Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4430 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Ransomware: thegentlemen claims Michigan Surgical Center (US) — Healthcare
CVE-2026-5241 (CVSS 9.6) — A vulnerability in the LightGlue model loading path of huggingface/transformers version 5....
CVE-2026-49185 (CVSS 9.8) — The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(...
CVE-2026-49186 (CVSS 9.8) — The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allo...
CVE-2026-49188 (CVSS 9.8) — The ai_cmd utility executes with full root permissions. It pipes socket inputs directly t...
CVE-2026-49191 (CVSS 9.8) — The production build of the M3WebServer hard-codes its backend API keys, which can be eas...
CVE-2026-50208 (CVSS 9.4) — High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined wi...
CVE-2026-50211 (CVSS 9.8) — Leftover engineering diagnostics and factory-level diagnostic software remain exposed on ...
CVE-2026-4104 (CVSS 9.8) — Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Inform...
CVE-2019-25727 (CVSS 9.8) — WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability t...
CVE-2019-25729 (CVSS 9.8) — PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauth...
CVE-2019-25738 (CVSS 9.8) — WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability...
CVE-2019-25741 (CVSS 9.8) — Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overfl...
CVE-2026-25550 (CVSS 9.8) — Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code ex...
CVE-2026-48567 (CVSS 10.0) — Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to ...
CVE-2026-48579 (CVSS 9.1) — Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to di...
arXiv: What If Prompt Injection Never Left? Exploring Cross-Session Stored Prompt Injection in Agentic Systems
This publication, a research paper from arXiv, identifies a new vulnerability in AI agentic systems called cross-session stored prompt injection. Unlike traditional prompt injection attacks that oc...
Read analysis →
Ransomware: krybit claims www.elumax.com (DE) — Business Services
[claim-framed]On 2026-06-03, the ransomware group krybit published a claim on a leak-site mirror, listing www.elumax.com, a German business services firm, as an alleged victim. The posting asserts ...
Read analysis →
arXiv: Preserving Data Privacy in Learning Causal Structure with Fully Homomorphic Encryption
A new research paper published on arXiv proposes a method for learning causal structures from data while preserving privacy using Fully Homomorphic Encryption (FHE). This technique allows organizat...
Read analysis →
arXiv: A-Live: Passive Liveness Detection via Neuromuscular Micro-Motion Signatures on Commodity Sensors
This paper, published on arXiv, introduces a novel passive liveness detection method called A-Live, which uses commodity sensors to identify neuromuscular micro-motion signatures. This technology c...
Read analysis →