An e-commerce site running on an open-source CMS has, since September 11, 2026, a new obligation: to report any actively exploited vulnerability in its digital components within 24 hours. This is no longer just a best practice recommendation; it is the European Cyber Resilience Act entering its operational phase. This web news illustrates how this year’s digital trends are not limited to product launches or algorithm updates.
Cyber Resilience Act: what mandatory notification changes concretely
Since September 11, 2026, the CRA imposes two strict deadlines on manufacturers of products containing digital elements: an initial alert within 24 hours and a detailed notification within 72 hours in case of an exploited vulnerability or serious incident. The source of this obligation is the European Commission through its implementation guide, supplemented by the analysis from the Bird & Bird firm published on September 21, 2026.
On the ground, we are already seeing the consequences. Technical teams that managed security patches “when they had time” must now document, qualify, and escalate information within a timeframe that allows little leeway. For an SME with two developers, this means establishing a monitoring and reporting process that did not previously exist.
This regulatory framework concerns both software publishers and manufacturers of connected devices. We are talking about an obligation that affects almost all digital products sold in the European Union, from home routers to SaaS platforms. To keep up with these regulatory developments and their repercussions on digital professions, The Click website regularly aggregates the most significant web news.
Artificial intelligence and cybercrime: an expanding attack surface

ENISA (European Union Agency for Cybersecurity) published a report on September 22, 2026, documenting a change in the nature of cyberattacks. Malicious groups are using artificial intelligence to enhance their operations, not just to generate more credible phishing, but to automate target recognition and adapt their tools in real time.
The problem does not only come from the attackers. The integration of AI systems in businesses creates new entry points. A language model connected to an internal database, for example, becomes a target if its API is not properly segmented. ENISA emphasizes that technological dependencies weaken the digital resilience of organizations.
Specifically, we observe three cumulative trends:
- AI-assisted social engineering campaigns are becoming more sophisticated, making traditional filters less effective
- Companies deploying generative AI tools without prior security audits expose sensitive data to unprecedented attack vectors
- Software supply chains (open source dependencies, third-party libraries) remain the weak link primarily exploited
Feedback varies on this point, but several analysts note that cybersecurity budgets are not increasing at the same pace as the attack surface created by the rapid adoption of AI.
European digital sovereignty: beyond political discourse
The European Union is now structuring its technology policy around digital sovereignty. We are talking about semiconductors, cloud, and network infrastructure.
What makes this trend different from previous years is that it translates into concrete funding and legal obligations, not just statements of intent. The CRA mentioned above is part of this. The Digital Services Act and the Data Act are also continuing their operational ramp-up.

For digital marketing professionals and content publishers, these regulations change the way user data is collected and processed. Brands operating in multiple European markets must adapt their advertising targeting practices to a framework that is tightening every quarter.
Google updates and SEO: spam in the crosshairs
Google has launched the September 2026 Spam Update, its fourth anti-spam update of the year. The pace is accelerating compared to previous years. There is also the emergence in Search Console of a distinction between visual searches and text queries, which changes the interpretation of performance data for SEOs.
Searches initiated from a smartphone camera or a screenshot are no longer confused with traditional queries. For sites generating traffic through images (e-commerce, recipes, decoration), this separation finally allows for measuring the actual contribution of visual search.
Digital trends to watch by the end of the year
The most significant signals this fall do not come from product announcements, but from regulatory and security constraints that are reshaping the daily lives of technical and marketing teams.
- The CRA mandates a redesign of reporting processes for any publisher of digital products sold in Europe
- Generative AI, omnipresent in business tools, expands the attack surface without security protocols keeping pace
- European digital sovereignty is materializing through project calls and dedicated budgets, notably via the Digital Europe program
- Google’s anti-spam updates are multiplying, focusing on content quality in the face of AI-assisted production
This year’s web news reads less like a succession of innovations and more like a tightening of the rules of the game for all digital players. Teams that anticipate these constraints, particularly regarding cybersecurity and regulatory compliance, gain a measurable operational advantage over those that wait until the last moment.



