Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

782 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-48686 (CVSS 9.8) — FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the ...
CVE-2026-48687 (CVSS 9.8) — FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability...
CVE-2026-24212 (CVSS 7.5) — NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is...
CVE-2026-35221 (CVSS 9.8) — Improperly built filter clauses lead to a SQL injection vulnerability in the search query...
CVE-2026-35222 (CVSS 9.8) — Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-40383 (CVSS 9.8) — An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-48691 (CVSS 9.8) — FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PAT...
CVE-2026-8760 (CVSS 9.8) — The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all vers...
CVE-2026-7524 (CVSS 9.8) — IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper val...
CVE-2026-8175 (CVSS 9.8) — IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High...
CVE-2026-48027 (CVSS 9.8) — Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of N...
Ransomware: spacebears claims BASE SPA (IT) — Business Services
A new ransomware incident has been publicly reported involving the Italian business services company BASE SPA. The attack was claimed by the threat group known as Spacebears and published on the ra...
Read analysis →
arXiv: Shortest Path Problem with Subnormal Gaussian Fuzzy Costs
This publication, titled "Shortest Path Problem with Subnormal Gaussian Fuzzy Costs," is a theoretical computer science paper from arXiv, not a regulatory change. It proposes a new mathematical mod...
Read analysis →
arXiv: Risk Averse Alert Prioritization for IDS Using Subnormal Gaussian Fuzzy Models
This publication introduces a novel methodology for prioritizing cybersecurity alerts generated by Intrusion Detection Systems (IDS) using a mathematical approach called Subnormal Gaussian Fuzzy Mo...
Read analysis →
arXiv: Landseer: Exploring the Machine Learning Defense Landscape
This publication, titled Landseer: Exploring the Machine Learning Defense Landscape, is a technical research paper from arXiv that maps current adversarial attack and defense methods for machine le...
Read analysis →
arXiv: Do Modern Post-Hoc Watermarking Methods Beat Broken-Arrows?
A new preprint from arXiv, titled "Do Modern Post-Hoc Watermarking Methods Beat Broken-Arrows?" published on May 26, 2026, evaluates the robustness of current AI-generated content watermarking tech...
Read analysis →
arXiv: BAIT: Boundary-Guided Disclosure Escalation via Self-Conditioned Reasoning
This paper, published on arXiv, introduces BAIT, a new technical framework for improving the safety of large language models (AI systems). BAIT stands for Boundary-Guided Disclosure Escalation via ...
Read analysis →
arXiv: On the Hidden Costs of Counterfactual Knowledge Training in LLM Unlearning
This paper, published on arXiv, presents research on a hidden cost associated with a specific technique used to make large language models (LLMs) forget or "unlearn" problematic data, such as copyr...
Read analysis →
arXiv: Lessons from Penetration Tests on Large-Scale Agent Systems
A new research paper, "Lessons from Penetration Tests on Large-Scale Agent Systems," has been published on arXiv, detailing systematic security vulnerabilities found in autonomous AI agent systems....
Read analysis →
arXiv: Prompt Injection Detection is Regime-Dependent: A Deployment-Aware Evaluation with Interpretable Structural Si...
This paper, published on arXiv, presents a new evaluation framework for detecting prompt injection attacks against large language models. The key finding is that no single detection method works un...
Read analysis →