HHS Releases Updated Security Risk Assessment Tool
HHS OCR and ONC released version 3.7 of the Security Risk Assessment Tool for healthcare organizations.
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) released version 3.7 of the Security Risk Assessment (SRA) Tool. The tool helps covered entities conduct HIPAA security risk assessments. ONC and OCR provided guidance on the updates.
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Helpfeel's Gyazo image-sharing service disclosed a breach exposing 23.62 million user records and 490 million image metadata records via a compromised upload server.
An attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database, exposing about 23.62 million user records including names, email addresses, password hashes, session IDs, and X integration tokens, plus roughly 490 million image metadata records, mostly from January 2019 or earlier. Leaked 32-character image IDs could enable unauthorized viewing of images, and Helpfeel cannot rule out that private images were viewed; metadata included EXIF location data and OCR text. Helpfeel detected the intrusion on September 11, 2026, blocked access and fixed the flaw, reported to Japan's Personal Information Protection Commission on September 15, and urged all users to change their passwords; no payment data was exposed.
Recorded Future Launches Digital Risk Protection, Unifying Brand and Identity Monitoring
Recorded Future launched Digital Risk Protection, unifying brand and identity monitoring across five external threat surfaces in one workflow.
Recorded Future announced Digital Risk Protection, combining brand threat monitoring and identity exposure monitoring across five use cases: malicious site, impersonation, code repository, dark web brand, and identity exposure monitoring. The platform includes an AI Triage Agent that automates alert evaluation with explicit verdicts and context, expanding social media analysis, OCR, full Telegram coverage, and infostealer log ingestion. Gartner's 2026 Magic Quadrant folded digital risk protection into cyber threat intelligence technologies, and the launch cites $15.9 billion in 2025 US fraud/scam losses, up 28% year over year.
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft details high-volume phishing campaign using ASCII smuggling (Unicode tag chars) for filter evasion, peaking at 2.3M messages.
Microsoft researchers observed a high-volume finance-themed phishing campaign using invisible Unicode tag characters (U+E0000–U+E007F), a technique known from AI prompt injection research as ASCII smuggling, to split lure words like 'funding' and evade email filters. Telemetry from Microsoft Defender for Office 365 showed signature hits jump from roughly 21,000 messages on February 8, 2026 to more than 1.3 million on February 9, peaking above 2.3 million on February 11, with elevated weekday activity lasting approximately three months. The discovery emerged from prompt injection protection research, showing AI-era evasion techniques crossing into traditional phishing. Most messages were flagged by layered Defender protections rather than a single Unicode-specific signal.