Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform