LOWVulnerability
Verified
United States

SEC Proposes Updated Cybersecurity Incident Reporting Rules for Public Companies

·Source: SEC

Updated:

Executive Summary

SEC proposes amendments requiring public companies to report material cyber incidents within 48 hours, down from 4 business days.

Analysis

The SEC has proposed amendments to its cybersecurity incident reporting rules that would shorten the material incident reporting deadline from four business days to 48 hours. The proposal also requires quarterly disclosure of cyber risk management metrics and board-level cyber expertise. The rule change comes after criticism that the current four-day window allows too much time for market manipulation. Public comment period runs through May 2026.
Source Attribution

Originally published by SEC on Mar 7, 2026. Verified by: SEC.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-15896 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au

CVE-2026-15896
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-19660 — The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass ...

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled

CVE-2026-19660
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-14378 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi...

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

CVE-2026-14378
NIST NVD