Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

EU Cyber Resilience Act Gap Assessment:Key Areas to Review Before the September 2026 Deadline

Rate this post Last Updated on July 22, 2026 by Narendra Sahoo Most compliance teams have filed the EU Cyber Resilience Act under “2027” — the date the regulation becomes fully applicable. That’s the wrong filing date. From 11 September 2026, manufacturers must already report actively exploited vulnerabilities and severe incidents affecting products with digital elements, more than a year before the rest of the regulation takes effect.

When the Breach Isn't Yours, But the Risk Still Might Be

Every time a cyber breach breaks headlines, leadership teams pose the same urgent question: Does this affect us? But a third-party risk team is likely already asking: Was one of our vendors, suppliers, partners, or other third parties involved? And increasingly: What if it was not our direct vendor, but one of theirs?

The New Face of AI Risk

Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’. But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines.

Finding eight high-severity vulnerabilities in NodeBB in six hours

TL;DR While improving our AI Pentest, we ran a whitebox assessment on NodeBB, a forum software powered by NodeJS. The result? Eight high-severity vulnerabilities that would all be exploitable on default instances of NodeBB. This includes Cross-Site Scripting (XSS), two of which require interaction with a custom Federation server that the AI agent had to set up itself. Another affects practically every input on NodeBB due to a template injection.

Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.

Oracle's July 2026 Critical Patch Update (CPU) is nearly three times larger than any release in the company's history. To understand it, we parsed all 23 of Oracle's quarterly advisories going back to 2021, matched them against the official CVE record, and compared Oracle against eight other major vendors. We set out to answer three questions: How much of this is genuinely new? Does it really reflect AI-accelerated patching? And how unusual is it?

Security Strategies That Help Minimize Data Breach Risks

Data compromises happen daily, creating massive headaches for companies of all sizes. Cyber criminals constantly find fresh entry points into modern networks. Smart business leaders focus on proactive defense methods to stay ahead of bad actors. Simple systemic upgrades can keep sensitive customer records safe from harm.