#SEC disclosure
28 stories taggedSEC disclosure · page 2 of 2.

Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems
The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

Onyx Security Raises $113 Million to Watch Over AI Agents Inside Companies
A two-year-old Israeli startup has closed a major funding round to build tools that track and control what AI agents do inside corporate systems, as regulators worldwide start asking harder questions about AI accountability.

Analog Devices Discloses Data Breach After Hackers Stole Files in June Attack
The Massachusetts chip-maker told federal regulators that unauthorised intruders accessed its systems on 23 June and took files. A separate extortion group now claims to hold 570,000 records from the company.

Clover Health Discloses Data Breach After Social Engineering Attack Hits Staff Accounts
Three employee accounts were broken into through a social engineering attack, exposing personal and health information belonging to Medicare Advantage plan members.

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

Ransomware Attack Halts Fairlife Milk Production Across the US
Coca-Cola told the SEC that hackers broke into its Fairlife dairy subsidiary, forcing the company to stop making protein shakes and ultra-filtered milk at its American plants.

Microsoft Tightens Teams Meeting Controls for External AI Bots
A new admin policy requires organizer approval before automated external participants can join Teams meetings, a quiet but consequential shift in how enterprises govern AI access to sensitive calls.

Behavioral AI Pitched as Answer to Identity-Abuse Phishing, But Regulators Still Set the Bar
A vendor webinar makes the case for behavioral detection against BEC and account takeover. The compliance questions sit underneath.

Adobe Ships Emergency Fixes for Seven CVSS 10.0 Bugs in ColdFusion, Campaign Classic
Out-of-band advisories cover arbitrary code execution and privilege escalation paths. Self-managed deployments carry the full remediation burden; cloud tenants do not.

WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least nine jurisdictions.

When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.

MDR's AI Reckoning: When the Old Service Model Stops Keeping Up
Managed detection and response solved a staffing problem. It is not, by itself, an answer to adversaries who automate reconnaissance and intrusion at machine speed.

Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated, and enterprises are deploying it despite knowing it carries unresolved flaws.