Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] 24(3) not referencing 14(2), 14(4)

On 7 Sep 2026, at 17:06, Daniel Thompson-Yvetot via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:

> But Dirk, why do you say nothing will be reported? If it’s indeed a KEV with actual IoC in the manufacturer’s product, then the incident must be reported under threat of penalties. A manufacturer suffering under an exploit or severe incident cannot just walk away from their problem because the “fault” lies in some OSS component.

Right - if they are aware of this exploit.

In 99 of the 100 historic cases - they never ware -- only the open source foundations were. Even today - a lot of manufactures still ship with vulnerable log4j code.

So my thesis is that 9 out of 10 of the qualifying things won't be reported - as the open source foundations will not inform their downstream normally until they have a patch. The manufacturer never hear of it in time.

Dw



Back to the top