Cyber Resilience Act: under three weeks to 11 September
In July we explained why the CRA's first binding deadline is 11 September 2026, not 2027. Now time is up: from 11 September the 24 and 72-hour clocks for exploited vulnerabilities start. The final checklist, no theory.
Next.js flags a critical patch for 26 August: get ready now
Vercel did something rare and right: it gave advance notice that a patch for a critical Next.js vulnerability lands on 26 August, in versions 16.3.3 and 15.5.24. The details come that day. What to do in the days before so you do not eat the exploitation window.
The worm that infected keyv: inside August's npm supply chain attack
On 4 August the GitHub account of the keyv maintainer was compromised, 127 million weekly downloads, and within two days a self-propagating worm poisoned over 1,300 package versions. You do not need to use keyv to be hit. What we checked across client pipelines.
Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026
The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.
WP2Shell: the WordPress flaw that needs no login
On 17 July WordPress closed WP2Shell, a two-CVE chain giving unauthenticated code execution on a clean install, and the first attempts landed within hours. What we checked across the sites we maintain, and why patched does not mean clean.
One year of NIS2: what we actually learned implementing it
Twelve months after Italian Decree 138/2024 came into force, we walked seven companies through the path. Five things that make the difference, and three that can be skipped.
Zero-trust for SMEs: how it really gets done, without snake oil
Zero-trust is the most overused term in cybersecurity. For an SME, what does it actually mean, where do you start, and what does it cost.
NIS2 in Italy: October 17 is here, and Decree 138/2024 is reality
Italian Decree 138/2024 is now in the Official Gazette. What it operationally means for companies in the NIS2 scope, and what to do in the next 90 days.
NIS2: the new EU cybersecurity directive (and why it hits SMEs too)
The NIS2 directive lands in Italy in 2024. The scope is far wider than NIS1: who is affected, what to do, and where to start.