Skip to content

Security1 publisher2 min readPublished

A 95-item bug report ended in a $100,000 demand to keep the real findings quiet

Two or three of the 95 were genuine, and reviewers had to read all of them to find out. The EU's 24-hour ENISA clock starts on September 11, 2026, and only evidence of active exploitation starts it.

The Watch · Security desk

What happened

  • A GPG-signed report arrived at the security address of a free software project last year claiming 95 vulnerabilities, and it followed the project's own published disclosure guidelines.
  • Reviewers read all 95 items to establish that two or three were real, according to ActiveState principal architect Shane Warden, who helps review the project.
  • A follow-up email then demanded $100,000, or the report would be published with Heartbleed-style press coverage.
  • The EU Cyber Resilience Act's reporting duties begin on September 11, 2026, requiring notification to ENISA within 24 hours of learning a shipped vulnerability is being actively exploited.
  • The CRA's engineering requirements, covering how products are built and maintained, do not apply until December 11, 2027.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The people who read 92 dead items are the same people who would have to file inside 24 hours, so triage capacity rather than legal awareness is what the September date taxes.
  • contradiction The incident and the CRA trigger are different events: the demand rested on unpublished findings, while the 24-hour clock needs evidence of exploitation, so this inbox flood would not by itself have started one.
  • cost At the 55-day remediation baseline cited in the piece, a manufacturer can file both CRA notifications on time and still be seven weeks from a fix, and customers carry that window.
  • exposure With 98% of applications carrying open source components, the set that must prove what shipped and when they knew is nearly every manufacturer selling into the EU, not a specialist tier.

Article 14's clock starts on knowledge of active exploitation, not on the arrival of an email [5]. On the facts Shane Warden gives, nothing in the sequence he describes is an actively exploited vulnerability [1][3]. His argument for why the demand still had teeth is scanning: the blast radius of publication is every deployment of the affected software an attacker can find on the open internet [10]. That is a maintainer's problem now, and a filing problem only if someone begins exploiting one of the real bugs.

The cost sits in the reading. Getting to the genuine findings meant working through all 95, which is about 92 items of nothing and a true-positive rate near 2 to 3 percent [2][17]. Warden does not name the sender and does not attribute the report to a model [16]. His stated tell is volume: he asks how many human researchers would compile a list 95 long instead of stopping at three or four and asking for a longer engagement [8]. Volume is the whole of the evidence on origin, and it is worth holding separately from the compliance timeline it gets attached to.

One number in his piece will matter more after September 11, 2026. Edgescan's 2026 report puts average time to remediate a high or critical application vulnerability at about 55 days [9]. Full CRA notification is due in 72 hours, or three days, so the repair baseline runs roughly 18 times the reporting deadline [18]. Filing on time and shipping a fix are separate exercises, and for the first fifteen months only the filing carries a date [7].

Article 13 asks for a current SBOM [12], which is where the comparison to Executive Order 14028 does real work: the 2021 federal requirement produced documents generated once under deadline pressure, accurate for the moment of production and stale by the next request [13]. Black Duck's 2026 figure, as Warden cites it, is 98% of applications containing open source components [14].

This is one maintainer's account, written by an employee of a company that sells software supply chain tooling, and it cites that company's CEO, Abby Kearns, for the framing that the CRA is functionally a visibility requirement until the engineering rules land in December 2027 [11][6]. The framing is arguable; the inbox arithmetic is checkable, and it says 95 items read to find two or three, by reviewers who cobbled together their own tooling because nobody built it for them [2][15].

What to watch

  • Official guidance on what counts as "actively exploited" for the September 11, 2026 obligation, which decides whether unverified inbound reports cost anyone a clock.
  • A second maintainer publishing comparable triage ratios; Warden says he is not the only person who has received a report like this one.
  • Whether Article 13 enforcement asks for SBOM freshness dates rather than the document, which is what would separate a live inventory from a compliance artifact.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories