Tag

#EU Cyber Resilience Act

5 stories taggedEU Cyber Resilience Act.

Illustration for the story: CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
Policy & Regulation

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means

The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

4 min read
Illustration: a large industrial server room at night
Policy & Regulation

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.

The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

4 min read
A calendar showing September 11 highlighted in red with notification badges, surrounded by software vendor communication interfaces and vulnerability disclosure
Policy & Regulation

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.

A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

4 min read
A split timeline visualization: on the left, an AI system rapidly discovering security bugs with green checkmarks appearing in seconds, on the right, a slow man
AI Security

AI Finds the Bugs in Hours. Fixing Them Still Takes Months.

Artificial intelligence is now fast enough to discover serious security flaws in widely used software within hours. The human systems needed to patch those flaws haven't come close to keeping pace, and the gap is growing.

4 min read
Illustration: a circuit board with dense rows of chips and soldered components
Policy & Regulation

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report

A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

3 min read
© 2026 Threat Vectr