Security.io Intelligence DeskSunday, 13 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekend Intelligence Edition
Free to readers
Supported by underwriters
Weekend lead:The CRA reporting clock is running — and the weekend exposed…GitLab file-read flaw enters KEV with Monday’s deadlineRevolut released customer records after fraudulent government requestsScreenConnect joins KEV: check clients and remote-session evidence
Front page · Monday intelligence

The CRA reporting clock is running — and the weekend exposed an operational caveat

Cyber Resilience Act reporting obligations started on Friday, and ENISA used the weekend to clarify both the operational workflow and a deadline-counter defect that manufacturers must not mistake for the legal clock.

Manufacturers of products with digital elements made available in the EU must now operationalise a 24-hour early warning, a 72-hour notification and subsequent final reporting through ENISA’s Single Reporting Platform.

Why today: This ranked first because the underlying Act is older, but its Article 14 reporting duties became legally operative on 11 September 2026 and ENISA added an operational counter warning on 12 September. That combination changed today’s decision from…
“Name an accountable CRA reporting owner and deputy.”

Decision owner: Chief Product Security Officer with General Counsel and EU regulatory leadership

Decision horizon: Immediate: establish filing readiness today; the first early-warning decision may be due within 24 hours of awareness.

Continue the lead analysis →

Full source ledger, evidence of closure and escalation triggers appear in the article.

1Dominant story selected for executive consequence
4Supporting developments, tightly edited
7 minTarget time to understand the weekend
0Programmatic banners, pop-ups or paywalls

The weekend ledger

Selected for consequence, not social volume
Vulnerability Management

GitLab file-read flaw enters KEV with Monday’s deadline

GitLab fixed CVE-2026-85706 in 19.1.8, 19.2.6 and 19.3.2. CISA added the unauthenticated repository-API file-read vulnerability to KEV on Friday, placing patch verification and compromise assessment on…

Monday action: Inventory all self-managed GitLab CE and EE instances.

Data Protection

Revolut released customer records after fraudulent government requests

Revolut confirmed that an unauthorised third party used a legitimate government agency email domain to obtain sensitive customer information. The company says systems and funds were…

Monday action: Require out-of-band verification for sensitive government data requests.

Vulnerability Management

ScreenConnect joins KEV: check clients and remote-session evidence

ConnectWise released ScreenConnect 26.6.5 for CVE-2026-84869 after an earlier mitigation notice. CISA added the flaw to KEV on Friday, changing the Monday task from advisory tracking…

Monday action: Inventory cloud and on-premises ScreenConnect deployments.

Signal desk

Interactive editorial evidence
Monday decision pressure

Security.io executive pressure score

Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.

Scores are Security.io editorial assessments from 0–100. Exposure reflects affected operating models, urgency reflects the shortest decision window, and business consequence reflects regulatory, data, control-plane and recovery impact.

Higher scores indicate greater executive consequence, urgency and decision value. Security.io editorial scoring is a prioritisation aid, not a prediction of incident probability.Source: Security.io editorial assessment using evidence from the five selected stories and their cited sources.
Evidence accumulated across the edition

Verified references behind today’s five decisions

Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.

This line shows cumulative cited references across the lead and four supporting briefs.

primary: 9 · research: 0 · reporting: 7 · context: 0

Appointments, dinners & sponsored intelligence

Paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →