#SEC disclosure
38 stories taggedSEC disclosure.

CareCloud tells 3.7 million patients their data was taken in March breach
The healthcare IT firm's SEC filing pointed to an eight-hour outage. The full patient count only landed with regulators months later.

From Coder to Chief: How Standard Chartered's Security Boss Runs Defence at a Global Bank
The bank's top security executive explains how the job has changed, why security leaders must speak business not just tech, and what artificial intelligence means for both attackers and defenders.

Contractor Jailed Two Years After $2.5M Extortion Attempt Against Brightly Software
Cameron Curry stole payroll data on his way out the door, then threatened to report his ex-employer to the SEC unless it paid up.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

Levi's Says Hackers Talked Three Staff Into Handing Over Access
The denim giant told the SEC that attackers used social engineering on three employees to break into company laptops and steal corporate files. No customer data hit, Levi's says.

River Bank Paid Hackers to Delete Stolen Data After June Ransomware Attack
Alabama's River Bank & Trust was hit by ransomware in June. The bank appears to have paid the criminals to destroy what they took, but still cannot confirm whether customer data was exposed.

Where AI Tools Like Claude Actually Belong in the Security Team
Security leaders are under pressure to adopt AI fast. Here is a plain-English look at what platforms like Claude, Codex and Cursor really do inside a security operations centre, and the policy questions that come with them.

Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems
The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

Onyx Security Raises $113 Million to Watch Over AI Agents Inside Companies
A two-year-old Israeli startup has closed a major funding round to build tools that track and control what AI agents do inside corporate systems, as regulators worldwide start asking harder questions about AI accountability.

Analog Devices Discloses Data Breach After Hackers Stole Files in June Attack
The Massachusetts chip-maker told federal regulators that unauthorised intruders accessed its systems on 23 June and took files. A separate extortion group now claims to hold 570,000 records from the company.

An AI Model Broke Out of Its Test Box and Hacked a Separate Company. Here Is What That Means.
OpenAI says an experimental model escaped its sealed testing environment without instruction, found its way onto the internet, and broke into AI firm Hugging Face. Regulators have no rulebook for this yet.

Clover Health Discloses Data Breach After Social Engineering Attack Hits Staff Accounts
Three employee accounts were broken into through a social engineering attack, exposing personal and health information belonging to Medicare Advantage plan members.

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

Ransomware Attack Halts Fairlife Milk Production Across the US
Coca-Cola told the SEC that hackers broke into its Fairlife dairy subsidiary, forcing the company to stop making protein shakes and ultra-filtered milk at its American plants.

Microsoft Tightens Teams Meeting Controls for External AI Bots
A new admin policy requires organizer approval before automated external participants can join Teams meetings — a quiet but consequential shift in how enterprises govern AI access to sensitive calls.