Severity Daily

IT and AI security incidents, checked against the primary source

Tag: Nutex Health

  • Four of today’s nine stories are about the gap between a fix and the record of it

    Four of today’s nine stories are about the gap between a fix and the record of it

    The item to act on tonight is Ruby on Rails, and it is not the biggest-sounding thing that happened today. Rails’ patch for CVE-2026-66066 stops the file read that leaks secret_key_base. It does not stop the Marshal deserialization gadget that read exposed, which still executes on a fully patched server for anyone holding a valid key. An organization that upgraded in early August and did nothing else is closed to the theft and still open to code execution by whoever completed the theft first. Patch status and compromise status have come apart here, and the step that reconciles them — rotating secret_key_base and every other secret readable from the application process — is the one no scanner reports as missing. VulnCheck says exploitation began the week of August 24. That claim is thin, and it is not what should decide this: a working exploit against more than 7,100 exposed instances has been public since August 7.

    Bigger headlines were available today, and both of them shrank on inspection. The Justice Department rewrote its China hacking announcement so that NASA, the Federal Reserve, and the Senate are now “among the targets” of QTFY rather than its victims — a withdrawal, not an escalation. And a 9.8 critical CVE for the open-source project hulumi turns out to describe an over-permissive IAM policy in the project’s own CI sandbox account, a resource nobody who installs hulumi has.

    The day did have a thread, and it is a narrow one: in four of the nine stories, the fix and the record of the fix do not match. Rails is one. Nodemailer’s new 9.8 names 8.0.3 as the fixed version, and the 8.0.3 tarball on npm still carries the vulnerable line. Eight MCPHub CVEs published within a single second this afternoon carry fixes shipped between April 22 and August 23 — the critical remote code execution among them was fixed in May and disclosed today. And Eclipse Theia’s agent-mode workspace escape, an 8.8 that let the AI agent write and delete files outside the workspace on a model-supplied path, was closed in a release whose notes described the change only as a breaking API change. The engineering is not the failure in any of the four. The patch exists in all of them. What is unreliable is the thing a vulnerability management program actually reads.

    Second for most shops is Microsoft’s confirmation that Windows is falsely reporting Defender as turned off across effectively every supported client and server version, with no originating update to roll back, no named build to compare against, and alerts that persist even when notification settings are off. Expect it at the service desk at boot tomorrow, and brief staff with Get-MpComputerStatus rather than “ignore it” — the alert being trained out is the tamper signal.

    Then the rest. Seven ToolJet CVEs describe the same cross-tenant authorization gap in tooljet-db, and the worst of them carries a 9.9 and a 2.4 from the same scorer in the same record, against the vendor’s own 5.9. Nutex Health refiled its August 24 breach disclosure under Item 1.05 seven days later without adding the materiality determination that item exists for — a change of flag that automated screening will read and the filing’s own text contradicts.

    Still open: Microsoft has named neither the Defender build that causes the false alert nor a fix date. VulnCheck has published no correction on the ToolJet scoring conflict or the Nodemailer fixed-version range. The Justice Department has not said which, if any, of the seven named bodies QTFY actually compromised, and the pre-edit wording survives only in contemporaneous reporting. Nutex has not said whether it made a materiality determination, and the affected-individual count will come from state and federal breach portals, not EDGAR. And the Rails exploitation claim still rests on one social media post that VulnCheck’s own weekly report for that week does not list.

  • Nutex Health moved its breach disclosure to Item 1.05 seven days after filing it under 8.01

    Nutex Health moved its breach disclosure to Item 1.05 seven days after filing it under 8.01

    Nutex Health disclosed the same data-theft incident twice in seven days — first as an Item 8.01 “other event,” then, in an after-close filing on Monday, under Item 1.05, the item reserved for cybersecurity incidents a company has determined to be material.

    What happened

    Nutex Health Inc. (NASDAQ: NUTX), the Houston-based physician-led operator of micro-hospitals and outpatient clinics, filed a Form 8-K with the Securities and Exchange Commission on Monday, August 31, 2026. EDGAR stamped it accepted at 4:25 p.m. ET, after the closing bell.

    The filing carries one item: Item 1.05, Material Cybersecurity Incidents. It is accession number 0001628280-26-059602, and its cover-page XBRL sets the amendment flag to false. That detail matters: this is not an 8-K/A amending an earlier report but a new current report, filed under a different item, about an incident the company had already disclosed.

    The earlier disclosure was accession number 0001628280-26-058606, filed Monday, August 24, 2026, with a period of report of the same date. It carries a single item as well: Item 8.01, Other Events. In it, Nutex said it had identified unauthorized activity on its computer network, had engaged outside cybersecurity experts and notified law enforcement, and believed “certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party.” The August 24 filing added that the company “does not believe that the unauthorized access has had, or is reasonably likely to have, a material impact” on its business strategy, operations, financial condition, or results of operations.

    The August 31 filing repeats the substance. The company again says information on its servers was accessed and exfiltrated, again identifies patient, employee, and business or financial data as the categories under assessment, and again states that it has not identified any material impact on its business operations or financial reporting systems. It adds that the unauthorized party has threatened to publish the stolen information, that Nutex intends to make the notifications its findings require, including to affected patients, and that a putative class action — Haley v. Nutex Health, Inc., No. 4:26-cv-07197, filed August 27, 2026, in the U.S. District Court for the Southern District of Texas — is now pending. The company says it cannot predict the outcome of that suit.

    What the August 31 filing does not contain is a sentence saying the company has now determined the incident to be material. Item 1.05 exists for exactly that determination. The filing arrives under that item while still carrying the no-material-impact language that belonged to the August 24 Item 8.01 report.

    Nutex has not published a record count or named an attacker, and no extortion group has publicly claimed the intrusion. The filings give no date of intrusion and no date of discovery, only the August 24 date of earliest event reported.

    Why it matters

    The two items are not interchangeable, and the distinction was built deliberately. When the cybersecurity disclosure rules took effect, the SEC’s Division of Corporation Finance addressed a specific worry in a May 21, 2024 statement: companies were filing under Item 1.05 defensively, before they had made any materiality determination, and the result was that the item stopped meaning anything. The staff’s answer was to point voluntary and undetermined disclosures to Item 8.01 and to keep Item 1.05 for incidents actually determined material, so that investors could tell one from the other at a glance.

    Read against that, the Nutex sequence is the well-behaved one. A company discovers an intrusion, does not yet know how bad it is, files under 8.01 to get the fact on the record, and moves to 1.05 when the determination lands. That is the path the staff described. Item selection is the signal, and a company that changes item is telling investors something changed.

    Which is why the missing sentence is the finding. If a determination was made between August 24 and August 31, the second filing is where it should appear, and it does not appear there. Instead the reader gets an Item 1.05 heading sitting above language stating that no material impact has been identified — two claims that point in opposite directions, in the same document, without a word reconciling them.

    There are readings that do not involve a determination at all. The class action landed on August 27, three days after the first filing and four days before the second, and counsel weighing a securities-fraud tail risk may simply prefer the stronger item on the theory that no one is ever sued for filing a 1.05 where an 8.01 would have done. Nutex has not said which, and this publication is not going to guess. The observable fact is the item change and the absence of any explanation for it.

    The practical consequence lands on anyone who tracks 8-K cyber disclosures programmatically, which now includes a good deal of the insurance, credit, and vendor-risk industry. Item 1.05 is a machine-readable flag. Dashboards count it, screens sort on it, and a fair number of downstream systems treat a 1.05 as an issuer’s own statement that an incident was material. When the body of a 1.05 filing says the opposite of the item it is filed under, the flag and the text disagree, and only the flag travels. This is a recurring shape on this site: the structured field and the prose diverge, and the structured field is the one everyone actually reads.

    The healthcare context sharpens it. Nutex operates emergency and micro-hospital facilities, so the records on those servers are patient records, and the notification obligations that follow are not SEC obligations. HIPAA breach notification and the state attorney general regimes run on their own clocks and their own thresholds, and none of them care what item an 8-K was filed under. A company can hold that an incident is immaterial to its financial condition and still owe individual notice to a large number of people. Those are simply different questions, and the securities filing answers only one of them. Readers waiting for the 8-K to tell them how many people were affected are waiting for the wrong document; that number, when it exists, will surface in state attorney general portals and in the U.S. Department of Health and Human Services breach portal, and it will surface later.

    Finally, the timing is worth naming. The second filing was accepted at 4:25 p.m. ET, half an hour after the close. That is a legitimate and extremely common filing window. It is also the window in which disclosures reliably get the least attention, which is why this publication checks EDGAR again at the end of the day rather than only in the morning.

    What to do

    If you are a Nutex patient or employee: there is nothing to act on yet beyond ordinary hygiene. The company says it intends to notify affected individuals once its assessment identifies them. Watch for a mailed notice, and be skeptical of email or phone contact claiming to be that notice — breach notifications are a favored pretext, and this one is now public enough to imitate.

    If you screen 8-K cyber filings: stop treating the item number as the materiality determination. Check whether the body of the filing contains an affirmative determination sentence, and flag filings where it does not. The Nutex pair is a clean test case for that logic: an 8.01 and a 1.05, seven days apart, with substantially the same body text.

    If you are a filer: if you move an incident from Item 8.01 to Item 1.05, say in the second filing what changed. A one-sentence statement that the company has determined the incident to be material costs nothing and removes the ambiguity entirely. Leaving the earlier no-material-impact language in place under the new item creates a document that contradicts itself on its face.

    If you are a Nutex counterparty: the exfiltrated categories named in the filings include business and financial information, and Nutex says the unauthorized party has threatened publication. That is the company’s characterization, not a confirmed leak. Treat it as a reason to check what of yours sits in their environment, not as a reason to assume it is public.

    Sourcing note

    Both 8-K filings were read on EDGAR: accession 0001628280-26-058606, filed August 24, 2026 under Item 8.01, and accession 0001628280-26-059602, filed August 31, 2026 under Item 1.05, with acceptance time and item designation taken from the filing index and the amendment flag from the cover-page XBRL. Quoted language is reproduced from the filings as filed. A third Nutex 8-K filed August 13, 2026 also carries Item 8.01 but concerns the Fifth Circuit’s Texas Medical Association v. HHS decision on the No Surprises Act and is unrelated to the incident; it is noted here so that anyone counting Nutex 8.01 filings does not miscount.

    The class action caption, number, court, and filing date are as stated in the August 31 filing; the docket itself was not retrieved. No record count, no date of intrusion, and no date of discovery appears in either filing, and none is asserted here. No extortion group had publicly claimed the intrusion at the time of writing; the threat to publish is reported by Nutex, not observed here. Trade coverage of the August 24 filing was used only to confirm that the earlier disclosure had been reported.

    Unresolved: whether Nutex made a materiality determination between August 24 and August 31, and if so why the August 31 filing does not say so. This site did not seek comment. Also unresolved: how many individuals are affected, which will not come from EDGAR.