logo

Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time

ID: a9a3c606-a7af-52fc-abfb-243ad0294c24

STIX ID: report--a9a3c606-a7af-52fc-abfb-243ad0294c24

Feed Name: Help Net Security

Date Published: 2026-04-15

Date Updated: 2026-04-28

Author: Mirko Zorz

...
...

An interview with ENISA’s Nuno Rodrigues Carvalho about the recent CVE program funding scare and what it revealed about the fragility of global vulnerability disclosure. The piece outlines how EU regulations (Cyber Resilience Act, NIS2) and ENISA’s expansion of European vulnerability services aim to strengthen accountability, improve coordinated disclosure, and reduce single points of failure in the CVE ecosystem; it contains policy and operational analysis rather than technical indicators or exploit details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.