The CRA reporting clock is running — and the weekend exposed…GitLab file-read flaw enters KEV with Monday’s deadlineRevolut released customer records after fraudulent government requestsScreenConnect joins KEV: check clients and remote-session evidence
Monday flagship · Weekend decision brief
The CRA reporting clock is running — and the weekend exposed an operational caveat
Cyber Resilience Act reporting obligations started on Friday, and ENISA used the weekend to clarify both the operational workflow and a deadline-counter defect that manufacturers must not mistake for the legal clock.
Security.io Intelligence Desk · Monday, 14 September 2026
Executive consequence
Manufacturers of products with digital elements made available in the EU must now operationalise a 24-hour early warning, a 72-hour notification and subsequent final reporting through ENISA’s Single Reporting Platform.
Decision today
Name an accountable CRA reporting owner and deputy.
Read the full decision briefPrimary reporting: European Commission CRA reporting obligations · ENISA CRA Single Reporting Platform FAQ · ITPro
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
GitLab fixed CVE-2026-85706 in 19.1.8, 19.2.6 and 19.3.2. CISA added the unauthenticated repository-API file-read vulnerability to KEV on Friday, placing patch verification and compromise assessment on Monday’s agenda.
Do today
Inventory all self-managed GitLab CE and EE instances.
Revolut confirmed that an unauthorised third party used a legitimate government agency email domain to obtain sensitive customer information. The company says systems and funds were unaffected, while the agency, affected count, markets and technical route remain undisclosed.
Do today
Require out-of-band verification for sensitive government data requests.
ConnectWise released ScreenConnect 26.6.5 for CVE-2026-84869 after an earlier mitigation notice. CISA added the flaw to KEV on Friday, changing the Monday task from advisory tracking to version proof and session-level compromise review.
Do today
Inventory cloud and on-premises ScreenConnect deployments.
Brevo says a SAML SSO boundary failure exposed 138 customer accounts; six sent phishing and 43 had contacts exported. Trezor says roughly 347,000 newsletter addresses were targeted and 2,500 recipients clicked before the malicious destination was disabled.
Do today
Ask communications vendors to attest to post-SSO tenant isolation.