* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Monday, May 12, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    John Legend Says He’s Shocked by Ye’s ‘Descent’ Into ‘Antisemitism’ and ‘Anti-Blackness’ – Yahoo

    John Legend Expresses Shock Over Ye’s Troubling Descent into Antisemitism and Anti-Blackness

    Free Flowin’ Fest brings entertainment to Pascagoula’s Beach Park – WLOX

    Experience the Excitement: Free Flowin’ Fest Lights Up Pascagoula’s Beach Park!

    ‘Experimental entertainment venue’ sets sights on Austin area – MySA

    ‘Experimental entertainment venue’ sets sights on Austin area – MySA

    Taylor Swift’s team calls subpoena in Blake Lively-Justin Baldoni case ‘tabloid clickbait’ – Yahoo

    Taylor Swift’s Team Slams Subpoena in Blake Lively-Justin Baldoni Case as ‘Tabloid Clickbait

    The Weeknd made the apocalypse sexy at his 2025 tour launch in Arizona – Yahoo

    The Weeknd Turns Up the Heat at His 2025 Tour Launch in Arizona!

    Flutter Entertainment eyes U.S. prediction markets amid growing interest – Sports Business Journal

    Flutter Entertainment Sets Its Sights on U.S. Prediction Markets as Interest Soars

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Well completions per location more than double in Lower 48 states as technology advances – U.S. Energy Information Administration (EIA) (.gov)

    Revolutionizing Oil Production: Lower 48 States See Doubling of Well Completions Thanks to Technological Breakthroughs!

    Officials announce massive project that could reshape electric vehicle technology: ‘This is exactly the type of investment that will help us grow the economy’ – Yahoo Finance

    Game-Changer Ahead: Major Investment Set to Transform Electric Vehicle Technology and Boost the Economy!

    Federal agents raid Dymeng Technology Solutions in St. Augustine – Action News Jax

    Federal Agents Storm Dymeng Technology Solutions in St. Augustine: What You Need to Know

    SoundHound’s Amelia 7.0 Platform Delivers Agentic AI With Category Leading Voice Technology – Business Wire

    Unleashing the Future: SoundHound’s Amelia 7.0 Revolutionizes Voice Technology with Agentic AI

    Comings and goings: MPT hires VP of technology, NPR announces changes to Business Desk – Current – For people in public media

    Exciting Leadership Changes: MPT Welcomes New VP of Technology and NPR Revamps Business Desk!

    Harnessing emerging technologies to power a small business – The Oaklandside

    Unlocking Success: How Emerging Technologies Can Transform Your Small Business

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    John Legend Says He’s Shocked by Ye’s ‘Descent’ Into ‘Antisemitism’ and ‘Anti-Blackness’ – Yahoo

    John Legend Expresses Shock Over Ye’s Troubling Descent into Antisemitism and Anti-Blackness

    Free Flowin’ Fest brings entertainment to Pascagoula’s Beach Park – WLOX

    Experience the Excitement: Free Flowin’ Fest Lights Up Pascagoula’s Beach Park!

    ‘Experimental entertainment venue’ sets sights on Austin area – MySA

    ‘Experimental entertainment venue’ sets sights on Austin area – MySA

    Taylor Swift’s team calls subpoena in Blake Lively-Justin Baldoni case ‘tabloid clickbait’ – Yahoo

    Taylor Swift’s Team Slams Subpoena in Blake Lively-Justin Baldoni Case as ‘Tabloid Clickbait

    The Weeknd made the apocalypse sexy at his 2025 tour launch in Arizona – Yahoo

    The Weeknd Turns Up the Heat at His 2025 Tour Launch in Arizona!

    Flutter Entertainment eyes U.S. prediction markets amid growing interest – Sports Business Journal

    Flutter Entertainment Sets Its Sights on U.S. Prediction Markets as Interest Soars

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Well completions per location more than double in Lower 48 states as technology advances – U.S. Energy Information Administration (EIA) (.gov)

    Revolutionizing Oil Production: Lower 48 States See Doubling of Well Completions Thanks to Technological Breakthroughs!

    Officials announce massive project that could reshape electric vehicle technology: ‘This is exactly the type of investment that will help us grow the economy’ – Yahoo Finance

    Game-Changer Ahead: Major Investment Set to Transform Electric Vehicle Technology and Boost the Economy!

    Federal agents raid Dymeng Technology Solutions in St. Augustine – Action News Jax

    Federal Agents Storm Dymeng Technology Solutions in St. Augustine: What You Need to Know

    SoundHound’s Amelia 7.0 Platform Delivers Agentic AI With Category Leading Voice Technology – Business Wire

    Unleashing the Future: SoundHound’s Amelia 7.0 Revolutionizes Voice Technology with Agentic AI

    Comings and goings: MPT hires VP of technology, NPR announces changes to Business Desk – Current – For people in public media

    Exciting Leadership Changes: MPT Welcomes New VP of Technology and NPR Revamps Business Desk!

    Harnessing emerging technologies to power a small business – The Oaklandside

    Unlocking Success: How Emerging Technologies Can Transform Your Small Business

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Cyber experts urge EU to rethink vulnerability disclosure plans

October 8, 2023
in Technology
Cyber experts urge EU to rethink vulnerability disclosure plans
Share on FacebookShare on Twitter

The European Union’s proposed cyber security vulnerability disclosure measures are well-intentioned but ultimately counterproductive, as making unmitigated vulnerabilities public knowledge increases the risk of their exploitation by various actors, experts claim

Sebastian Klovig Skelton

By

Sebastian Klovig Skelton,
Senior reporter

Published: 03 Oct 2023 14:15

Dozens of cyber security experts are urging the European Union (EU) to reconsider the “counterproductive” vulnerability disclosure requirements in its proposed Cyber Resilience Act (CRA), which they say opens the door to misuse by both threat actors and intelligence agencies.

Introduced in September 2022 by the European Commission (EC), the act builds on the EU’s cyber security Strategy and Security Union Strategy, and is intended to improve the security of all connected digital devices and the software they run for consumers across the bloc.

It imposes mandatory cyber security requirements and obligations on manufacturers by obliging them to provide ongoing security support and software patches, and to provide sufficient information to consumers about the security of their products.

On vulnerability disclosures specifically, Article 11 of the CRA states that software manufactures must notify the European Union Agency for cyber security (ENISA) of any vulnerabilities within 24 hours of their exploitation.

In an open letter to various EU officials – including Nicola Danti, the rapporteur for the CRA in the European Parliament; Thierry Breton, commissioner for internal market at the EC; and Carme Artigas Burga, Spain’s state secretary for digitalisation and artificial intelligence – dozens of cyber security exerts from a range of public and private sector organisations said the CRA’s disclosure provisions will create new threats that undermine the security of digital products and the individuals who use them.

“[Article 11] means that dozens of government agencies would have access to a real-time database of software with unmitigated vulnerabilities, without the ability to leverage them to protect the online environment and simultaneously creating a tempting target for malicious actors,” they wrote, adding there are several risks associated with rushing the disclosure process and widely disseminating information about unmitigated vulnerabilities.

This includes the potential for misuse by European governments, an increased risk of vulnerabilities being disclosed to malicious threat actors, and its potentially chilling effect on good faith security research.

“Government access to a wide range of unmitigated software vulnerabilities could be misused for intelligence or surveillance purposes. The absence of restrictions on offensive uses of vulnerabilities disclosed through the CRA and the absence of transparent oversight mechanism in almost all EU member states open the doors to potential misuse,” they wrote.

“Breaches and the subsequent misuse of government-held vulnerabilities are not a theoretical threat, but have happened at some of the best protected entities in the world. While the CRA does not require a full technical assessment to be disclosed, even the knowledge of a vulnerability’s existence is sufficient for a skillful person to reconstruct it.”

On how it affects security research, the cyber security experts added the disclosure measures may interfere with collabroaiton between software publishers and security resaearchers, who need time to veriy, test and patch vulnerabilities before making them public knowledge.

“As a result, the CRA may reduce the receptivity of manufacturers to vulnerability disclosures from security researchers, and may discourage researchers from reporting vulnerabilities, if each disclosure triggers a wave of government notifications,” they wrote.

“While the intention behind disclosing vulnerabilities promptly may be to facilitate mitigation, CRA already requires software publishers to mitigate vulnerabilities without delay in a separate provision. We support this obligation, but also advocate for a responsible and coordinated disclosure process that balances the need for transparency with the need for security.”

As an alternative, the experts recommend adopting a “risk-based approach” that takes into account the severity of the vulnerability, the availability of mitigations, the potential impact on end users, and the likelihood of its broader exploitation.

As such, they have also recommended either completely removing the Article 11 provisions, or at least revising them to protect against the threats they outlined.

The additional revisions suggested include explicitly prohibiting government agencies from using or sharing disclosed vulnerabilities for intelligence or surveillance purposes; changing the reporting requirements to only include mitigatable vulnerabilities within 72 hours of a patch; and to completely exclude reporting of vulnerabilities identified through good faith security research.

“In contrast to malicious exploitation of a vulnerability, good faith security research does not pose a security threat,” they wrote, adding that ISO/IEC 29147 should be reference in the CRA and used as a baseline for all EU vulnerability reporting.

Alex Rice, co-founder and chief technology officer at HackerOne, added that while the intentions of the legislation are good, the proposed disclosure requirements directly conflict with established best practice in the area.

“Reporting highly sensitive data into only a handful of EU government agencies creates a strong incentive for bad actors to breach those hubs and acquire vulnerabilities to attack susceptible organisations – among a whole host of other risks. An increased risk of breach for organisations will also significantly complicate managing reports from the security researcher community, making organisations less receptive to good-faith security research,” he said.

“Everyone suffers when these vulnerabilities are prematurely reported. Parliament should revise the CRA only to require disclosure once vulnerabilities are patched.”

In June 2023, the European Digital Rights Group (EDRi) and 10 other civil society groups wrote a similar open letter raising concerns about the disclosure of unmitigated vulnerabilities.

“Such recently exploited vulnerabilities are unlikely to be mitigated within such a short time, leading to real-time databases of software with unmitigated vulnerabilities in the possession of potentially dozens of government agencies,” they wrote at the time.

“The more this kind of information is spread, the more likely it is to be misused for state intelligence or offensive purposes, or to be inadvertently exposed to adversaries before a mitigation is in place. In addition, laws that require disclosure of unmitigated vulnerabilities to government agencies create an international precedent that may be reflected by other countries.”

Read more on IT governance


Microsoft: Nation-state cyber espionage on rise in 2023

SebastianKlovig Skelton

By: Sebastian Klovig Skelton


Infosec experts divided on SEC four-day reporting rule

ArielleWaldman

By: Arielle Waldman


US cyber breach reporting rules to have global impact

AlexScroxton

By: Alex Scroxton


Hacking Policy Council launches, aims to improve bug disclosure

AlexanderCulafi

By: Alexander Culafi

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366554133/Cyber-experts-urge-EU-to-rethink-vulnerability-disclosure-plans

Tags: CyberExpertstechnology
Previous Post

Amnesia hides names of individuals behind Post Office’s ‘head on a spike’ strategy

Next Post

IT decision-makers confident they can handle tech disruptions

Towards synthetic ecology: strategies for the optimization of microbial community functions – Frontiers

Unlocking the Future of Synthetic Ecology: Innovative Strategies to Enhance Microbial Community Functions

May 12, 2025
12 reasons to ignore computer science degrees – cio.com

12 Compelling Reasons to Rethink Pursuing a Computer Science Degree

May 12, 2025
Don’t feel guilty about poaching scientists fleeing Trump, US science body tells Europe – Science|Business

Embrace the Brain Drain: Why Europe Should Welcome Scientists Leaving the Trump Era

May 12, 2025
Sagittarius Daily Horoscope Today (Nov 22- Dec 21), May 12, 2025: Lifestyle will improve! – India Today

Unlock a Brighter Future: Exciting Lifestyle Changes Await Sagittarius Today!

May 12, 2025
USA breaks mixed 4x400m championship record in Guangzhou – worldathletics.org

USA Shatters Mixed 4x400m Championship Record in Guangzhou!

May 12, 2025
Is the US economy about to collapse? – FreightWaves

Is a US Economic Collapse on the Horizon

May 12, 2025
John Legend Says He’s Shocked by Ye’s ‘Descent’ Into ‘Antisemitism’ and ‘Anti-Blackness’ – Yahoo

John Legend Expresses Shock Over Ye’s Troubling Descent into Antisemitism and Anti-Blackness

May 12, 2025
Merck Animal Health announces $895 million investment in Kansas – Reuters

Merck Animal Health Unveils Ambitious $895 Million Investment in Kansas!

May 12, 2025
How Dartmouth Has Avoided Trump’s Retribution So Far – The New York Times

How Dartmouth Has Skillfully Navigated Trump’s Retribution

May 11, 2025
Well completions per location more than double in Lower 48 states as technology advances – U.S. Energy Information Administration (EIA) (.gov)

Revolutionizing Oil Production: Lower 48 States See Doubling of Well Completions Thanks to Technological Breakthroughs!

May 11, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (601)
  • Economy (613)
  • Entertainment (21,526)
  • General (15,211)
  • Health (9,655)
  • Lifestyle (618)
  • News (22,149)
  • People (616)
  • Politics (620)
  • Science (15,835)
  • Sports (21,123)
  • Technology (15,603)
  • World (603)

Recent News

Towards synthetic ecology: strategies for the optimization of microbial community functions – Frontiers

Unlocking the Future of Synthetic Ecology: Innovative Strategies to Enhance Microbial Community Functions

May 12, 2025
12 reasons to ignore computer science degrees – cio.com

12 Compelling Reasons to Rethink Pursuing a Computer Science Degree

May 12, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version