🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsK-Lite Mega Codec Pack(12.09.2026 um 12:00 Uhr)
🕵️ SicherheitslückenDefender 0-Day ShieldBreak (CVE-2026-69414) nicht sauber gepatcht - BornCity(11.09.2026 um 12:52 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsK-Lite Mega Codec Pack(12.09.2026 um 12:00 Uhr)
🕵️ SicherheitslückenDefender 0-Day ShieldBreak (CVE-2026-69414) nicht sauber gepatcht - BornCity(11.09.2026 um 12:52 Uhr)

🎥 IT Security Video 🕛 vor 35 Min. 2 Min Lesezeit SECURITY-FEED
0

media.ccc.de: MRMCD2026 - The CRA: A key to a more resilient FOSS ecosystem

↗ Quelle (YouTube · media.ccc.de)
🗣️ Stimme:
📺
YouTube · media.ccc.de
4 YouTube-Aufrufe
https://media.ccc.de/v/2026-765-the-cra-a-key-to-a-more-resilient-foss-ecosystem

With the Cyber Resilience Act FOSS projects are legally on the hook as part of software supply chain ecosystems. In order to address regulatory obligations and foster open collaboration within software supply chain ecosystems best practices, tooling and standards as well as established pathways for public benefit stewardship are needed. The talk will present current work in various Open Source Foundations, the IETF, as well the EU.

Various supply chain regulations (EO 14028 [1], SSDF [2], SEC Cyber Rule [3], SLSA [4], NTIA [5]) and the currently developing Cyber Resilience Act (CRA) in the EU create obligations [6,7] for both software suppliers and dependents. For the first time, this includes Free and Open Source Software (FOSS) projects, with the CRA introducing the legal concept of the Open Source Software Steward in the EU framework.

The talk will provide an overview of the work being done to ease the regulatory burden of these regulations on FOSS projects and their dependents (aka manufacturers). This includes:

- Standards to enable compliance-critical communication within software supply chain ecosystems (e.g., the SCITT Working Group at the IETF [8]);
- Machine-readable information about FOSS projects at the OpenSSF [9];
- The development of best practices for collaboration between FOSS projects and their dependents (aka manufacturers) under the CRA in the ORC Working Group [10].

Additionally, the talk will cover the current debate on recognizing public benefit status for the stewardship of Digital Commons (aka "Gemeinnützigkeit Open Source"), such as the recent policy paper by the German Association of Computer Scientists [11].

[1] https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity
[2] https://csrc.nist.gov/projects/ssdf
[3] https://www.sec.gov/rules-regulations/2023/07/s7-09-22
[4] https://slsa.dev/
[5] https://www.ntia.gov/page/information-quality-guidelines
[6] https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
[7] https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation
[8] https://datatracker.ietf.org/group/scitt/about/
[9] https://openssf.org/blog/2026/05/29/aligning-on-machine-readable-signals-as-the-foundation-for-due-diligence/
[10] https://orcwg.org/
[11] https://gi.de/fileadmin/GI/Allgemein/PDF/2026-06_GI_Policy_Brief_Anerkennung_und_Besserstellung_von_OSSS.pdf

Gregor "Little Detritus" Bransky

https://talks.mrmcd.net/2026/talk/9LHP77/

#mrmcd26 #InfrastructureandSoftware

https://creativecommons.org/licenses/by-sa/4.0/
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
4 Quellen
CVE-2026-71328 | Microsoft .NET/Visual Studio buffer overflow (Nessus ID 344808)
3 Quellen
CVE-2026-65669 | Microsoft SQL Server up to 22.8.1 injection (Nessus ID 344797)
1 Quelle
CVE-2026-75650 | Adobe Commerce/Commerce B2B/Magento Open Source Template Engine StyleSmuggler neutralization (EUVD-2026-72530 / Nessus ID 344801)