Severity Daily

IT and AI security incidents, checked against the primary source

Tag: medical devices

  • NovoCure discloses a mid-August breach under Item 8.01 and writes its own Item 1.05 trigger into the filing

    NovoCure discloses a mid-August breach under Item 8.01 and writes its own Item 1.05 trigger into the filing

    Over 1,400 U.S. patient records were exposed as internal ID numbers with no names attached, fewer than 50 with identifying information, and the oncology-device maker says no treatment device was reached.

    What happened

    NovoCure Limited filed a Form 8-K with the Securities and Exchange Commission on Tuesday, September 1, 2026. EDGAR accepted it at 7:00:43 a.m. ET. The filing is checked under Item 8.01, Other Events, and Item 9.01, Financial Statements and Exhibits. The only exhibit is the cover page interactive data file. There is no Item 1.05.

    The disclosure opens by dating the intrusion: “In mid-August 2026, NovoCure Limited (the ‘Company,’ ‘we,’ or ‘us’) through a subsidiary, became aware of unauthorized access to some of its information systems.” The company says it “activated its cybersecurity response plan, implemented containment measures, and initiated an internal investigation of the event,” and engaged outside forensic experts to review what was accessed.

    What those experts found is stated in two tiers. The first is large and thin: “internal Company patient ID numbers for over 1,400 U.S. patient records (these ID numbers are only used internally and no patient names or other identifying data for these was exposed).” The second is small and thick: “patient data for fewer than 50 other patients in the western U.S. that included additional identifying information.” Beyond those two groups, the filing lists “general contact information for healthcare providers we work with” and “general contact information for Novocure employees, such as their job titles and phone numbers.”

    Then the sentence patients will read first: “No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional.”

    NovoCure makes Tumor Treating Fields devices — Optune Gio, Optune Lua, and Optune Pax — worn by patients being treated for glioblastoma, pleural mesothelioma, and, following a recent FDA approval, locally advanced pancreatic cancer. These are patient-operated appliances used at home for many hours a day. The company is registered in Jersey and trades on Nasdaq as NVCR.

    On materiality, the filing says: “At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations; however, at the time of this filing we are continuing to ascertain additional information regarding this incident.”

    And then it does something most Item 8.01 cyber filings do not. It writes its own trigger for the item it did not use: “If additional information is obtained whereby we determine this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations, we undertake to file an amendment to this Form 8-K filing under Item 1.05 containing such information within four business days after we, without unreasonable delay, determine such information, or within four business days after such information becomes available.”

    On notification, the company says only that it “continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.” No date is given. As of this writing there is no breach notice on novocure.com, and no press release accompanied the filing. A patient who wants to know whether their record is among the 1,400 currently has one place to look, and it is EDGAR.

    Why it matters

    The Item choice is not evasion here, and it is worth saying so directly, because Severity Daily has spent two days on filings where the Item choice was the story. Item 1.05 exists for a material cybersecurity incident and its four-business-day clock runs from the determination of materiality, not from discovery. Item 8.01 is the general-purpose box for events a company wants on the record without asserting materiality. When the SEC’s Division of Corporation Finance addressed this in 2024, its guidance pointed in exactly this direction: companies that have not determined an incident to be material should disclose under Item 8.01, so that a filing under 1.05 keeps its meaning as a materiality signal. A registrant that dumps every incident into 1.05 makes the item useless to investors. NovoCure filed the way the staff asked companies to file.

    What makes this filing worth reading is the undertaking. Most 8.01 cyber disclosures stop at “we do not believe this is material.” NovoCure’s states the condition under which it will refile, names the item, and restates the four-business-day clock. That is a disclosure control written into the disclosure itself, and it is cheap to copy. It also creates a public commitment that can be checked later, which is more than most readers get.

    The contrast with yesterday is instructive rather than accusatory. Nutex Health moved its breach disclosure from Item 8.01 to Item 1.05 seven days after first filing it, while still saying it did not expect a material impact — a refiling that raised the question of what the 1.05 designation was doing there at all. NovoCure has taken the other route: file 8.01, say plainly it is not material yet, and name in advance the circumstance that would change that. Two companies, two weeks apart, reaching opposite conclusions about the same pair of boxes. The boxes are the problem, not either filer.

    On the data itself, the two-tier description deserves a careful read rather than a reassured one. “Internal Company patient ID numbers” with “no patient names or other identifying data” is a real distinction, and 1,400 bare identifiers are worth much less than 1,400 records. But the qualifier is that these IDs “are only used internally” — an assertion about how NovoCure uses them, not a claim that they are meaningless to someone who took them out of NovoCure’s internal systems. Whether an internal ID is re-identifiable depends on whether the party holding it can also reach a mapping. The filing does not say what else was in the environment those IDs came out of, and it does not name the subsidiary involved. Both are reasonable things to withhold mid-investigation. Both are also the difference between 1,400 numbers and 1,400 patients.

    The “fewer than 50” tier is the one that carries the identifying information, and small numbers have consequences under the federal breach rules. HHS requires notice to affected individuals without unreasonable delay and no later than 60 days from discovery; breaches touching 500 or more residents of a single state additionally trigger prominent media notice and near-immediate reporting to the Secretary. A group of fewer than 50, concentrated in the western United States, sits below that threshold. That does not reduce NovoCure’s obligation to notify those individuals. It does mean the loudest parts of the notification machinery may never engage, which is a good reason for the company to publish something patients can find without an EDGAR search.

    Finally, the device sentence. This is the second implanted- or worn-device story in three days: Boston Scientific said on Saturday that implanted cardiac devices still worked while newly implanted units stopped transmitting to remote monitoring. In both cases the therapy was unaffected and the data path around it was not. NovoCure’s statement is narrower than it first reads: it says no access to treatment devices was obtained, and that all systems are functional. It does not address whether any patient-facing service that sits beside the device — logging, support, adherence tracking — was interrupted. For a device worn for long daily stretches and supported by usage documentation, that surrounding layer is not incidental.

    What to do

    Patients and clinicians: no action is indicated by the filing. NovoCure says devices were not reached and that it will notify affected individuals. If you are treated with an Optune system and want to confirm your status, the company’s patient support line is the route; there is no public lookup.

    Investors and disclosure teams: watch for an 8-K/A. The company has told the market, in writing, what would produce one. Its absence over the coming weeks is itself information.

    Everyone else: the transferable item is the drafting. If your disclosure committee has an incident-response playbook, the paragraph NovoCure wrote — not material today, here is the item we would use, here is the clock — is a template worth stealing, and it costs nothing to have on the shelf before you need it. The second transferable item is less comfortable: the intrusion reached the group “through a subsidiary.” Subsidiary environments are where consolidated identity, shared service accounts, and inherited network trust tend to be least examined, and they are named in a growing share of these filings.

    Sourcing note

    Written from NovoCure Limited’s Form 8-K, SEC accession number 0001645113-26-000065, filed September 1, 2026 and accepted at 7:00:43 a.m. ET, retrieved from EDGAR; all quoted language is transcribed from that filing. Product and corporate details are from novocure.com, checked the same morning, which carries no breach notice. EDGAR full-text search was used to identify 8-K filings mentioning a cybersecurity incident on August 31 and September 1, 2026.

    Not established: the name of the subsidiary, the initial access vector, whether the intruder retained access after containment, whether a ransom demand was made, when patient notifications will go out, and whether the internal patient ID numbers can be mapped to individuals using anything else taken in the same intrusion. NovoCure has not published a statement outside the filing, and no attacker has publicly claimed the incident as of this writing; nothing here should be read as attribution. The description of the SEC staff’s 2024 position on Item 8.01 versus Item 1.05 is a characterization of published guidance, not a quotation from it.

  • In six of today’s ten stories, the authoritative record has nothing to say at all

    In six of today’s ten stories, the authoritative record has nothing to say at all

    The most consequential item on the site today is cPanel’s parked-domain flaw. The vendor’s own advisory says an authenticated account holder who can add a parked or addon domain “can create arbitrary files on the server,” and that “successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.” Fixed builds are named across five branches, so this is a task you can finish tonight. It outranks the bigger-sounding story — Boston Scientific told the SEC that a cybersecurity incident caused a global disruption to its operations, and the clinical detail is worse than the filing, but almost nobody reading this can act on it. What decides the ranking is the second half of the cPanel item: three days after the advisory, CVE-2026-65643 has no record at NVD or the CVE Program, so nothing in your scanner or your ticket queue will raise it on its own. Tonight’s one fixable catastrophic flaw is the one your tooling is guaranteed to miss.

    The day had a thread, and it is yesterday’s failure mode inverted. Yesterday the authoritative record said the wrong thing; today, in six of ten stories, it says nothing at all. cPanel’s CVE has no record. AjaxPro’s record, now on a federal clock, still says no fixed version exists, though the maintainer shipped deserialization controls in November 2021. Two CVE records describe unauthenticated root code execution on the Unitree G1 EDU humanoid, one of them from Bluetooth range with no pairing, and neither the records, the CNA, nor Unitree names a firmware version that fixes it. The argocd-mcp flaw scored 10.0 on Saturday had a public GitHub advisory, and a fix, eighteen days before any CVE was attached to it. libuser’s only modern score says the bug cannot touch confidentiality or integrity, and NVD has published no primary v3 score of its own to arbitrate. And Anthropic’s warning to Claude users exists only as an email, with nothing on the newsroom or the status page.

    Order of business after cPanel. WPMU DEV Dashboard’s second unauthenticated admin bypass this month, CVSS 9.8, fixed in version 5.0.2 on August 24 and hitting exactly the Hub-connected sites the first one missed. Then MCP servers: VulnCheck published thirteen CVEs against thirteen separate projects inside a thirteen-second window on August 27, and the recurring defect — bind to every interface, accept sessions without credentials — is the one that earned argocd-mcp its 10.0. Then the two KEV additions that share a September 9, 2026 federal deadline, libuser and AjaxPro; ten days out rather than this week, and in both cases what an agency has to work around is the record, not the code. Unitree G1 operators have no patch to apply and should treat network and radio range as the only control they have.

    Four items moved without handing anyone a task, though one is worth an hour on your endpoints. Anthropic says commodity infostealers — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, Atomic Stealer on macOS — are lifting Claude sessions off users’ machines, which makes it a workstation problem rather than a vendor one. An extortion group calling itself FulcrumSec put 86 GB, a sample, and a claimed access path behind the Manchester Airports breach. Socket found nineteen wallet-draining Chrome and Edge extensions, five of them bought from the developers who built them. And at Boston Scientific, every patient implanted since August 25 is storing data instead of sending it.

    Still open. CVE-2026-65643 still has no record, and nobody has said which CNA holds it. MAG’s statement, dated August 27 and not updated since, lists four field types; FulcrumSec’s sample shows itineraries and payment amounts, which are not among them. Anthropic has neither confirmed nor disputed the email, and nobody outside the company knows how many accounts received it. No one has named fixed firmware for the Unitree G1. Boston Scientific says the timeline for a full restoration is not yet known. And the September 9 deadline falls a week from Wednesday.

  • Boston Scientific says implanted cardiac devices still work, but patients implanted since August 25 are not transmitting

    Boston Scientific says implanted cardiac devices still work, but patients implanted since August 25 are not transmitting

    The company’s own updates say implanted devices still function and existing remote monitoring still works — but new communicators cannot be activated and new insertable cardiac monitors cannot pair, so every patient implanted since the incident began is storing data instead of sending it.

    What happened

    Boston Scientific identified a cybersecurity incident on Tuesday, August 25, 2026. It filed a Form 8-K with the Securities and Exchange Commission on August 26 and has posted four dated updates to its newsroom since, the most recent on Saturday, August 29, 2026 at 4:55 p.m. ET. Everything below comes from that filing and those updates.

    The 8-K, accession number 0000885725-26-000056, is filed under Item 8.01, Other Events. Its language is worth reading exactly as written: “On August 25, 2026, Boston Scientific Corporation (the ‘Company’) identified a cybersecurity incident affecting certain of its information technology systems that has resulted in a global disruption to the Company’s operations.” The filing continues that the incident “has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders,” and that “the timeline for a full restoration is not yet known.” On materiality the company says plainly that it “has not yet determined whether the incident is reasonably likely to have a material impact on the Company.” Item 1.05, the SEC’s dedicated cybersecurity item, does not appear anywhere in the document.

    The clinically significant detail is not in the filing. It is in the August 28 newsroom update, which breaks the impact down by product line. On cardiac rhythm management devices the company states there are “No known impacts to implantable device function or the ability for remote patient monitoring.” Then the exception: “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted.” For insertable cardiac monitors the same shape appears: “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data will NOT be transmitted.” The capitalization of “NOT” is the company’s own.

    The company also states what happens afterward: “Once systems are restored and pairing with home monitoring equipment occurs, the device will transmit recorded data.” On ordering, customers can submit “orders through the Global Health Exchange (GHX) which will be held until we are back online,” and the August 29 update adds that Boston Scientific is “able to intake orders electronically (through EDI) and place them in a queue for future fulfillment.” That same update reports that “our investigation indicates there is no impact to our cloud-based systems and applications,” locating the damage on premises.

    CrowdStrike and other third-party experts are engaged. No threat actor has claimed the incident on any leak site we could find. Across four updates and one filing, the company has made no statement about whether data was accessed, copied, or removed. That is neither a denial nor a confirmation; it is an absence, and worth naming as one.

    Why it matters

    Start with the asymmetry in the device impact, because it is the part most likely to be misread. An implanted cardiac device is not a server that pages someone when it goes offline. It records, it stores, and it hands data off to a communicator at the patient’s bedside or to a phone app. When that handoff works, the device is a monitored asset. When the handoff was never established in the first place, the device is a functioning implant that no one is watching, and nothing in the monitoring system says so.

    That distinction matters operationally. A clinic’s remote monitoring dashboard shows enrolled patients. A patient implanted on August 27 whose communicator could not be activated was never enrolled, so they do not appear on the dashboard as a gap, an alert, or a missed transmission. They simply are not there. The failure mode is silence in a system whose entire purpose is to break silence, and it is invisible from inside the tool a clinic would normally use to find it. Finding these patients means going to the implant log, not the monitoring console — a manual step no workflow currently prompts.

    The company’s recovery language is genuinely reassuring on one axis and should not be over-read on the other. “The device will transmit recorded data” means the episodes are retained on the device and will arrive once pairing happens. This is a transmission outage, not a data loss event, and that is an important difference. But retained is not reviewed. An arrhythmia recorded on August 27 is read whenever the backlog clears, and the clinical value of remote monitoring is substantially about timeliness. Deferred review is better than lost data and worse than monitoring.

    On the SEC filing, this publication has twice recently reported companies routing cybersecurity disclosures away from Item 1.05 — McKesson under Item 7.01 and Hasbro under Item 8.01. Consistency requires saying that this one looks different. Item 1.05 is triggered by a determination that an incident is material. Boston Scientific states in the filing itself that it has not made that determination, and SEC staff guidance has been explicit that Item 8.01 is the appropriate home for an incident whose materiality is still undetermined. Filing under 8.01 while saying so in terms is the rule working as designed rather than around it. The thing to watch is what follows: if the determination changes, an amended filing under Item 1.05 is what the rule expects, and the absence of one after a global operational disruption of unknown duration would become the story.

    The supply-chain shape deserves attention beyond this company. Order intake still works; fulfillment does not. Orders placed through EDI and GHX enter a queue rather than bouncing. From a hospital materials-management view, that is a system behaving normally right up until the delivery does not arrive, and queued orders do not generate the exception reports that rejected orders do. A manufacturer outage becomes a hospital inventory problem on a delay, and the delay is exactly the period during which the problem looks smaller than it is. Cardiac devices are not commodity supplies with interchangeable vendors; substitution involves physician preference, sizing, and lead selection.

    Finally, note where the damage landed. The company reports no impact to cloud-based systems and applications, with the disruption confined to on-premise systems. For organizations that have spent years being told the cloud is the risk surface, an incident that stops manufacturing and shipping while leaving cloud applications untouched is a useful corrective. It does not make on-premise infrastructure worse than cloud infrastructure. It does mean the systems that move physical goods are often the older, more tightly coupled ones, and that resilience planning aimed at the customer-facing tier does not automatically protect the tier that puts a device on a truck.

    What to do

    If you run a cardiology or electrophysiology program, pull the implant log rather than the monitoring dashboard, and identify every patient who received a Boston Scientific cardiac rhythm management device or insertable cardiac monitor on or after August 25, 2026. Those are the patients whose remote monitoring was never activated. Track them on a manual list until pairing is confirmed, and for any patient in that window with a clinical reason not to wait, schedule an in-office interrogation rather than waiting on restoration with no published timeline.

    Do not tell patients in that group that their data is lost. Per the company, the device retains recorded data and transmits it once pairing occurs. The accurate message is that transmission is delayed, not that recording stopped.

    For materials management, confirm the status of every order submitted through EDI or GHX since August 25, treat all of them as queued rather than in process, and check consignment stock against scheduled cases for the next several weeks. The restoration timeline is stated as unknown, so plan against duration rather than a date.

    For risk and legal teams, the current filing is Item 8.01 with materiality expressly undetermined. Monitor for an amended or subsequent 8-K. If your organization is a customer, the absence of any statement about data access is the open question to put in writing to your account team now, rather than after a notification arrives.

    Sourcing note

    Checked: Boston Scientific’s Form 8-K, accession number 0000885725-26-000056, filed August 26, 2026, read directly from SEC EDGAR — the item designation and all quoted filing language come from that document, and the Item 8.01 designation was independently confirmed through SEC full-text search. Also checked: the company’s newsroom page “Update on recent cybersecurity incident,” which carries dated updates on August 26, 27, 28, and 29, 2026; all device, ordering, and cloud statements quoted above are from that page in the company’s own words.

    Could not reach: cisa.gov returns HTTP 403 to automated fetching, so we could not check for a CISA or sector-specific advisory; none was found through search. We found no FDA safety communication on this incident and no statement from any device-safety regulator. We found no attacker claim on any leak site.

    Unresolved: whether any data was accessed or removed — the company has said nothing on this point across four updates and one filing. Also unresolved: the number of patients implanted during the affected window, which the company has not disclosed and which is not derivable from public information; the initial access vector; and the restoration timeline, which the company states is not yet known. No exploited vulnerability has been named by the company or by any agency, so this page names none.