Skip to content
tag — vulnerability-disclosure

grep -rl "vulnerability-disclosure" ./articles

#vulnerability-disclosure

4 articles

Europe's 24-hour exploit-reporting clock reaches products sold years ago. Its security rules do not

2026-09-15World

Since 11 September, manufacturers selling connected products in the EU must warn authorities within 24 hours of learning that a flaw in one is being exploited. The Cyber Resilience Act applies that duty to products already on the market, while its security requirements reach only those placed on the market from December 2027. For a device already on sale, the Act now requires the report, but not the patch.

They knew every chain was at risk on 13 August. They shipped the fix quietly anyway

2026-08-31Security

A Cosmos EVM flaw let attackers underflow account balances to roughly 2^256. Cosmos Labs learned on 13 August that every chain running its software was affected, patched on the 19th without private notification, and a public pull request in a fork spelled out the exploitation path on the 20th. Six chains were drained.