Weekend lead:The CRA reporting clock is running — and the weekend exposed…GitLab file-read flaw enters KEV with Monday’s deadlineRevolut released customer records after fraudulent government requestsScreenConnect joins KEV: check clients and remote-session evidence
Front page · Monday intelligence
The CRA reporting clock is running — and the weekend exposed an operational caveat
Cyber Resilience Act reporting obligations started on Friday, and ENISA used the weekend to clarify both the operational workflow and a deadline-counter defect that manufacturers must not mistake for the legal clock.
By Security.io Intelligence Desk · Executive analysis
Manufacturers of products with digital elements made available in the EU must now operationalise a 24-hour early warning, a 72-hour notification and subsequent final reporting through ENISA’s Single Reporting Platform.
Why today: This ranked first because the underlying Act is older, but its Article 14 reporting duties became legally operative on 11 September 2026 and ENISA added an operational counter warning on 12 September. That combination changed today’s decision from…
“Name an accountable CRA reporting owner and deputy.”
Decision owner: Chief Product Security Officer with General Counsel and EU regulatory leadership
Decision horizon: Immediate: establish filing readiness today; the first early-warning decision may be due within 24 hours of awareness.
Manufacturers of products with digital elements made available in the EU must now operationalise a 24-hour early warning, a 72-hour notification and subsequent final reporting through…
Monday action: Name an accountable CRA reporting owner and deputy.
GitLab fixed CVE-2026-85706 in 19.1.8, 19.2.6 and 19.3.2. CISA added the unauthenticated repository-API file-read vulnerability to KEV on Friday, placing patch verification and compromise assessment on…
Monday action: Inventory all self-managed GitLab CE and EE instances.
Revolut confirmed that an unauthorised third party used a legitimate government agency email domain to obtain sensitive customer information. The company says systems and funds were…
Monday action: Require out-of-band verification for sensitive government data requests.
ConnectWise released ScreenConnect 26.6.5 for CVE-2026-84869 after an earlier mitigation notice. CISA added the flaw to KEV on Friday, changing the Monday task from advisory tracking…
Monday action: Inventory cloud and on-premises ScreenConnect deployments.
Brevo says a SAML SSO boundary failure exposed 138 customer accounts; six sent phishing and 43 had contacts exported. Trezor says roughly 347,000 newsletter addresses were…
Monday action: Ask communications vendors to attest to post-SSO tenant isolation.
Signal desk
Interactive editorial evidence
Monday decision pressure
Security.io executive pressure score
Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.
Scores are Security.io editorial assessments from 0–100. Exposure reflects affected operating models, urgency reflects the shortest decision window, and business consequence reflects regulatory, data, control-plane and recovery impact.
Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.
This line shows cumulative cited references across the lead and four supporting briefs.