Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4608 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-10134 (CVSS 10.0) — IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available t...
CVE-2026-10140 (CVSS 9.6) — IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling ...
CVE-2026-11708 (CVSS 9.3) — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulne...
CVE-2026-11712 (CVSS 9.3) — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulne...
CVE-2026-7663 (CVSS 9.1) — IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access prote...
CVE-2026-7803 (CVSS 9.8) — IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper...
CVE-2026-7871 (CVSS 9.8) — IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary ...
CVE-2026-7873 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary ...
CVE-2026-7874 (CVSS 9.1) — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored creden...
CVE-2026-58449 (CVSS 9.8) — txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose fun...
CVE-2026-56278 (CVSS 9.1) — Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default...
CVE-2026-56700 (CVSS 9.8) — Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsa...
MaRisk-Novelle: Mehr Proportionalität
arXiv: Proofs of Ownership for Machine Learning Models
This publication from arXiv introduces a technical framework for establishing proof of ownership for machine learning models, addressing a critical gap in AI governance. The paper proposes cryptogr...
Read analysis →
arXiv: Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model Hubs
This publication, "Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model Hubs," is a research paper from arXiv that identifies critical security vul...
Read analysis →
arXiv: Quantum Lazy Sampling and Path Recording for Any Group
This publication introduces a novel computational method called Quantum Lazy Sampling and Path Recording for Any Group, which proposes a framework for more efficient quantum algorithm design. While...
Read analysis →
arXiv: Defending Against Harmful Supervision Hidden in Benign Samples
As a senior EU regulatory compliance analyst, I provide the following summary of this publication for compliance professionals. This paper, published on arXiv, introduces a novel vulnerability in ...
Read analysis →
arXiv: Robust secret storage in networks
This is a technical research paper published on arXiv, not a regulatory change. It proposes a new cryptographic method for robust secret storage across distributed networks, focusing on resilience ...
Read analysis →
arXiv: The Spectrum Strikes Back: Infrared POV Attacks on Traffic Sign Classification
A new preprint from arXiv, titled "The Spectrum Strikes Back: Infrared POV Attacks on Traffic Sign Classification," published on June 29, 2026, demonstrates a novel adversarial attack method that e...
Read analysis →
arXiv: On the Internet, Nobody Knows You're an LLM Bot: Unmasking Web Agents with Multi-Layer Fingerprinting
This paper, published on arXiv, introduces a new method for detecting AI-powered web bots, specifically large language model agents, by using multi-layer fingerprinting. The research demonstrates t...
Read analysis →