[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
|
Re: [open-regulatory-compliance] 24(3) not referencing 14(2), 14(4)
|
On 7 Sep 2026, at 17:06, Daniel Thompson-Yvetot via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:
> But Dirk, why do you say nothing will be reported? If it’s indeed a KEV with actual IoC in the manufacturer’s product, then the incident must be reported under threat of penalties. A manufacturer suffering under an exploit or severe incident cannot just walk away from their problem because the “fault” lies in some OSS component.
Right - if they are aware of this exploit.
In 99 of the 100 historic cases - they never ware -- only the open source foundations were. Even today - a lot of manufactures still ship with vulnerable log4j code.
So my thesis is that 9 out of 10 of the qualifying things won't be reported - as the open source foundations will not inform their downstream normally until they have a patch. The manufacturer never hear of it in time.
Dw