news.mlab.sh
Back to the feed
threat-intel

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

Medium
Summary

The European Union's Cyber Resilience Act is introducing a 24-hour vulnerability disclosure window, aiming to accelerate the patching of security flaws in hardware and software. This shift represents a significant change in how security vulnerabilities are handled, potentially impacting a wide range of tech companies and products. The move is driven by a desire to improve overall cybersecurity and reduce the window of opportunity for attackers.

The European Union’s Cyber Resilience Act is set to introduce a 24-hour vulnerability disclosure window for hardware and software, a substantial change from the current approach. This means that companies will be required to address security vulnerabilities within 24 hours of receiving a notification. The goal is to proactively address security flaws and minimize the time attackers have to exploit them. The Act intends to create a more secure digital landscape by incentivizing rapid patching and reducing the risk of exploitation.

Several security-related developments are also occurring. Microsoft has been experiencing issues with its on-prem SharePoint, leading to a zero-day attack. Meanwhile, China is upgrading smartphone surveillance tools, and Ring is easing its anti-snooping stance. Acronis, a Swiss cybersecurity firm, was acquired by EQT for a valuation exceeding $3.5 billion. Additionally, the open-source CSS framework Tailwind is now under the stewardship of Shopify, and Audacity, a popular audio-editing tool, has received a visual refresh. The move reflects a broader trend of embracing FOSS (Free and Open Source Software) as a means of achieving greater control over technology and security.

Read the full article at The Register