😁 Hello, super humans! There is a new clock in your build pipeline this morning, and you did not add it. If you ship anything with software in it into the European Union, you now have 24 hours to tell a regulator when someone starts exploiting a hole in it. Not 24 hours to fix it. Twenty-four hours to say it is happening, which is a very different engineering problem, and the part almost nobody has wired up.
📰 Quick Signals
- 🧠 AI: Positron AI raised $875 million at a $5 billion post-money valuation, roughly a five-fold markup on its February Series B, to fund the tapeout of Asimov, an inference chip that carries 288 GB to 2,304 GB of commodity LPDDR5X per part instead of high-bandwidth memory.
- 🤖 Robotics: Vecna Robotics closed $31 million led by Unless, with Drive Capital, Tiger Global, Highland and Tectonic returning, aimed squarely at flexible dock-to-dock material handling rather than another humanoid.
- 💻 Programming: Node.js shipped v26.8.2 and v24.21.0 LTS inside 24 hours of each other, both carrying the OpenSSL 3.5.8 upgrade, which is a useful rehearsal for how fast a crypto bump has to move now.
- ⚡ Electronics: Analog Devices agreed to buy Alif Semiconductor for $1.35 billion in cash, picking up AI-native microcontrollers and fusion processors built for on-device inference rather than datacenter racks.
- 📡 Telecom: Eutelsat signed a roughly €1 billion agreement with Airbus for 229 additional OneWeb satellites, extending its low Earth orbit constellation plan through 2034 with deployment starting late this year.
The Big Story: The CRA’s reporting clock starts today, and “aware” is the trigger
If your product has software in it and it reaches a customer in the European Union, a new legal obligation started this morning. It does not ask you to be secure. It asks you to be fast at telling the truth, and the timer starts at a moment most teams cannot currently identify.
What happened: Today, 11 September 2026, the reporting obligations in Article 14 of Regulation (EU) 2024/2847, the Cyber Resilience Act, enter into application. Manufacturers of products with digital elements must notify actively exploited vulnerabilities and severe security incidents to their national CSIRT and to ENISA. The schedule is staged: an early warning within 24 hours of becoming aware, a fuller technical notification within 72 hours, and a final report within 14 days for an actively exploited vulnerability or one month for a severe incident. Filing happens once, through ENISA’s Single Reporting Platform, which routes the notification to the CSIRT where you have your main establishment and makes it available to ENISA at the same time. The platform was built to be operational on exactly this date, so the portal opens the same morning the duty does. Two details do most of the damage: the obligation covers products already on the EU market, not just things you place there from today, and the rest of the CRA, including the conformity and CE-marking machinery, does not apply until 11 December 2027. So the reporting duty arrives first, alone, ahead of the framework it belongs to.
The details: The engineering problem here is not the filing. The filing is a web form. The problem is the word “aware”. The 24-hour clock does not start when you publish a patch, when a CVE is assigned, or when your lawyers agree on wording. It starts at the moment your organization can be said to know that a vulnerability in your product is being exploited, and for most teams that moment is distributed across a support inbox, a Discord channel, a GitHub issue, a customer’s SOC, and an on-call engineer’s hunch at 2am. If awareness has no single timestamped entry point, you cannot prove when the clock started, which means you cannot prove you met the deadline, and you also cannot tell the difference between a late report and an early one. That makes the first real deliverable an intake funnel rather than a policy document: one published channel, a security.txt that points at it, a ticket created automatically on arrival with an immutable received-at timestamp, and a named rota that can make a two-way call (“is this actively exploited?” and “is this our product?”) within hours rather than days. Note the second question is often the hard one, because the answer depends on an inventory of what you shipped, in which firmware version, to which market, going back years. Anyone who has tried to reconstruct a bill of materials for an EOL device knows how that goes. The other structural surprise is directional: this regulation makes vendors the reporters. Most security processes built over the last decade optimized for receiving reports from researchers and sitting on them until a coordinated release date. The CRA keeps coordinated disclosure intact for the public, but it cuts a separate, fast, non-public channel straight to the state, and it runs on a clock you do not control.
flowchart TD
A["Signal arrives<br/>support inbox · GitHub issue<br/>customer SOC · researcher email"] --> B["Single intake point<br/>timestamped, immutable<br/>THIS is 'aware'"]
B --> C{"Actively exploited?<br/>Our product?"}
C -->|"No"| D["Normal VDP track<br/>coordinated disclosure"]
C -->|"Yes"| E["T+24h: early warning<br/>to CSIRT + ENISA"]
E --> F["T+72h: technical notification<br/>severity, impact, mitigations"]
F --> G["T+14 days: final report<br/>(1 month for severe incidents)"]
style B fill:#1FB6F5,stroke:#0B1117,color:#0B1117
style C fill:#1FB6F5,stroke:#0B1117,color:#0B1117
style D fill:#22C55E,stroke:#0B1117,color:#0B1117
style E fill:#FF4D4F,stroke:#0B1117,color:#0B1117
Important
Our take: I think the 24-hour window is defensible and the “aware” trigger is where this will actually go wrong. Regulators will eventually have to judge awareness after the fact, from your own logs, and the teams that get hurt will not be the negligent ones; they will be the ones with five honest, undated intake channels and no way to show which signal counted. So the highest-value hour you can spend this week is not reading the regulation, it is drawing your awareness graph: every path by which a stranger can tell you something is broken, and whether each one lands in a system that writes down the time. Second thought, aimed at maintainers: read the open-source carve-out carefully before you panic, because non-commercial open source is largely out of scope, but a steward monetizing a project is a different story, and “we have a paid support tier” is exactly the kind of fact that moves you across that line. Third, and least comfortable: this only bites if someone is exploiting your bug, and finding that out at all requires telemetry or customers who talk to you. Plenty of vendors will comply perfectly and honestly for years simply because they never learn.
🗞️ More News
🧠 AI
- Microsoft is reportedly planning to more than triple its datacenter footprint from around 12 GW today to about 38 GW by 2032, with AI-specific silicon going from roughly 2 GW to about a third of that total.
- Anthropic says dozens of Claude agents working in parallel formalized Fermat’s Last Theorem in Lean in 11 days, writing about 13 million lines and proving roughly 29,500 intermediate theorems on the way.
- Worth reading next to that announcement: Nature’s assessment is that the result is a genuine milestone for machine-checked mathematics and explicitly not a new proof, since Andrew Wiles did the mathematics in 1995 and the model translated it.
- Google, Anthropic and OpenAI all unveiled cyber-focused models, safeguards and gated access programs in the same stretch, which puts three vendors in the business of shipping offensive-capable tooling under contract.
- The quiet structural story of this cycle is recursive synthetic improvement: frontier gains increasingly come from loops of model-generated judges, corpora, teachers, curricula and RL environments rather than new human data.
- Memory prices are now visible in accelerator price tags: Huawei has reportedly lifted the indicated price of its Ascend 950DT card past RMB 250,000, and Chinese AI chip vendors are raising across the board.
🤖 Robotics
- The Humanoid Robots Summit runs in Stuttgart until today, with 37 speakers from Bosch, Boston Dynamics, Google DeepMind, Unitree, PAL Robotics and BMW, which is a fair snapshot of who is actually shipping versus who is presenting.
- First-half 2026 humanoid shipments are estimated at roughly 19,000 to 22,000 units, up about 272 percent year over year, with Chinese manufacturers holding the overwhelming majority of volume and industrial use above 70 percent of it.
- AGIBOT showed its multi-robot lineup at IFA in Berlin, arriving with TÜV Rheinland safety certifications and a European distribution deal, which is the unglamorous paperwork that decides whether a robot can be sold here at all.
- Warehouse robotics startups took in roughly $336 million across eight disclosed deals in early 2026, with the average round size nearly tripling from about $13 million to $42 million, so the money is consolidating into fewer, larger bets.
💻 Programming
- September’s TIOBE index leaves the top ten unmoved but shows Python slipping below 18 percent, from 18.53 to 17.76, C falling from 11.10 to 10.28, C++ widening its lead over Java, and Julia closing on the top twenty.
- Node.js is changing its release cadence: from version 27 there will be one major per year, and every major will move to long-term support after a six-month Current phase, with Node.js 26 entering LTS in October.
- TinyGo 0.42 added startup code, register definitions, linker scripts, GPIO and UART for the Puya PY32 family, covering 87 individual MCU targets plus two cheap EmbedFire boards.
- A worked example of exactly what the CRA now wants reported: the keyv and cacheable npm compromise spread through a preinstall hook to at least 444 packages across 1,381 versions, with no CVE assigned during initial analysis.
⚡ Electronics
- Renesas announced another price adjustment across its portfolio, with the new levels taking effect on 1 January 2027, so anyone quoting 2027 hardware on today’s BOM costs should re-run the numbers.
- Malaysia is pushing to move up the chip value chain rather than stay a base for outsourced assembly and test, which matters for anyone whose packaging capacity currently sits in Penang.
- The XIAO SAMD21 Plus puts a Microchip SAMD21G18 Cortex-M0+ at up to 48 MHz with 256 KB flash and 32 KB SRAM into the thumbnail-sized XIAO footprint, which is a lot of headroom for that outline.
📡 Telecom
- India’s Digital Communications Commission approved a 5 percent spectrum usage charge for satellite communications, unblocking spectrum assignment for Starlink, Eutelsat OneWeb and Jio Satellite Communications.
- The FCC is moving to open more than 1,000 MHz for satellite broadband, with AT&T, T-Mobile and SpaceX all repositioning around the reshaped US spectrum map.
- Wire 3 is expanding its fiber build into Athens, Georgia with a fully funded $40 million investment expected to pass more than 39,000 homes and businesses.
👨💻 Code Corner
The CRA deadlines are simple arithmetic, which is exactly why they are worth computing in code rather than in your head at 3am. Feed this the timestamp your intake system recorded, not the time you finished reading the ticket.
# cra_clock.py: Article 14 deadlines from a single awareness timestamp.
from datetime import datetime, timedelta, timezone
WINDOWS = { # kind -> (early_warning, technical, final)
"exploited_vuln": (24, 72, 14 * 24), # final report: 14 days
"severe_incident": (24, 72, 30 * 24), # final report: ~1 month
}
def cra_deadlines(aware_at: datetime, kind: str = "exploited_vuln") -> dict:
if aware_at.tzinfo is None:
raise ValueError("aware_at must be timezone-aware; UTC avoids DST disputes")
early, tech, final = WINDOWS[kind]
return {
"early_warning": aware_at + timedelta(hours=early),
"technical_notification": aware_at + timedelta(hours=tech),
"final_report": aware_at + timedelta(hours=final),
}
aware = datetime(2026, 9, 11, 21, 40, tzinfo=timezone.utc) # Friday night, of course
for stage, due in cra_deadlines(aware).items():
print(f"{stage:<24} due {due:%Y-%m-%d %H:%M %Z}")
Tip
Two traps hide in those three lines of arithmetic. First, the windows are wall-clock, not working hours, so an awareness event at 21:40 on a Friday is due before Saturday night; build the rota before you need it. Second, aware_at is a finding, not an input: if your intake is a shared mailbox, the defensible timestamp is whatever the mail server wrote, so keep those headers and never let a human retype the time into a ticket.
🧰 Toolbox
- ENISA Single Reporting Platform: the portal itself, plus ENISA’s FAQs and user guidance; register before you have something to report, not after.
- Commission CRA reporting page: the official scope statement in plain language, which is the document to cite when someone asks whether your product counts.
- CRA reporting readiness checklist: an independent, practical list of what to have in place before filing, useful if you are starting from nothing this morning.
- TinyGo: version 0.42 brings 87 Puya PY32 targets, so writing Go for a sub-dime ARM part is now a real option rather than a stunt.
- PY32F002A at LCSC: live pricing and stock for this week’s component, handy for sanity-checking what “cheap microcontroller” actually costs at your quantity.
🔌 Component of the Week (rotating)
Puya PY32F002A is the cheapest flash microcontroller you can buy that is also a real Arm Cortex-M0+. The A-series part runs at up to 24 MHz with up to 20 KB of flash and 3 KB of SRAM, takes anything from 1.7 V to 5.5 V, works from -40 to 85 °C, and brings I2C, SPI, USART, a 12-bit ADC and several timers along for the ride. Price is the headline: roughly $0.08 per unit at volume from LCSC, and about $0.15 if you only want five, which puts a 32-bit core below the cost of many 8-bit parts and well below a decent tactile switch. The obvious use is anything where you were going to reach for discrete logic or a 555 and then wished you could change the behavior later: battery-powered sensor nodes, LED drivers, a smart cable, a one-off replacement brain for dead consumer hardware. Two caveats before you design it in. The toolchain is less polished than an STM32’s, though TinyGo 0.42 just added 87 PY32 targets and the community has mapped the SWD quirks fairly thoroughly. And the community has also found that some “F002A” chips are physically PY32F030 dies with more capability than the datasheet promises, which is a fun surprise in a hobby build and an unacceptable one in production, so program against the published spec. Datasheet and stock are on the LCSC listing.
📚 From the Blog
- Turning Pixels Into Something the AI Can Eat: the decode, resize and normalize stage between a camera and a model, and a reminder that every one of those cameras is a product with digital elements that somebody now has to report on.
- Building Your First Neuron From Scratch: weights, bias, activation and one gradient step by hand, which is the shortest path to understanding what Positron’s memory-first chip is actually being asked to move.
- The Network Behind the Cameras: the unglamorous plumbing of moving video without saturating the link, a good companion to today’s satellite and fiber capacity items.
😀 The Bot Says…
The regulation gives you 24 hours to report an actively exploited vulnerability, and the portal you report it into opened the same morning the obligation did. Somewhere in Europe, a compliance officer is watching a password reset email fail to arrive while a 24-hour timer runs in the next tab.

