EU Cyber Resilience Act's 24-hour breach reporting deadline arrives September 2026
An open-source maintainer describes receiving an extortion attempt disguised as a bulk vulnerability report—95 claimed flaws, only two or three real—followed by a $100,000 ransom demand threatening public disclosure. He argues this scenario foreshadows a legal reality coming for far more companies: starting September 11, 2026, the EU Cyber Resilience Act requires any manufacturer selling connected products into the EU to notify ENISA within 24 hours of learning that a vulnerability in their product is being actively exploited.