Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Update on reporting obligations for open source software stewards

On Sun, Sep 6, 2026 at 12:26 Arnout Engelen via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:
On Sun, Sep 6, 2026, at 12:15, August Bournique via open-regulatory-compliance wrote:
So the distinction between an actively exploited vulnerability and a severe incident is somewhat vague to me - both require an attacker to be doing or have done somethign to the product ... 
It's easy to find severe incidents that don't involve exploited vulnerabilities: insider threats, brute-forced weak passwords, misconfigured machines, etc etc.

You can also imagine incidents that involve software that isn’t subject to the CRA, for example because it is not placed on the EU market (it could be just internal software, for example) or is strictly a service.

—tobie

Back to the top