Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

4507 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Ransomware: anubis claims Prelys Courtage (FR) — Financial Services
Ransomware: incransom claims foundationstofreedom.org (US) — Other
Ransomware: termite claims JD Young (CN) — Not Found
Ransomware: anubis claims Coca-Cola / Fairlife (US) — Agriculture and Food Production
Ransomware: safepay claims zinorm.de (DE) — Not Found
Ransomware: safepay claims moebelmayer.de (DE) — Retail & E-Commerce
Ransomware: safepay claims paritaet-nrw.org (DE) — Professional Services
CVE-2026-48144 (CVSS 9.1) — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_gl...
CVE-2026-55971 (CVSS 9.8) — Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affec...
CVE-2026-58023 (CVSS 9.1) — Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Ap...
CVE-2026-58662 (CVSS 9.1) — Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in A...
KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor V...
KEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulne...
arXiv: Incentives and Market Structure in Intent-Based Exchanges: Evidence from a Solver-Reward Reform
This paper, published on arXiv, analyzes a specific regulatory-style reform within a decentralized exchange system, focusing on how changes to solver rewards in an intent-based trading protocol aff...
Read analysis →
arXiv: SIREN (Luring LLMs onto the Rocks): PAIR-Driven Preference Manipulation in Web-RAG Recommenders
This paper, published on arXiv, presents a novel attack vector called SIREN that exploits how large language models (LLMs) are integrated with web-based retrieval-augmented generation (RAG) systems...
Read analysis →
arXiv: Cleaning the NTP Pool: Detecting and Mitigating NTP-Sourced IPv6 Scanning
This paper, published on arXiv, presents a technical analysis of how the Network Time Protocol (NTP) pool can be exploited to conduct large-scale IPv6 scanning, effectively mapping active IPv6 addr...
Read analysis →
arXiv: ISPCloak: Weaponizing ISP for Optimization-Free Physical Camouflage against Deepfake Detectors
This paper, published on arXiv, introduces a novel adversarial attack called ISPCloak that weaponizes the image signal processing (ISP) pipeline—the standard hardware and software chain in cameras—...
Read analysis →
arXiv: PrivDNN: A Secure Multi-Party Computation Framework for Deep Learning using Partial DNN Encryption
This publication introduces PrivDNN, a technical framework for secure multi-party computation in deep learning that uses partial encryption of deep neural networks. While not a regulatory change it...
Read analysis →
arXiv: No Snake Oil: Verifying Python Package Builds
This paper, published on arXiv, presents a technical framework for verifying the integrity of Python package builds, addressing a critical gap in software supply chain security. It proposes methods...
Read analysis →
arXiv: Decentralized Compute on Untrusted Hardware Using Intel TDX and Encrypted CVMs
This paper, published on arXiv, proposes a technical architecture for running decentralized compute workloads on untrusted hardware using Intel TDX and encrypted confidential virtual machines. Whil...
Read analysis →