European Commission cybersecurity package on high-risk telecom suppliers
Public Sector Action
Summary
Hide ▲
Show ▼
The European Commission proposed new cybersecurity legislation that would remove high-risk suppliers from telecommunications networks, strengthening protections for critical infrastructure across the EU. The package is meant to reduce exposure to state-backed and cybercrime threats while expanding EU-wide risk assessments. It also opens the door to restrictions or bans on sensitive equipment, making this a major shift in EU cyber policy.
Related Happenings
CISA onboards ENISA for CVE TL-Root CNA role
Public Sector Action
First: 15.04.2026 18:31
Last: 15.04.2026 18:31
Sources 1
About this happening:
**ENISA** is being onboarded by **CISA** to become a **top-level root CVE Numbering Authority (TL-Root CNA)** in the **CVE Program**, expanding the European agency’s influence ove...
CISA onboards ENISA for CVE TL-Root CNA role
Public Sector ActionAbout this happening: **ENISA** is being onboarded by **CISA** to become a **top-level root CVE Numbering Authority (TL-Root CNA)** in the **CVE Program**, expanding the European agency’s influence ove...
FCC bans new foreign-made consumer routers
Public Sector Action
First: 25.03.2026 09:11
Last: 25.03.2026 09:11
Sources 1
About this happening:
The U.S. Federal Communications Commission banned the import of new foreign-made consumer routers after concluding they pose unacceptable cyber and national security risks to U.S....
FCC bans new foreign-made consumer routers
Public Sector ActionAbout this happening: The U.S. Federal Communications Commission banned the import of new foreign-made consumer routers after concluding they pose unacceptable cyber and national security risks to U.S....
Latest development: 26.03.2026 21:48
The FCC's March 23 ban on new foreign-made consumer-grade routers may leave U.S. consumers and small businesses using older devices longer, while businesses replacing network gear could face a more constrained and potentially more expensive market with fewer approved options and longer procurement cycles.
FCC Covered List update on foreign-made consumer routers
Public Sector Action
First: 24.03.2026 22:41
Last: 24.03.2026 22:41
Sources 1
About this happening:
The **FCC** updated its **Covered List** to ban new **consumer routers made in foreign countries** from U.S. sales, tightening a national-security restriction on **March 24, 2026*...
FCC Covered List update on foreign-made consumer routers
Public Sector ActionAbout this happening: The **FCC** updated its **Covered List** to ban new **consumer routers made in foreign countries** from U.S. sales, tightening a national-security restriction on **March 24, 2026*...
EU sanctions cyberattack-linked companies and individuals
Regulatory/Legal Action
First: 17.03.2026 20:41
Last: 17.03.2026 20:41
Sources 1
About this happening:
The **Council of the European Union** sanctioned **three companies** and **two individuals** for **cyberattacks** targeting **devices** and **critical infrastructure**, escalating...
EU sanctions cyberattack-linked companies and individuals
Regulatory/Legal ActionAbout this happening: The **Council of the European Union** sanctioned **three companies** and **two individuals** for **cyberattacks** targeting **devices** and **critical infrastructure**, escalating...
Europol-coordinated Tycoon2FA takedown
Law Enforcement
First: 04.03.2026 19:01
Last: 04.03.2026 19:01
Sources 1
About this happening:
**Europol** coordinated a law-enforcement operation that **seized 330 domains** tied to **Tycoon2FA**, disrupting a **phishing-as-a-service** platform used for **credential theft*...
Europol-coordinated Tycoon2FA takedown
Law EnforcementAbout this happening: **Europol** coordinated a law-enforcement operation that **seized 330 domains** tied to **Tycoon2FA**, disrupting a **phishing-as-a-service** platform used for **credential theft*...
Latest development: 23.03.2026 23:52
CrowdStrike observed Tycoon2FA return to pre-disruption activity levels within days after the March 4, 2026 Europol-led takedown, with daily campaign volumes on March 4 and March 5, 2026 falling to 25% of pre-disruption levels before rebounding to early 2026 levels. The phishing-as-a-service platform continued using largely unchanged TTPs against Microsoft 365 and Gmail accounts and remained active in malicious email campaigns, BEC, email thread hijacking, cloud account takeovers, and malicious SharePoint links.
Timeline
-
20.01.2026 20:54 2 articles · 4mo ago
European Commission proposes EU cybersecurity package
Legal Policy Action UpdateThe European Commission proposed new cybersecurity legislation to remove high-risk suppliers from telecommunications networks and critical ICT supply chains, strengthen defenses against state-backed and cybercrime groups, and expand EU-wide risk assessments, restrictions or bans on sensitive equipment, ENISA-managed certification schemes, early threat alerts, incident reporting, ransomware response support, and cybersecurity skills initiatives.
Show sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54