Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4507 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Ransomware: qilin claims PJ Daly Contracting (IE) — Construction
[claim-framed]The ransomware group Qilin has published a claim on the ransomwarelive leak-site mirror, dated 19 June 2026, listing PJ Daly Contracting (IE) as a victim. The posting alleges an incid...
Read analysis →
Ransomware: nova claims Desert Micro — Technology
[claim-framed]Ransomware group "nova" has listed Desert Micro on its leak site, claiming the organization as a victim. The posting, mirrored by ransomwarelive, alleges an incident but provides no v...
Read analysis →
Ransomware: anubis claims KTR Real Estate Advisors (US) — Financial Services
[claim-framed]On 2026-06-19, the ransomware group anubis posted a claim on its leak site naming KTR Real Estate Advisors, a US financial services firm. The posting alleges an incident involving the...
Read analysis →
Ransomware: Icarus claims Klue.com (CA) — Technology
[claim-framed]On 2026-06-19, the ransomware group Icarus published a claim on the ransomwarelive leak-site mirror, listing Klue.com (CA) as a victim in the Technology sector. The posting alleges an...
Read analysis →
Ransomware: stormous claims mlit.com.my UPDATE-FULL DATA DUMP 10GB (MY) — Public Sector
Ransomware: aurora claims Hagerman & Company — Business Services
CVE-2026-56081 (CVSS 9.1) — Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker regist...
CVE-2026-11551 (CVSS 9.8) — The Branda plugin for WordPress is vulnerable to privilege escalation via account takeove...
Breach: JCPenney (368,418 accounts) — Dates of birth, Email addresses, Government issued IDs
CVE-2026-8024 (CVSS 9.8) — A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnera...
CVE-2026-54390 (CVSS 9.8) — JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerabi...
CVE-2026-47647 (CVSS 9.9) — Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevat...
CVE-2026-54130 (CVSS 9.8) — Missing authentication for critical function in M365 Copilot allows an unauthorized attac...
CVE-2026-7515 (CVSS 9.8) — The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions ...
CVE-2026-8713 (CVSS 9.1) — The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion d...
CVE-2026-45480 (CVSS 10.0) — Improper authentication in Azure Active Directory allows an unauthorized attacker to ele...
CVE-2026-48582 (CVSS 9.6) — Missing authorization in Microsoft Exchange Online allows an authorized attacker to eleva...
CVE-2026-48584 (CVSS 9.9) — Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to e...
CVE-2026-56073 (CVSS 9.4) — Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verificatio...
Press release - Press conference: European Democracy Shield findings and recommendations