Severity Daily

IT and AI security incidents, checked against the primary source

Tag: CenterPoint Energy

  • In five of today’s nine stories, the version field is the part that’s wrong

    In five of today’s nine stories, the version field is the part that’s wrong

    Patch Cisco Secure Email Gateway first, and do it before Thursday. Cisco’s advisory, published Monday at 11:00 a.m. Central, describes an unauthenticated flaw that runs arbitrary commands as root, reached by sending the appliance an email — the one input a mail gateway cannot decline. Cisco says it became aware of active exploitation this month, and that there are no workarounds. CISA put the CVE on the federal catalog the same afternoon with a September 17 deadline and a forensic-triage obligation, meaning agencies must not only remediate but also determine whether the box has already been used. Three days, an appliance that sits at the edge, and no mitigation short of the upgrade.

    That outranks the story with the bigger name on it. CenterPoint Energy told the SEC on Monday evening that an unauthorized third party took customer personal information from an external-facing system, then gave no count, no date, no system name, and no data types — filed under Item 8.01 rather than the breach item. It is the day’s most consequential story for the people whose information is in that file and the least actionable one on the site tonight. There is nothing in it to patch, block, or notify against.

    The thread runs through most of the rest: in five of today’s nine stories, the field you would patch from is the field that is wrong. Froxlor’s CVE says the flaw was fixed in 2.2.5; the newline check first appears in 2.3.8, twelve releases and 19 months later. CVE-2026-57127’s machine-readable range stops ten releases short of the version its own description names, one of sixteen PraisonAI records published Monday against fixes that shipped in June. Three SIPp buffer overflows are fixed on master and in no release at all, because there has not been one since 3.7.7. Strapi’s June fix never reaches the 4.x branch, which went end-of-life in April and still ships the flaw. And the Cisco record’s own version list stops short of one of the three release trains Cisco says is affected. A scanner reading those five records gets five different wrong answers about what to install.

    Apache Storm is the same failure one layer up: fourteen CVEs published Monday with almost no severity data, backfilled by CISA’s data publisher five hours later, and on the one record Apache had scored itself the two numbers are 10.0 and 6.5. MISP is the day’s clean one and the next thing to do after Cisco — an empty password accepted as a valid login through the LDAP and LinOTP plugins, fixed in 2.5.46, with the CVE four days behind the release. And Langflow’s component scanner ran the code it was checking and reported “validated: true”; the fix reached PyPI on June 23 and the CVE record arrived Monday evening, 83 days later.

    Still open. Cisco’s deadline is Thursday and the CVE record still lists no fixed 16.5 build, so anyone on that train has to work from the advisory rather than the record. Froxlor’s advisory and its CVE both still name 2.2.5, and neither has been corrected. Apache Storm’s CVE-2026-82434 carries a 10.0 and a 6.5 from two publishers, and neither has been withdrawn. SIPp and Strapi both have code that fixes the flaw and no release a 4.x or packaged user can install. And CenterPoint has still not said how many people are in the file.

  • CenterPoint Energy confirms an unauthorized third party took customer personal information, and the 8-K gives no number

    CenterPoint Energy confirms an unauthorized third party took customer personal information, and the 8-K gives no number

    The utility filed Monday evening under Item 8.01 rather than Item 1.05, said an unauthorized third party took personal information from an external-facing system, and gave no count, no date, no system name, and no data types.

    What happened

    CenterPoint Energy filed an 8-K on Monday, September 14, 2026, accepted by EDGAR at 5:15 p.m. ET, accession number 0001104659-26-107560. It was filed jointly by three registrants — CenterPoint Energy, Inc., CenterPoint Energy Houston Electric, LLC, and CenterPoint Energy Resources Corp. — and it reports one item: Item 8.01, Other Events. The filing carries no press-release exhibit. Apart from XBRL taxonomy files, the 8-K document is the entire disclosure.

    Here is how it opens, in the company’s words: “In September 2026, CenterPoint Energy, Inc. (the ‘Company’) became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company’s customer information. Upon becoming aware of the post, the Company promptly took action and activated its cybersecurity incident response protocols, initiated an investigation with the assistance of third-party cybersecurity experts, and took steps to further protect the Company’s systems.”

    The confirmation comes in the third paragraph: “While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems (the ‘Incident’). The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law. The Company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue.”

    On operations and materiality: “The Company’s delivery of electric and gas services has not been impacted and remains operational and undisrupted. As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company’s financial condition or results of operations.” And on cost: “The Company has incurred, and expects to continue to incur, certain expenses related to the Incident and its response to the Incident. The Company maintains customary cybersecurity insurance coverage and believes this insurance will offset related costs.”

    The filing establishes that data was taken and that CenterPoint has confirmed it. It establishes almost nothing else: no number of affected customers, no categories of personal information, no date or date range for the intrusion, no name for the external-facing system, and no identification of the third party whose post started the clock. It says only “In September 2026” for when the company became aware, placing discovery somewhere in the two weeks before the filing.

    Why it matters

    Start with where this filing sits. Item 1.05 of Form 8-K is the cybersecurity disclosure item created by the Commission’s 2023 rule; a registrant uses it once it has determined an incident is material. Item 8.01, Other Events, is the general-purpose item for something a company has simply decided to disclose. CenterPoint used 8.01 and then stated, in the same filing, that it “does not believe it is reasonably likely that there will be a material impact.” That is not an oversight or a dodge — it is the two halves of the same decision, and the negative materiality sentence is the tell that the company made the determination rather than deferring it.

    The practical consequence is that the SEC is now the least relevant regulator here. If the incident is not material, the federal disclosure obligation is essentially satisfied by what was filed Monday. The obligations that remain are state breach-notification laws, which turn on residents affected rather than on financial materiality, and which are the reason the company says it “intends to notify affected customers and regulatory authorities as required by applicable law.” CenterPoint’s own figures put the denominator in perspective: the company says it sells and delivers natural gas to “approximately 7 million homes and businesses in four states: Indiana, Minnesota (including Minneapolis), Ohio and Texas (including greater Houston area),” and that it serves “more than 2.9 million metered customers” with electric infrastructure in greater Houston and southwestern Indiana. “A portion” of that is the phrase in the filing. There is no numerator, and multiplying a vague fraction by a large denominator would produce a number this page is not willing to print.

    The more useful detail is the detection path, and it is easy to skim past. CenterPoint did not learn of this from its own telemetry, a partner, or law enforcement. It learned of it from “an online post by a third party claiming to have obtained a data set.” The company’s incident response began after someone advertised the data publicly. The investigation that followed confirmed the substance of that claim — which is the ordering that matters, and the reason this page treats the theft as confirmed while treating everything about volume and content as open. An attacker’s listing is a claim; a registrant’s determination, filed with the Commission, is not.

    That ordering is increasingly the common shape of a breach disclosure. The first signal is an extortion post or a forum listing, and the timeline starts from the adversary’s publishing schedule rather than from detection. Monitoring for your own name in the places stolen data gets advertised is no substitute for detection, but a company that learns about its own breach at the same time as the public has already lost the option of a controlled disclosure.

    The second paragraph of the filing is doing real work too. “The Company’s delivery of electric and gas services has not been impacted and remains operational and undisrupted” is the sentence a utility has to write, because the question anyone reads a utility breach disclosure asking is whether the grid moved. The answer here is no, and the filing locates the incident in an “external facing system” holding customer information — the customer-facing side of the IT estate, not the operational technology that runs wires and pipes. That distinction is also what lets a utility hold a customer-data breach to be immaterial: the regulated business is unaffected, the costs are response costs, and there is insurance against those.

    Plaintiff firms announced investigations within hours of the filing. Those announcements are not evidence of scope; they are evidence that a public company disclosed a customer-data breach, which is enough on its own to start that process. Anyone sizing this incident from law-firm press releases is reading a reaction to the 8-K, not a second source on it.

    What to do

    If you are a CenterPoint customer in Texas, Indiana, Minnesota, or Ohio, there is nothing actionable yet and no way to determine from public information whether your data is in the set. The company has said it will notify affected customers. The next primary sources with real content will be the state attorney general breach portals, which publish the notification letters with categories of data and affected counts; California’s list, checked at the time of writing, has no CenterPoint entry, with the most recent filing on it reported September 9, 2026. Treat any unsolicited call or email referencing a CenterPoint breach as a pretext until a notification arrives through a channel you initiated.

    If you run a similar estate, the two checks this filing suggests are unglamorous. First, inventory which external-facing systems hold customer personal information and confirm each one is in scope for the monitoring you actually read, not just the monitoring you own. Second, make sure someone is responsible for noticing when your organization’s name appears in a data-for-sale post, and that the path from that notice to your incident response process takes hours rather than days — because in this case that post was the starting gun.

    If you are a public company weighing a disclosure decision, this filing is a clean example of the Item 8.01 route: disclose the incident, state the materiality determination explicitly, and say plainly what the investigation has not yet determined. It commits to very little, but it does not claim to know what it does not know.

    Sourcing note

    Checked: CenterPoint Energy’s Form 8-K filed September 14, 2026, accession number 0001104659-26-107560, accepted at 5:15 p.m. ET, located through EDGAR full-text search and read from the filing index and the 8-K document itself. Every quotation above is from that filing. The customer and service-territory figures are quoted from CenterPoint Energy’s own company overview page. The absence of a California attorney general breach entry was checked against that office’s published breach list, whose most recent entry at the time of writing was reported September 9, 2026.

    Could not reach: the Maine attorney general’s breach database has been offline on recent checks and was not treated as checked on this run. No attempt was made to locate or read the “online post” the filing describes; this page does not report attacker claims about volume or data types, and no leak-site listing is used as a source here.

    Unresolved: the number of affected customers, the categories of personal information taken, the date or date range of the intrusion, the identity or nature of the external-facing system, and the identity of the party that published the data set are all unstated in the filing and unknown here. No attribution is made. The company’s statement that a material impact is not reasonably likely is its own determination as of the filing date and may change as the investigation continues; this page will follow the state attorney general filings, which are where the affected counts usually appear first.