Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4742 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Breach: Fluke (821,100 accounts) — Email addresses, Employers, Job titles
Breach: Goose Creek (6,574,121 accounts) — Email addresses, Names, Phone numbers
CVE-2026-59836 (CVSS 7.5) — A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through ...
CVE-2026-45063 (CVSS 9.1) — Symfony is a PHP framework for web and console applications and a set of reusable PHP com...
CVE-2026-45069 (CVSS 9.1) — Symfony is a PHP framework for web and console applications and a set of reusable PHP com...
CVE-2026-47767 (CVSS 9.8) — Symfony is a PHP framework for web and console applications and a set of reusable PHP com...
CVE-2026-47984 (CVSS 8.2) — Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result ...
CVE-2026-47988 (CVSS 8.6) — Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result ...
CVE-2026-48320 (CVSS 8.5) — ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attack...
CVE-2026-46633 (CVSS 9.8) — Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape ...
CVE-2026-46634 (CVSS 9.8) — Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() comp...
KEV: CVE-2026-46817 — Oracle E-Business Suite (Oracle E-Business Suite Improper Privilege Management Vulnerability)
KEV: CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1 (KNX Association KNX Protocol Con...
arXiv: When Binaries Talk Back: Representation-Confusion Attacks on LLM-Assisted Reverse Engineering
A new academic paper published on arXiv, titled "When Binaries Talk Back: Representation-Confusion Attacks on LLM-Assisted Reverse Engineering," identifies a novel security vulnerability in large l...
Read analysis →
arXiv: On the Security Implications of PQC in TLS: Handshake Exhaustion and IDS Degradation
This publication from July 2026 presents a security analysis of Post-Quantum Cryptography (PQC) integration within the TLS protocol, specifically identifying two novel attack vectors: handshake exh...
Read analysis →
arXiv: Trust but Verify? Uncovering the Security Debt of Autonomous Coding Agents
A new research paper published on arXiv, titled "Trust but Verify? Uncovering the Security Debt of Autonomous Coding Agents," presents empirical evidence that AI-powered coding agents introduce sig...
Read analysis →
arXiv: Policy-Conditioned Constrained Decoding for Column-Level Access Control in Text-to-SQL
This publication introduces a technical framework called Policy-Conditioned Constrained Decoding, designed to enforce column-level access control in text-to-SQL systems. The paper proposes a method...
Read analysis →
arXiv: Skills That Don't Exist: A Large-Scale Study of Hallucinated Skill Recommendation in LLM Agents
This paper, published on arXiv, presents a large-scale study demonstrating that large language model agents frequently recommend skills or actions that do not actually exist in the real world, a ph...
Read analysis →
arXiv: Antiproof: Synthesizing Vulnerability Detectors and Proofs of Exploitability
This publication from arXiv presents a new methodology called Antiproof, which automates the generation of both vulnerability detectors and proofs of exploitability for AI systems. The research dem...
Read analysis →
arXiv: $\mathrm{P}^{3}$CDA: Privacy-Preserving and Provably Secure Cross Domain Authentication Scheme for Internet of...
This publication, titled P3CDA, presents a new cryptographic framework designed to secure cross-domain authentication for Internet of Drones operations. It proposes a privacy-preserving and provabl...
Read analysis →