BLOGSEM Devs
Articles on software development, web and technology
Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026
The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.
WP2Shell: the WordPress flaw that needs no login
On 17 July WordPress closed WP2Shell, a two-CVE chain giving unauthenticated code execution on a clean install, and the first attempts landed within hours. What we checked across the sites we maintain, and why patched does not mean clean.
One year of NIS2: what we actually learned implementing it
Twelve months after Italian Decree 138/2024 came into force, we walked seven companies through the path. Five things that make the difference, and three that can be skipped.
Zero-trust for SMEs: how it really gets done, without snake oil
Zero-trust is the most overused term in cybersecurity. For an SME, what does it actually mean, where do you start, and what does it cost.