The EU Now Regulates the Product Itself (09/09/2026)
- › The European Commission published guidance on the Cyber Resilience Act clarifying scope, reporting duties, and product requirements for manufacturers.
- › The FBI warned about OAuth consent phishing, where a victim grants an attacker's application standing access instead of surrendering a password.
- › Wellstar Health System and Cone Health both settled class actions over website pixel tracking.
- › FinCEN published an alert to financial institutions describing the scale of digital asset investment scams.
- › Two separate ransomware groups have each claimed the same attack on the home health care provider Interim Healthcare.
Most security regulation binds the organization that gets breached, and the Cyber Resilience Act binds the company that shipped the thing. That shift in who carries the obligation is the more consequential half of today’s board, because a manufacturer’s compliance burden eventually becomes a procurement question for everybody buying from them.
Top 5 Critical Compliance Alerts
1. New Commission Guidance on the Cyber Resilience Act
The European Commission published guidance on July 27, 2026 clarifying the scope, reporting obligations, and product requirements of the Cyber Resilience Act, the EU’s horizontal cybersecurity regulation covering products with digital elements. The regulation reaches anybody placing a connected product on the EU market, which sweeps in a great many manufacturers who have never thought of themselves as software companies and now owe vulnerability handling and disclosure duties for the life of the product. Guidance on scope is the part worth reading first, since the argument most companies are quietly making internally is that this does not apply to them. JD Supra has the analysis.
Operator Note: If your organization sells anything with a network connection into Europe, the CRA question belongs to product engineering and legal together, and neither one of them will raise it alone.
2. The FBI Warns on OAuth Consent Phishing
The Federal Bureau of Investigation issued a warning about ongoing phishing that persuades a victim to approve an attacker-controlled application rather than to hand over a password. Consent grants survive password changes and frequently survive multi-factor enrollment, so the usual response to a phishing report leaves the access exactly where the attacker put it. The permission is recorded as a legitimate authorization, because from the identity platform’s point of view that is what it is. HIPAA Journal has the warning.
Operator Note: Pull the list of third-party applications with consented access to your tenant and set a review interval, because nobody has looked at that list since the day it was first populated.
3. Two Health Systems Settle Pixel Tracking Suits
Wellstar Health System and Moses H. Cone Memorial Hospital Operating Company agreed to settle class action litigation over the use of website tracking pixels. Marketing analytics on a patient-facing page collects the fact that somebody looked at a page about a condition, which is a disclosure about that person even when no record from the clinical system moves. These cases keep settling because the technology was installed by a marketing team under an ordinary vendor agreement and never crossed the desk of anybody who reads HIPAA for a living. HIPAA Journal has both settlements.
4. FinCEN Puts a Scale on Digital Asset Investment Scams
The Treasury Department’s Financial Crimes Enforcement Network published an analysis and an alert directing financial institutions to watch for digital asset investment scams, laying out how large the category has become and which fraud patterns it covers. An alert of this kind sets a supervisory expectation, so an institution that files nothing in a category the regulator has flagged is making an implicit claim about its monitoring that it will eventually be asked to support. The typologies in the alert are the useful part for anybody tuning detection rules. Compliance Building has the summary.
5. Two Ransomware Groups Claim the Same Healthcare Attack
Two separate ransomware groups have each claimed responsibility for attacks on the nationwide home health care provider Interim Healthcare, with breaches now announced. Competing claims usually mean either that one crew bought access from the other or that two intrusions happened independently through the same weakness, and both readings change what the notification and forensic scope has to cover. A home health provider holds clinical records alongside the home addresses and schedules of the people receiving care. HIPAA Journal has the claims.
Operator Note: When two actors claim your incident, resist the urge to pick the more credible one, because the scope of your investigation has to hold both explanations until the forensics rules one out.
Additional Compliance Alerts
Regulatory Updates
- FINRA adopted new intraday margin requirements: Amendments to Rule 4210 substantially change the supervision of margin day trading, with firms needing to align surveillance and documentation to the revised requirements. JD Supra
- The PCI Council continues its post-quantum series: The latest installment covers how payment security stakeholders are preparing for post-quantum cryptography, which is the migration nobody’s compliance calendar has a date for yet. PCI Security Standards Council
Governance and Audit
- A practical list of what a privacy audit should actually test: Ten items covering websites, mobile applications, advertising platforms, CRM systems, cloud services, AI tools, and vendor data flows, aimed at counsel who need to test a program instead of describing one. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.