The European Union's Cyber Resilience Act (CRA), which requires the quasi-immediate notification of actively exploited vulnerabilities in digital products, came into effect in September. The EU wants to ensure that when a manufacturer of such a device or software learns that a security flaw is already being exploited, the information cannot be swept under the rug and remain an internal problem for the company.
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
The European Union's Cyber Resilience Act (CRA), which requires the quasi-immediate notification of actively exploited vulnerabilities in digital products, came into effect in September. The EU wants to ensure that when a manufacturer of such a device or software learns that a security flaw is already being exploited, the information cannot be swept under the rug and remain an internal problem for the company.