Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4430 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-42904 (CVSS 9.6) — Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate p...
CVE-2026-44815 (CVSS 9.8) — Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to exe...
CVE-2026-45602 (CVSS 9.1) — No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform t...
CVE-2026-45657 (CVSS 9.8) — Use after free in Windows Kernel allows an unauthorized attacker to execute code over a n...
CVE-2026-47281 (CVSS 9.6) — Improper input validation in Visual Studio Code allows an unauthorized attacker to elevat...
CVE-2026-47291 (CVSS 9.8) — Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to exe...
CVE-2026-47643 (CVSS 9.8) — External control of file name or path in Azure Stack Edge allows an unauthorized attacker...
CVE-2026-34691 (CVSS 9.3) — Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by...
CVE-2026-47928 (CVSS 9.6) — ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validat...
CVE-2026-48303 (CVSS 10.0) — Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an In...
KEV: CVE-2026-11645 — Google Chromium V8 (Google Chromium V8 Out-of-Bounds Read and Write Vulnerability)
KEV: CVE-2026-7473 — Arista Extensible Operating System (Arista Extensible Operating System Incomplete Comparison wit...
CELEX:32024R1178R(01)
arXiv: Pretrained, Frozen, Still Leaking: Auditing Cross-Encoder Attribute Transfer in EEG Foundation Models
This paper, published on arXiv, presents a security audit of foundation models used for electroencephalography (EEG) data. The researchers demonstrate that even when an EEG model is "frozen" (its p...
Read analysis →
arXiv: EnclaveScale: Hardware-Assisted Edge-DP for Secure Data Centre Power Telemetry
This publication introduces EnclaveScale, a hardware-assisted framework designed to enable differential privacy for power telemetry data in data centres. The paper proposes using trusted execution ...
Read analysis →
arXiv: Customization under Fire: Plugin Poisoning in Text-to-Image Ecosystem
A new research paper, titled "Customization under Fire: Plugin Poisoning in Text-to-Image Ecosystem," has been published on arXiv, highlighting a significant security vulnerability in AI-driven tex...
Read analysis →
arXiv: PrivCode++: Latent-Conditioned Differentially Private Code Generation for Comprehensive Guarantees
This paper, PrivCode++: Latent-Conditioned Differentially Private Code Generation for Comprehensive Guarantees, published on arXiv, introduces a new technical framework for generating code with for...
Read analysis →
arXiv: Steganography Without Modification: Hidden Communication via LLM Seeds
This paper, published on arXiv, introduces a novel steganography technique that embeds hidden messages within the outputs of large language models without altering the generated text itself. Instea...
Read analysis →
arXiv: Unveiling Privacy Risks in Multi-modal Large Language Models: Task-specific Vulnerabilities and Mitigation Cha...
This publication is a pre-print research paper from arXiv, not a regulatory change. It analyzes privacy vulnerabilities in multi-modal large language models (MLLMs) that process text, images, and a...
Read analysis →
arXiv: Context-Fractured Decomposition Attacks on Tool-Using LLM Agents: Exploiting Artifact Provenance Gaps
This paper, published on arXiv, identifies a novel vulnerability in large language model agents that use external tools, such as code interpreters or file systems. The attack, called Context-Fractu...
Read analysis →