Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4430 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-10966 (CVSS 9.6) — Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a ...
CVE-2026-10971 (CVSS 9.6) — Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior ...
CVE-2026-10972 (CVSS 9.6) — Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote...
CVE-2026-10974 (CVSS 9.6) — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827....
CVE-2026-10990 (CVSS 9.6) — Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker ...
CVE-2026-11002 (CVSS 9.6) — Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attac...
CVE-2026-11113 (CVSS 9.6) — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827....
CVE-2026-11120 (CVSS 9.6) — Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior...
CVE-2026-6274 (CVSS 9.8) — Improper Authentication, Missing authentication for critical function, Weak Authentication...
CVE-2025-71317 (CVSS 9.8) — NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' ...
CVE-2025-71318 (CVSS 9.8) — NetMan 204 fails to enforce authentication on its administrative pages and command endpoi...
CVE-2026-10580 (CVSS 9.8) — The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authenticatio...
KEV: CVE-2026-28318 — SolarWinds Serv-U (SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability)
CELEX:32024R0567R(02)
arXiv: Will the Agent Recuse Itself? Measuring LLM-Agent Compliance with In-Band Access-Deny Signals
This paper, published on arXiv, presents a study on whether large language model (LLM) agents will comply with in-band access-deny signals—essentially, instructions embedded in a system’s output th...
Read analysis →
arXiv: WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents
A new research paper published on arXiv, titled "WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents," identifies a novel vulnerability in large language model (LLM) agents th...
Read analysis →
arXiv: Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations
This paper, published on arXiv, analyzes a critical privacy vulnerability in the implementation of digital identity wallets under the updated eIDAS2 regulatory framework. The research identifies th...
Read analysis →
arXiv: Robust Ensemble of Selectively Strengthened and Augmented Predictors
This paper, published on arXiv, proposes a new technical framework called "Robust Ensemble of Selectively Strengthened and Augmented Predictors" (RESSAP) for improving the safety and reliability of...
Read analysis →
arXiv: SecRL-Prune: Structured Reinforcement Learning-Based Pruning of CodeLLMs for Preserving Adversarial Code Mutation
This paper, published on arXiv, introduces SecRL-Prune, a new technical framework for pruning large language models used in code generation. The method uses reinforcement learning to selectively re...
Read analysis →
arXiv: Steering LLM Viewpoints through Fabricated Evidence Injection
A new preprint from arXiv, titled "Steering LLM Viewpoints through Fabricated Evidence Injection," demonstrates a novel attack vector against large language models. The research shows that by injec...
Read analysis →