Cyber Resilience Act (CRA) stories
A decade of support has helped operators keep rail, power and factory systems running on Linux without frequent upgrades.
Financial regulators are alarmed after Anthropic said Claude Mythos can uncover software flaws at machine speed, raising bank security risks.
Companies face tougher, more fragmented compliance as governments tie cyber rules to national security, AI use and digital sovereignty.
Most engineering teams could struggle to meet EU Cyber Resilience Act reporting deadlines, with many still handling SBOMs manually or only after incidents.
New EU rules could force access control makers to prove stronger patching, sourcing and disclosure processes as cyberattacks rise.
Red Hat survey finds 97% of organisations hit by cloud-native security incidents, forcing delays, higher costs and loss of customer trust.
Red Hat reports 97% of organisations suffered cloud-native security incidents last year, exposing basic failings in configuration and governance.
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
OpenSSF adds new members and launches AI security, supply chain and training initiatives after securing USD $12.5 million in funding.
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
Secure.com warns most apps hide critical flaws in open source components, as unpatched dependencies and licence risks leave firms exposed.
Ransomware drives over half of UK cyber incidents as data loss surges, with healthcare, retail and complex supply chains hardest hit.
NCC warns that insecure connected farm machinery could let cyber attacks disrupt harvests, cut yields and threaten food supply chains.
Xiid and Cytex join forces to fuse AI governance with zero trust access, targeting shrinking attack paths and stricter cyber regulation.
Industrial AI and IT/OT convergence are forcing factories to abandon closed networks and adopt hybrid, zero trust cyber security architectures.
Codific urges boards to prioritise preemptive cyber defence, identity and supply-chain control as 2026 scrutiny and rules tighten.
ENCS and DIVD have agreed a new cyber pact to uncover and disclose vulnerabilities in Europe's high-impact energy and critical systems.
Umbraco's product arm wins ISO 27001/IEC:2022 certification, boosting security credentials for its open-source .NET CMS and partners.
Brussels moves to tighten EU cyber rules, targeting high risk foreign vendors while streamlining certification and boosting sovereignty.
Vincent Lomba joins ENISA's Advisory Group, bringing industry insight to EU efforts on NIS2, the Cyber Resilience Act and digital sovereignty.