Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

1668 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-41699 (CVSS 8.1) — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing ...
CVE-2026-11561 (CVSS 9.8) — Improper neutralization of special elements used in an expression language statement ('ex...
CVE-2026-11849 (CVSS 9.8) — The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credenti...
CVE-2026-53787 (CVSS 9.8) — Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated ar...
CVE-2026-6853 (CVSS 9.8) — Improper restriction of excessive authentication attempts vulnerability in Başbelen Group ...
CVE-2026-48558 (CVSS 10.0) — SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authenticat...
CVE-2026-53838 (CVSS 9.8) — OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconne...
Konsultation 06/2026: KAMaRisk - Änderungsübersicht/Konsultationsfassung
KAMaRisk: Bafin konsultiert Rundschreiben
arXiv: Amnesia: A Stealthy Replay Attack on Continual Learning Dreams
This paper, published on arXiv on June 10, 2026, introduces a novel cybersecurity vulnerability called the "Amnesia" attack, which targets continual learning systems. Continual learning is a machin...
Read analysis →
arXiv: Beyond Runtime Enforcement: Shield Synthesis as Defensibility Analysis for Adversarial Networks
This publication introduces a novel technical framework for evaluating the defensibility of AI systems against adversarial manipulation, moving beyond traditional runtime enforcement methods. The p...
Read analysis →
arXiv: Beyond the IT Checklist: Engineering a Reasonable Standard of Care for Cyber Safety
This paper, published on arXiv, proposes a new framework for defining a "reasonable standard of care" for cybersecurity, moving beyond simple compliance checklists. It argues that current regulator...
Read analysis →
arXiv: Differentially Private Hierarchical Heavy Hitters
This paper, published on arXiv, introduces a new algorithm for differentially private hierarchical heavy hitters, a technique used to identify the most frequent items in a dataset while preserving ...
Read analysis →
arXiv: Intent-Based Cryptographic API Design for Cryptographic Agility
This publication from arXiv introduces a new design framework for cryptographic APIs that prioritizes intent-based programming, enabling systems to automatically adapt cryptographic algorithms and ...
Read analysis →
arXiv: An Assessment Framework for Application-Level Cryptographic Agility
A new academic framework has been published on arXiv titled "An Assessment Framework for Application-Level Cryptographic Agility," which proposes a structured methodology for evaluating how easily ...
Read analysis →
arXiv: Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents
This paper, published on arXiv, introduces a new benchmarking framework called "Who Pays the Price?" designed to evaluate how real-world web agents—AI systems that interact with websites and online...
Read analysis →
arXiv: Split Tallies: A Discrete Certificate Calculus for Auditing Dynamic Ordered Sets in Constant Memory
This publication introduces a novel cryptographic method called Split Tallies, which enables the auditing of dynamic ordered sets, such as transaction logs or supply chain records, using only const...
Read analysis →
arXiv: The Invisible Ink of the Android Malware World: A Longitudinal Study on the Usage of Covert Communication Chan...
This publication, a longitudinal study from arXiv, analyzes how Android malware has increasingly used covert communication channels—such as steganography, encrypted payloads in network traffic, and...
Read analysis →
arXiv: The Emergence of Autonomous Penetration Capabilities in Large Language Model-Powered AI Systems
This paper, published on arXiv on June 11, 2026, presents research demonstrating that large language model-powered AI systems can now autonomously develop and execute penetration testing capabiliti...
Read analysis →
arXiv: DIG: Oracle-Guided Directed Input Generation for One-Day Vulnerabilities