Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

1767 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Ransomware: qilin claims C.C. Creations (US) — Consumer Services
Ransomware: qilin claims TagleRock Technologies — Technology
CVE-2025-6254 (CVSS 9.8) — The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versio...
CVE-2026-53469 (CVSS 9.1) — A flaw was found in migration-planner. An authenticated user can exploit this vulnerabili...
CVE-2026-53470 (CVSS 9.6) — A flaw was found in migration-planner. An authenticated attacker could exploit an imprope...
CVE-2026-53474 (CVSS 9.6) — A flaw was found in migration-planner. A remote authenticated attacker could exploit this...
CVE-2026-53475 (CVSS 9.3) — A flaw was found in assisted-migration-agent. The application hardcodes insecure Transpor...
CVE-2026-53476 (CVSS 9.6) — A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the...
CVE-2026-20253 (CVSS 9.8) — In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions...
CVE-2026-35273 (CVSS 9.8) — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (comp...
CELEX:32024R3103R(05)
CELEX:32024R2076R(08)
arXiv: Anchors that Don't Lift: Understanding Supply Chain Driven Kernel Lock-In and Governance-Mediated Mitigation S...
This paper, published on arXiv, is not a regulatory change but a research study that identifies a critical supply chain security vulnerability in small office/home office (SOHO) networking devices....
Read analysis →
arXiv: OpenPCC: Open and Confidential LLM Serving on Commodity TEEs
This paper, published on arXiv, introduces OpenPCC, a technical framework for running large language models (LLMs) on commodity Trusted Execution Environments (TEEs) while maintaining both performa...
Read analysis →
arXiv: A Longitudinal Study of Recently Observed Malicious Domains: Characteristics, Infrastructure, and Abuse Patterns
This publication is a research paper from arXiv, not a regulatory change, but it provides critical empirical evidence that should inform AI safety compliance frameworks. The study analyzes a longit...
Read analysis →
arXiv: Do Transformers Actually Help Intrusion Detection? A Temporal Sequence Evaluation on CIC-IDS2017
This publication is a research paper, not a regulatory change, but it has significant implications for compliance professionals overseeing AI-driven cybersecurity systems under frameworks like the ...
Read analysis →
arXiv: When Discovery Outpaces Remediation: Modeling AI-Accelerated Vulnerability Discovery in Interconnected Systems
This paper, published on arXiv, models a new systemic risk: AI systems can discover software vulnerabilities far faster than humans or traditional tools can patch them. It demonstrates that in inte...
Read analysis →
arXiv: Understanding and mitigating the risks of OpenClaw for non-technical users: A practical guide with Skill
This document, published on arXiv, is a practical guide titled "Understanding and mitigating the risks of OpenClaw for non-technical users." It introduces a new risk framework, AI_SAFETY, specifica...
Read analysis →
arXiv: Context-Based Adversarial Attacks on AI Code Generators: Vulnerability Analysis and Implications
This publication, a research paper from arXiv, presents a new vulnerability analysis of AI code generators. It demonstrates that these systems can be manipulated through context-based adversarial a...
Read analysis →
arXiv: What Do Deepfake Speech Detectors Actually Hear?
This paper, published on arXiv, presents a technical analysis of deepfake speech detectors, revealing that these systems often rely on superficial acoustic artifacts—such as background noise or rec...
Read analysis →