Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

5038 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Ransomware: thegentlemen claims Thialf (NL) — Energy & Utilities
Ransomware: thegentlemen claims Decoupe Laser Services (FR) — Manufacturing
Ransomware: thegentlemen claims Oldelval Oleoductos del Valle (AR) — Energy & Utilities
Ransomware: thegentlemen claims TC Printing (AU) — Manufacturing
Ransomware: qilin claims Corporate 360 Business Solutions (CA) — Professional Services
CVE-2026-65689 (CVSS 9.8) — Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath valida...
CVE-2026-65700 (CVSS 9.8) — h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible fil...
CVE-2026-15981 (CVSS 9.8) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication ...
CVE-2024-58354 (CVSS 9.9) — cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover v...
CVE-2025-71389 (CVSS 10.0) — Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execu...
CVE-2026-63732 (CVSS 9.9) — 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default...
CVE-2026-50517 (CVSS 9.9) — Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execut...
CVE-2026-54120 (CVSS 9.9) — Improper input validation in Microsoft Surface allows an authorized attacker to execute c...
CVE-2026-56160 (CVSS 9.1) — Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to ...
CVE-2026-56165 (CVSS 9.8) — Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execut...
CVE-2026-56191 (CVSS 10.0) — Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to ...
CVE-2026-58275 (CVSS 10.0) — Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges...
CVE-2026-62825 (CVSS 10.0) — Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate pr...
arXiv: Pure-DP Statistical Query Release at the Conjectured Square-Root Rate
This paper, published on arXiv, presents a new theoretical method for releasing statistical queries from a dataset while achieving pure differential privacy at the conjectured square-root rate. Thi...
Read analysis →
arXiv: Constant-time decoding of Gabidulin codes and their generalizations with application to RQC
This publication from July 2026 presents a new cryptographic algorithm for constant-time decoding of Gabidulin codes, which are a type of error-correcting code used in post-quantum cryptography. Th...
Read analysis →