[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-eu-cyber-law-gives-firms-24-hours-to-report-active-hacks":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},6057,"eu-cyber-law-gives-firms-24-hours-to-report-active-hacks","EU Cyber Law Gives Firms 24 Hours to Report Active Hacks","A new EU deadline forces makers of connected products to report actively exploited flaws within 24 hours, starting September 11.","The EU's Cyber Resilience Act starts the clock on hack disclosures next week.\n\nUnder the Cyber Resilience Act, manufacturers selling products with digital elements in the European Union must notify regulators within 24 hours of learning that a vulnerability in their product is being actively exploited. A more detailed follow-up report is due within 72 hours. The rule takes effect September 11. It applies broadly to anything with a digital element sold in the EU, not just traditional software vendors.\n\nThis kind of speed requirement forces companies to build real detection and reporting pipelines instead of quietly patching and hoping nobody notices. It also gives regulators, and by extension the public, a much earlier signal when something in the software supply chain is under active attack, rather than finding out months later in a breach disclosure.\n\nWhether a 24-hour clock actually improves security or just produces a flood of rushed, incomplete filings is the open question - breach-notification deadlines in other sectors have generated plenty of both.","[\"cyber resilience act\",\"eu regulation\",\"vulnerability disclosure\",\"supply chain security\"]","2026-09-03T21:25:02.000Z","2026-09-03T21:52:29.099Z","2026-09-03T21:52:40.970Z","published",null,[],"policy",[26,27,28,29],"cyber resilience act","eu regulation","vulnerability disclosure","supply chain security",[31],{"name":32,"url":33},"The Next Web","https:\u002F\u002Fthenextweb.com\u002Fnews\u002Fcra-24-hour-deadline-software-supply-chain-sbom",0,{"sections":36},[37,42,47,51,56,61,66,71,76,81,86,91,96,101],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":43,"slug":44,"count":45,"latest_published_at":46},"Security","security",565,"2026-09-05T00:03:08.000Z",{"name":48,"slug":24,"count":49,"latest_published_at":50},"Policy",300,"2026-09-04T22:18:34.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]