Citadelo - Hackers on Your Side! reported that a hardcoded password in firmware became a reportable event under the Cyber Resilience Act (CRA) starting from 11 September 2026.
Public source
Publisher name
Public post
A hardcoded password in firmware is a line in our test report today. From 11 September 2026 it can become a reportable event under the Cyber Resilience Act (CRA). 𝐍𝐨𝐭…
Company
Citadelo - Hackers on Your Side!
Citadelo helps fortune 500 companies identify vulnerabilities through simulated attacks.
- Industry
- Computer and Network Security
- Location
- Switzerland, CH
- Company size
- 11–50 employees
About Citadelo - Hackers on Your Side!
Citadelo was founded by ethical hackers to help companies identify vulnerabilities through simulated attacks. Backed by a team of 30 professionals, the company is a market leader in Slovakia and the Czech Republic and has offices in Zug (Switzerland), Prague and Bratislava. By engaging in cloud security testing, application testing, and more, the cybersecurity firm helps businesses achieve a higher level of security. • Perfect in-depth knowledge of web technologies and underlying technologies. • Lot of experience in ethical hacking of web applications. • Deep knowledge of OWASP Testing Guide. • Very good experience with the auditing of portable devices. • Reverse engineering of binary code of x86 (32/64) and ARM (32/64) architecture. • Deep understanding of Linux/Solaris/*BSD systems. • Deep understanding of Windows systems. • Very good knowledge of cryptography and it’s principles. • Deep understanding of networking and network protocols. • Ability to adapt to uncommon situations and technologies. • Ability to very quickly and effectively respond to security incidents. • Deep understanding of cloud security (AWS, Azure, VMware and Google Cloud) More information: https://citadelo.com/en/
See moreDiscover more
Similar signals
Similar public activity from other companies.
Legal & Regulatory
Cyber Solutions Luxembourg
Cyber Solutions Luxembourg announced that the Cyber Resilience Act reporting obligations begin to apply to manufacturers of products with digital elements on 11 September.
Legal & Regulatory
Defenced | Cyber Security
Defenced | Cyber Security announced that from 11 September 2026, the Cyber Resilience Act (CRA) mandates that manufacturers of products with digital elements must report vulnerabilities, incident classification, escalation, and reporting procedures before the end of the following week.
Legal & Regulatory
secunet Security Networks AG
secunet Security Networks AG notes that the Cyber Resilience Act (CRA) requires meldepflichtig Vorfallen to be reported by September 11, 2026, with a 24-hour first warning, 72-hour detailed report, and a 14-day closure report.
Legal & Regulatory
iGO Cyberphysical
iGO Cyberphysical noted that the EU Cyber Resilience Act vulnerability reporting obligation is now live, entering into force on November 10, 2024, and applying 21 months after entry into force.
Legal & Regulatory
Hackurity