EU product-security reporting clock starts todayAdaptHealth breach scope reaches 4.1 million peopleCheck Point VPN flaws expose gateways and management serversLiteLLM defaults turn AI gateways into credential exposure paths
Published 06:00 America/New_York · Executive decision brief
EU product-security reporting clock starts today
Manufacturers placing connected hardware or software on the EU market must now notify actively exploited vulnerabilities and severe product-security incidents through ENISA’s reporting platform.
Security.io Intelligence Desk · Friday, 11 September 2026
Executive consequence
Article 14 reporting under the EU Cyber Resilience Act applies from today. Covered manufacturers need a defensible process for recognising a reportable indication, submitting the 24-hour warning, enriching it within 72 hours and coordinating subsequent reports without compromising investigation or3.
Decision today
Name the accountable CRA reporting executive and two deputies.
Read the full decision briefPrimary reporting: European Commission — CRA reporting obligations · ENISA — Single Reporting Platform FAQ · EUR-Lex CRA legislative summary · Dark Reading
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
AdaptHealth’s earlier material-incident disclosure has been followed by reporting that 4,115,802 people were affected. The intrusion began with social engineering of a third-party contractor session and reached cloud applications containing patient, health-insurance and billing information.
Do today
Review contractor authentication methods and active cloud sessions.
Check Point disclosed CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate-processing vulnerabilities capable of unauthenticated remote code execution. CERT-EU now urges immediate hotfixing of affected perimeter and management appliances.
Do today
Inventory every affected Check Point appliance and release branch.
Wiz found 294 of 3,074 public LiteLLM instances in a point-in-time sample accepted the example master key or required no authentication. Older vulnerable versions could combine that access with container-level code execution and credential theft.
Do today
Discover every LiteLLM gateway across cloud and development accounts.
Treasury designated Xinbi Guarantee and two supporting technology companies, while DOJ reported more than US$52 million restrained across marketplace and vendor wallets. The action creates immediate sanctions, payment-monitoring and fraud-intelligence work.
Do today
Load the new designations into authorised sanctions-screening systems.