#EU Cyber Resilience Act
5 stories taggedEU Cyber Resilience Act.

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.
The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.
A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

AI Finds the Bugs in Hours. Fixing Them Still Takes Months.
Artificial intelligence is now fast enough to discover serious security flaws in widely used software within hours. The human systems needed to patch those flaws haven't come close to keeping pace, and the gap is growing.

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report
A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.