| |
A scan of 623 European software vendors found that 76% lack a security.txt file, leaving researchers without a standard way to privately report vulnerabilities ahead of the EU Cyber Resilience Act's August 2026 deadline. Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities to authorities within 24 hours of discovery, but three-quarters of EU vendors have no official channel for researchers to contact them, potentially forcing public disclosure that starts the reporting clock under the worst circumstances.
Read Full Article →
← More Tech news