CISA Advisories

📱 Your Pixel Can Be Hacked Without a Single Tap — And 23M Accounts Just Leaked

Two stories from today's security news deserve your attention: one is a phone flaw attackers are already using in the wild, and the other dumped the personal details of tens of millions of people onto the internet. Both have a clear action item for you.

A Pixel Flaw That Needs Zero Clicks From You

Google just patched a serious bug in the cellular modem inside Pixel phones (tracked as CVE-2026-58704). The scary part: attackers don't need you to click a link, open an attachment, or install anything. They can reach your phone over the cellular network and quietly gain elevated access to it.

Google says the flaw has already been used in real, targeted attacks, and the U.S. cybersecurity agency CISA added it to its official list of actively exploited vulnerabilities, ordering federal agencies to patch by September 19. Google hasn't released details about who was targeted or how.

Why you should care: "zero-click" means your usual good habits won't protect you here — only the patch will. If you or anyone on your team carries a Pixel, install the latest update today, not this weekend.

Read more →

23 Million Gyazo Users Just Had a Very Bad Day

Gyazo, the popular screenshot-sharing tool, was breached through a flaw in its upload server that let an attacker run commands and reach straight into its database. The haul: 23.62 million user records including password hashes, active session IDs, and integration tokens — plus metadata on 490 million images.

That last number is the quiet danger. Leaked image IDs could let outsiders pull up screenshots people assumed were private, and screenshots are exactly where sensitive things live: invoices, internal dashboards, chat threads, even credentials. Stolen session IDs and integration tokens are worse still, because they can let an attacker into an account without ever needing the password.

Gyazo's parent company Helpfeel has fixed the flaw and closed off the access routes, and is urging users to change their passwords. Do that — and if you reused that password anywhere else, change it there too. Turn on multi-factor authentication while you're in there.

Read more →

The Common Thread

Neither of these attacks depended on someone falling for a scam. They depended on unpatched software and on data sitting in places people forgot about. That's the unglamorous reality of modern security — and it's exactly the kind of exposure that's manageable when someone is actually watching for it.

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts