{
  "story_id": "6f78509abebed12d2f5d5b412f2db0f9",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-03T04:00:00.000Z",
  "content_hash": "a0501741bb94f13be1b9429e342daff6c8834f68c45f0010ab9de4791f856ade",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "Cyber Resilience Act Requires Verification Beyond Vulnerability Detection",
    "dek": "The Cyber Resilience Act mandates evidence-based verification processes, not just vulnerability detection, for software security.",
    "prose": "The Cyber Resilience Act (CRA) establishes cybersecurity requirements across the entire lifecycle of products with digital elements, from secure design and development to post-release support. [^1]\n\nAcross three generators, all 85 artifacts appeared among the Top-3 results for their corresponding queries, and CodePoisonRAG achieved attack success rates between 0.80 and 0.93. [^2]\n\nResearchers introduced CodePoisonRAG, a framework that transforms benign fixed-code entries into poisoned artifacts to influence Retrieval-Augmented Code Generation (RACG) systems. [^3]\n\nOrganizations need operational processes capable of moving quickly from detection to assessment, remediation, verification, and documentation rather than reconstructing information manually after an incident. [^4]\n\nThe CRA makes the traditional model of finding vulnerabilities, opening tickets, and closing them insufficient because it does not verify that the resulting software is secure. [^5]\n\nThe CRA's vulnerability-reporting requirements begin applying on September 11, ahead of the broader requirements scheduled for December 2027. [^6]\n\nThe attacker has no access to the victim's deployed knowledge base, retriever, re-ranker, generator, prompt, or defense mechanism and injects at most one artifact per anticipated programming task. [^7]\n\nThe CodePoisonRAG attack chain combines CWE-specific Vulnerability Injection, which embeds a selected source-to-sink flow, with Semantic Mislabeling, which adds false safety claims without repairing the vulnerable behavior. [^8]",
    "cited": "[{\"statement\":\"The Cyber Resilience Act (CRA) establishes cybersecurity requirements across the entire lifecycle of products with digital elements, from secure design and development to post-release support.\",\"source\":\"SD Times\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T16:15:20.000Z\",\"publisher_count\":1,\"sources\":[\"SD Times\"]},{\"statement\":\"Across three generators, all 85 artifacts appeared among the Top-3 results for their corresponding queries, and CodePoisonRAG achieved attack success rates between 0.80 and 0.93.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-03T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"Researchers introduced CodePoisonRAG, a framework that transforms benign fixed-code entries into poisoned artifacts to influence Retrieval-Augmented Code Generation (RACG) systems.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-03T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"Organizations need operational processes capable of moving quickly from detection to assessment, remediation, verification, and documentation rather than reconstructing information manually after an incident.\",\"source\":\"SD Times\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T16:15:20.000Z\",\"publisher_count\":1,\"sources\":[\"SD Times\"]},{\"statement\":\"The CRA makes the traditional model of finding vulnerabilities, opening tickets, and closing them insufficient because it does not verify that the resulting software is secure.\",\"source\":\"SD Times\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T16:15:20.000Z\",\"publisher_count\":1,\"sources\":[\"SD Times\"]},{\"statement\":\"The CRA's vulnerability-reporting requirements begin applying on September 11, ahead of the broader requirements scheduled for December 2027.\",\"source\":\"SD Times\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T16:15:20.000Z\",\"publisher_count\":1,\"sources\":[\"SD Times\"]},{\"statement\":\"The attacker has no access to the victim's deployed knowledge base, retriever, re-ranker, generator, prompt, or defense mechanism and injects at most one artifact per anticipated programming task.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-03T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"The CodePoisonRAG attack chain combines CWE-specific Vulnerability Injection, which embeds a selected source-to-sink flow, with Semantic Mislabeling, which adds false safety claims without repairing the vulnerable behavior.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-03T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "7daa579c24400b9739e799688dd56a5d",
      "thread_id": "24e8808aa7f3aaa7f661f72cee3fe0b5",
      "thread_label": "CWE",
      "novelty": "UPDATE",
      "content_hash": "7a65fbb520dd6533bb3d2eb6e041fb1a0f47ab87e5335e90cb562f941364ef0a",
      "last_published_at": "2026-09-03T04:00:00.000Z",
      "read_receipt": {
        "slice_hash": "a6974819026a155e1c79c99aba73ab29d5f9d0aaa9cffb05e88a08023354a690",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDNUMDM6MzI6MTkuMDAwMDAwWiIsImlkIjoiNzMzZDYyYTFiNGQwMmJmNjYzNTk3YjhmN2JhZDBiZTIiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDNUMDQ6MDk6MDAuMDAwMDAwWiIsImlkIjoiNjQ5MjI3ZDNmNWQyMGQ3NmI1ZTE1NGNhODNlMTI0ZTMiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 12568115,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "k4fkL1dHRNIJwSawY8K6wWBrTSdTIRM-buyZr56gcruiCoH5_IdJUeMzPH7d51ZTXAE0Qe6xSFoDys5UGTzsAw",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-03T06:46:28.696Z"
  },
  "cited_facts": [
    {
      "statement": "The Cyber Resilience Act (CRA) establishes cybersecurity requirements across the entire lifecycle of products with digital elements, from secure design and development to post-release support.",
      "source": "SD Times",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T16:15:20.000Z",
      "publisher_count": 1,
      "sources": [
        "SD Times"
      ]
    },
    {
      "statement": "Across three generators, all 85 artifacts appeared among the Top-3 results for their corresponding queries, and CodePoisonRAG achieved attack success rates between 0.80 and 0.93.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-03T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "Researchers introduced CodePoisonRAG, a framework that transforms benign fixed-code entries into poisoned artifacts to influence Retrieval-Augmented Code Generation (RACG) systems.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-03T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "Organizations need operational processes capable of moving quickly from detection to assessment, remediation, verification, and documentation rather than reconstructing information manually after an incident.",
      "source": "SD Times",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T16:15:20.000Z",
      "publisher_count": 1,
      "sources": [
        "SD Times"
      ]
    },
    {
      "statement": "The CRA makes the traditional model of finding vulnerabilities, opening tickets, and closing them insufficient because it does not verify that the resulting software is secure.",
      "source": "SD Times",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T16:15:20.000Z",
      "publisher_count": 1,
      "sources": [
        "SD Times"
      ]
    },
    {
      "statement": "The CRA's vulnerability-reporting requirements begin applying on September 11, ahead of the broader requirements scheduled for December 2027.",
      "source": "SD Times",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T16:15:20.000Z",
      "publisher_count": 1,
      "sources": [
        "SD Times"
      ]
    },
    {
      "statement": "The attacker has no access to the victim's deployed knowledge base, retriever, re-ranker, generator, prompt, or defense mechanism and injects at most one artifact per anticipated programming task.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-03T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "The CodePoisonRAG attack chain combines CWE-specific Vulnerability Injection, which embeds a selected source-to-sink flow, with Semantic Mislabeling, which adds false safety claims without repairing the vulnerable behavior.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-03T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}