The European Commission unveiled a revised EU Cybersecurity Act proposal that would allow the bloc to identify and potentially exclude “high-risk” suppliers—including those deemed vulnerable to third-country influence—from critical digital infrastructure across 18 essential sectors. The proposal also aims to streamline and accelerate EU-wide cybersecurity certification, reflecting a shift toward treating supply-chain security as both a technical and geopolitical risk-management issue.
Reporting highlighted that the proposal, while not naming countries, is widely viewed as targeting Chinese vendors and supply dependencies—particularly around network equipment and connected energy technologies such as solar inverters that may connect to cloud services and create potential access paths into the energy grid. Separate coverage of the same Commission initiative noted plans to expand ENISA’s mandate, including closer operational cooperation with national authorities to help counter threats such as ransomware, but emphasized that the proposal still requires negotiation and approval by the European Parliament and member states before it can take effect.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After the EU proposals were unveiled, China criticized the planned restrictions on suppliers such as Huawei and ZTE as protectionist. A Chinese foreign ministry spokesperson said Chinese companies had not endangered Europe's national security.
The Commission's proposal introduced mechanisms to identify and restrict or phase out high-risk third-country suppliers from critical digital infrastructure, including telecom networks. Member states would be required to derisk mobile networks, and operators could be given up to three years to remove components from suppliers deemed to pose significant cybersecurity risk.
On 2026-01-20, the European Commission presented draft revisions to the EU Cybersecurity Act and related NIS framework to strengthen EU cyber resilience. The package proposed faster certification, expanded ENISA responsibilities, improved ransomware reporting and response, and a new supply-chain security framework.
In September 2025, a malware attack on an IT service provider caused days of passenger and baggage handling disruptions at airports including Berlin, Brussels, Dublin, and London Heathrow. The incident was cited as an example of the real-world impact of ransomware and related cyberattacks on essential services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcetherecord.media
Open sourcetechrepublic.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.