Every entry below was pulled directly from a regulator’s feed in the last few days — CELLAR, EBA, ESMA, ENISA, BSI, BaFin, ANSSI and 14 other sources — classified against 21 EU compliance frameworks and summarised. Updates daily.
BREACHransomwarelive11 Sept 2026
Unverified leak-site claim: Dragonforce names Medical Department Store (US) — Retail & E-Commerce
A ransomware group has listed Medical Department Store (US), a retail and e-commerce organisation, on its leak site, according to a posting mirrored by ransomwarelive on 11 September 2026. The claim is unverified. The…
BREACHransomwarelive12 Sept 2026
Unverified leak-site claim: Securotrop names Shelco Filters (US) — Manufacturing
A ransomware group has listed Shelco Filters (US) on its leak site, according to a posting mirrored by ransomwarelive on 12 September 2026. The claim is unverified. Shelco Filters has not confirmed it, and such claims…
BREACHransomwarelive11 Sept 2026
Unverified leak-site claim: Safepay names compunnel.com (US) — Technology
A ransomware group using the name Safepay has listed compunnel.com, a US technology company, on its leak site, according to a posting mirrored by ransomwarelive on 11 September 2026. The posting is a claim only.…
BREACHransomwarelive11 Sept 2026
Unverified leak-site claim: Direwolf names Port of Tanjung Pelepas (MY) — Transportation
On 11 September 2026, a ransomware group using the name Direwolf listed Port of Tanjung Pelepas in Malaysia on its leak site, according to a posting mirrored by ransomwarelive. The posting is a claim only. The…
BREACHransomwarelive11 Sept 2026
Unverified leak-site claim: Fulcrumsec names Dustin Group (SE) — Technology
A ransomware group using the name Fulcrumsec has listed Dustin Group (SE), a technology company, on its leak site, according to a posting dated 11 September 2026 mirrored by ransomware.live. The posting is a claim only.…
BREACHransomwarelive11 Sept 2026
Unverified leak-site claim: Panzer names Konica Minolta Bulgaria (BG) — Manufacturing
A ransomware group calling itself Panzer has listed Konica Minolta Bulgaria (BG) — Manufacturing on its leak site, according to a posting mirrored by ransomwarelive on 11 September 2026. The posting is a claim only.…
BREACHransomwarelive11 Sept 2026
Unverified leak-site claim: Qilin names Imperial Healthcare Solutions (US) — Healthcare
A ransomware group calling itself Qilin has listed Imperial Healthcare Solutions (US) on its leak site, according to a posting mirrored by ransomwarelive on 11 September 2026. The posting is a claim only; it does not…
BREACHransomwarelive20 Jun 2026
Unverified leak-site claim: Lockbit5 names drwu.com (CN) — Not Found
Ransomwarelive, which mirrors ransomware groups' own leak-site postings, has listed drwu.com (CN) as a claimed victim of Lockbit5, according to a posting dated 20 June 2026. This is only an allegation published by the…
CVEnvd11 Sept 2026
CVE-2026-89009 (CVSS 9.1) — WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the devi
The National Vulnerability Database has published CVE-2026-89009, a critical vulnerability (CVSS 9.1) affecting WAVLINK WN535M1 and WN535M3 routers running firmware versions prior to M35M1_V250922. The flaw is an…
CVEkev11 Sept 2026
KEV: CVE-2026-84869 — ConnectWise ScreenConnect (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability)
CISA added CVE-2026-84869, an improper privilege management and missing authorization flaw in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities catalog on 11 September 2026. The vulnerability allows an…
CVEkev11 Sept 2026
KEV: CVE-2026-42016 — JFrog Artifactory (JFrog Artifactory Incorrect Authorization Vulnerability)
CVEkev11 Sept 2026
KEV: CVE-2026-42018 — JFrog Artifactory (JFrog Artifactory Improper Authentication Vulnerability)
CVEkev11 Sept 2026
KEV: CVE-2026-85706 — GitLab Community Edition and Enterprise Edition (GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability)
CRABSI11 Sept 2026
Cyber Resilience Act: Meldepflicht startet
DORAEU CELLAR11 Sept 2026
CELEX:32024R0249R(06)
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Don't Trust the Super-App: A Case Study of Russia's Max
A new arXiv case study examines Russia's Max super-app and argues that bundling messaging, payments, identity, and government services into a single platform creates systemic trust and surveillance risks. The paper,…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: SpecGuard: Inference-Time Backdoor Detection For Free
A new arXiv paper introduces SpecGuard, a method for detecting backdoors in AI models at inference time without requiring access to training data or model internals. Backdoors are hidden triggers that cause a model to…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Predicting Privacy Leakage from Weight Spectral Density
A new arXiv paper proposes a method to predict privacy leakage in machine learning models by analyzing weight spectral density, offering a way to assess privacy risk without running expensive attack simulations. While…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Differentially Private EEG Feature Anonymization: A Privacy-Utility Case Study in Clinical Neurophysiology
A new arXiv preprint (2609.11777v1, published 10 September 2026) presents a case study on applying differential privacy to anonymize EEG features in clinical neurophysiology. The authors demonstrate a privacy-utility…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Signing the Transaction but Not the Decision: Whisper Attacks and a Binding Defense for AP2
A new arXiv paper identifies a security flaw in the AP2 agent payment protocol, which lets AI agents authorize transactions on a user's behalf. The researchers describe "whisper attacks," where a malicious prompt hidden…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Certifying Adversarial Robustness of Quantum Classifiers under Known-Readout Query Access
A new arXiv paper proposes a certification method for the adversarial robustness of quantum classifiers operating under known-readout query access. The work, published on 10 September 2026, sets out a formal framework…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: PHAT: PHotonic Accelerator for TFHE
A new arXiv paper describes PHAT, a photonic accelerator designed to speed up TFHE, a form of fully homomorphic encryption that allows computation on encrypted data. The work is a technical research contribution rather…
EU AI Actarxiv_cscr10 Sept 2026
arXiv: From Intent to Execution Grant: An Execution-Boundary Conformance Profile for High-Risk AI Actions
A new arXiv paper proposes an "execution-boundary conformance profile" for high-risk AI actions under the EU AI Act. The work introduces a framework called the From Intent to Execution Grant, which focuses on the…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: CHERI-D Reincarnate: efficient multicore CHERI temporal memory safety through allocation reincarnation (draft version)
This publication is a draft research paper posted to arXiv, not a regulatory instrument. It describes CHERI-D Reincarnate, a technique for improving temporal memory safety in multicore CHERI-based processors through…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Accountability in Certificate Transparency and Variants
A new arXiv paper examines accountability gaps in Certificate Transparency (CT) and its variants, the systems that log TLS certificates so mis-issuance can be detected. The authors analyze how well these logs actually…
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: On Identifying Sound Conditions for Frontrunning Resistance
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Chypothermia: Clock Freezing for Static Side-channel Attacks
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Heterogeneous Cross-Chain Transaction Tracing for Solana Bridges via Candidate-Set Selective Decision
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: "They don't care about this": A Systematic Study of TEE Build Reproducibility in the Wild
AI_SAFETYarxiv_cscr10 Sept 2026
arXiv: Deep-Fake CAPTCHA: Mitigating Next-Generation Social Engineering Attacks