๐Ÿท๏ธ Cyber-Resilience-Act

4 articles tagged Cyber-Resilience-Act.

Twenty-Four Days: What the CRA's Reporting Clock Actually Changes for Offices That Buy Devices

Twenty-Four Days: What the CRA's Reporting Clock Actually Changes for Offices That Buy Devices

On 11 September the EU Cyber Resilience Act's reporting obligations switch on: 24 hours for an early warning, 72 for a full notification, 14 days after a fix for the final report. Almost every guide is written for manufacturers. If you buy and operate devices rather than make them, here is what actually changes โ€” and the six questions to add to procurement this month.

Root Before Login: A Camera Zero-Day, a One-Year Disclosure Timeline, and the OEM Firmware Nobody Owns

Root Before Login: A Camera Zero-Day, a One-Year Disclosure Timeline, and the OEM Firmware Nobody Owns

A format string bug in a camera's JSON parser gives an unauthenticated attacker root. The vendor took a year and still had no fix when the advisory dropped. The uncomfortable part isn't the bug โ€” it's that the vulnerable binary was written by a different company than the one on the box, and nobody in your office knows which brands share it.

The Credential Reckoning: Smart Office Security in the First Half of June 2026

The Credential Reckoning: Smart Office Security in the First Half of June 2026

In two weeks, CISA published three IoT advisories covering smart doorbells, cameras and a yard robot โ€” every headline flaw a hardcoded or default credential. Acer shipped fixes for two CVSS 10.0 mesh-router zero-days, Cisco confirmed active exploitation of an SD-WAN Manager flaw, and a multi-agency advisory warned of attacks on internet-exposed fuel-tank gauges. All of it lands as the EU Cyber Resilience Act's 24-hour reporting clock counts down to September 11.

Ninety Days to the Clock: What the EU Cyber Resilience Act's 24-Hour Reporting Rule Means for Connected Offices

Ninety Days to the Clock: What the EU Cyber Resilience Act's 24-Hour Reporting Rule Means for Connected Offices

From September 11, 2026, manufacturers of connected products sold in the EU must report actively exploited vulnerabilities to ENISA within 24 hours. The obligation reaches routers, cameras, smart-building devices and OT, carries fines up to โ‚ฌ15 million or 2.5% of global turnover, and reshapes how buyers should evaluate vendors. With roughly 90 days to go, two-thirds of vendors say they are still unfamiliar with the regulation.

โ† All topics

Ask Sage ๐Ÿค–