do reach out through our website www.amatas.com or by e-mailing office@amatas.com.
As always – be vigilant, stay alert, and think twice.

