{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "Regulatory & Compliance Intelligence Desk",
  "home_page_url": "https://intel.gabrieleilardi.com/",
  "feed_url": "https://intel.gabrieleilardi.com/feeds/en/all.json",
  "language": "en",
  "items": [
    {
      "id": "2026-09-28-a114e09a72",
      "url": "https://intel.gabrieleilardi.com/#2026-09-28-a114e09a72",
      "external_url": "https://www.acn.gov.it/portale/en/w/normativa-nis-date-e-informazioni-utili-per-un-implementazione-efficace",
      "title": "NIS2 Italy: baseline security measures due by October 2026",
      "content_html": "<p><strong>What changes:</strong> ACN set October 2026 as the deadline for NIS entities to complete the baseline cybersecurity measures, after incident notification obligations started in January 2026. It applies to every entity that received the NIS designation from ACN.</p><p><strong>Recommended action:</strong> Run a gap check of your controls against the ACN baseline measures now and document the evidence for each one before the deadline.</p><p>ACN (Agenzia per la Cybersicurezza Nazionale) | D.Lgs. 138/2024 Art. 24 | <a href=\"https://www.acn.gov.it/portale/en/w/normativa-nis-date-e-informazioni-utili-per-un-implementazione-efficace\">Original advisory</a></p>",
      "date_published": "2026-09-28T06:00:00.000Z",
      "tags": [
        "regulatory",
        "nis2",
        "deadline",
        "D.Lgs. 138/2024 Art. 24"
      ],
      "_intel": {
        "category": "regulatory",
        "source": "ACN (Agenzia per la Cybersicurezza Nazionale)",
        "framework": "NIS2 & D.Lgs. 138/2024",
        "updateType": "DEADLINE",
        "reference": "D.Lgs. 138/2024 Art. 24"
      }
    },
    {
      "id": "2026-09-27-52d2acb2d8",
      "url": "https://intel.gabrieleilardi.com/#2026-09-27-52d2acb2d8",
      "external_url": "https://www.acn.gov.it/portale/w/vulnerabilita-in-prodotti-citrix-netscaler",
      "title": "Citrix NetScaler ADC and Gateway: 8 vulnerabilities fixed, 2 already exploited",
      "content_html": "<p><strong>Impact:</strong> Citrix reports exploitation of CVE-2026-88771 and CVE-2026-88772 on unpatched NetScaler appliances. These devices usually sit on the internet edge and handle remote access.</p><p><strong>Recommended action:</strong> Apply the Citrix updates to every ADC and Gateway instance, then review appliance logs and active sessions for signs of access before the patch date.</p><p>CSIRT Italia (ACN) | CVE-2026-88771, CVE-2026-88772 | <a href=\"https://www.acn.gov.it/portale/w/vulnerabilita-in-prodotti-citrix-netscaler\">Original advisory</a></p>",
      "date_published": "2026-09-27T06:00:00.000Z",
      "tags": [
        "vulnerability",
        "critical",
        "CVE-2026-88771, CVE-2026-88772"
      ],
      "_intel": {
        "category": "vulnerability",
        "source": "CSIRT Italia (ACN)",
        "severity": "CRITICAL",
        "cve": "CVE-2026-88771, CVE-2026-88772"
      }
    },
    {
      "id": "2026-09-25-9267975d95",
      "url": "https://intel.gabrieleilardi.com/#2026-09-25-9267975d95",
      "external_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65660",
      "title": "Microsoft SharePoint code injection exploited in the wild",
      "content_html": "<p><strong>Impact:</strong> CISA confirms active exploitation: an authorized attacker can execute code over the network on SharePoint servers.</p><p><strong>Recommended action:</strong> Apply the Microsoft mitigations to all on-premises SharePoint farms and check whether any farm is reachable from the internet.</p><p>CISA Known Exploited Vulnerabilities | CVE-2026-65660 | <a href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-65660\">Original advisory</a></p>",
      "date_published": "2026-09-25T06:00:00.000Z",
      "tags": [
        "vulnerability",
        "critical",
        "CVE-2026-65660"
      ],
      "_intel": {
        "category": "vulnerability",
        "source": "CISA Known Exploited Vulnerabilities",
        "severity": "CRITICAL",
        "cve": "CVE-2026-65660"
      }
    },
    {
      "id": "2026-09-24-1c3d1f403b",
      "url": "https://intel.gabrieleilardi.com/#2026-09-24-1c3d1f403b",
      "external_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71362",
      "title": "Adobe Commerce and Magento authorization flaw exploited in the wild",
      "content_html": "<p><strong>Impact:</strong> An unauthenticated attacker can gain elevated access to sensitive resources without user interaction.</p><p><strong>Recommended action:</strong> Patch per the Adobe bulletin, then check the storefront and checkout pages for unexpected script changes.</p><p>CISA Known Exploited Vulnerabilities | CVE-2026-71362 | <a href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71362\">Original advisory</a></p>",
      "date_published": "2026-09-24T06:00:00.000Z",
      "tags": [
        "vulnerability",
        "critical",
        "CVE-2026-71362"
      ],
      "_intel": {
        "category": "vulnerability",
        "source": "CISA Known Exploited Vulnerabilities",
        "severity": "CRITICAL",
        "cve": "CVE-2026-71362"
      }
    },
    {
      "id": "2026-09-22-78e62c2680",
      "url": "https://intel.gabrieleilardi.com/#2026-09-22-78e62c2680",
      "external_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94127",
      "title": "F5 BIG-IP APM: unauthenticated remote code execution with OAuth profiles",
      "content_html": "<p><strong>Impact:</strong> Heap overflow exploitable without credentials when an access policy and an OAuth profile are configured on a virtual server. BIG-IP APM usually fronts VPN and SSO.</p><p><strong>Recommended action:</strong> Identify virtual servers with both an access policy and an OAuth profile and apply the F5 fix or mitigation.</p><p>CISA Known Exploited Vulnerabilities | CVE-2026-94127 | <a href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-94127\">Original advisory</a></p>",
      "date_published": "2026-09-22T06:00:00.000Z",
      "tags": [
        "vulnerability",
        "critical",
        "CVE-2026-94127"
      ],
      "_intel": {
        "category": "vulnerability",
        "source": "CISA Known Exploited Vulnerabilities",
        "severity": "CRITICAL",
        "cve": "CVE-2026-94127"
      }
    },
    {
      "id": "2026-09-22-fffdfafbdb",
      "url": "https://intel.gabrieleilardi.com/#2026-09-22-fffdfafbdb",
      "external_url": "https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/",
      "title": "containerd CRI plugin: 5 vulnerabilities affecting EKS, ECS, Fargate and Bottlerocket",
      "content_html": "<p><strong>Impact:</strong> The issues in containerd 1.7 to 2.3 include image cache poisoning and command execution, with CVSS up to 8.8. AWS patches managed runtimes; self-managed nodes and custom AMIs are the customer's responsibility.</p><p><strong>Recommended action:</strong> Inventory containerd versions on self-managed EKS node groups and custom AMIs, upgrade to the patched upstream release, and roll the nodes.</p><p>AWS Security Bulletins | CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262 | <a href=\"https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/\">Original advisory</a></p>",
      "date_published": "2026-09-22T06:00:00.000Z",
      "tags": [
        "vulnerability",
        "high",
        "CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262"
      ],
      "_intel": {
        "category": "vulnerability",
        "source": "AWS Security Bulletins",
        "severity": "HIGH",
        "cve": "CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262"
      }
    },
    {
      "id": "2026-09-16-5dd58e4e05",
      "url": "https://intel.gabrieleilardi.com/#2026-09-16-5dd58e4e05",
      "external_url": "https://aws.amazon.com/blogs/security/architecting-a-secure-landing-zone-in-the-aws-european-sovereign-cloud/",
      "title": "AWS guidance for a secure landing zone in the European Sovereign Cloud",
      "content_html": "<p><strong>What changes:</strong> The European Sovereign Cloud is a separate AWS partition (aws-eusc) operated in the EU, with its own control plane and IAM. Accounts, policies and tooling built for commercial Regions do not carry over automatically.</p><p><strong>Recommended action:</strong> If you plan EU sovereign workloads, design the account structure, SCPs and logging for the aws-eusc partition from scratch instead of copying the commercial setup.</p><p>AWS Security Blog | AWS European Sovereign Cloud | <a href=\"https://aws.amazon.com/blogs/security/architecting-a-secure-landing-zone-in-the-aws-european-sovereign-cloud/\">Original advisory</a></p>",
      "date_published": "2026-09-16T06:00:00.000Z",
      "tags": [
        "regulatory",
        "cloudsec",
        "guidance",
        "AWS European Sovereign Cloud"
      ],
      "_intel": {
        "category": "regulatory",
        "source": "AWS Security Blog",
        "framework": "Cloud Security",
        "updateType": "GUIDANCE",
        "reference": "AWS European Sovereign Cloud"
      }
    },
    {
      "id": "2026-09-15-1cc9c281ff",
      "url": "https://intel.gabrieleilardi.com/#2026-09-15-1cc9c281ff",
      "external_url": "https://blog.pcisecuritystandards.org/just-published-security-considerations-for-ai-systems",
      "title": "PCI SSC publishes an information supplement on AI system security",
      "content_html": "<p><strong>What changes:</strong> The supplement covers the security of AI used inside payment environments and the defence of traditional systems against AI-assisted attacks. It is guidance, not a new requirement, but assessors are likely to use it as a reference.</p><p><strong>Recommended action:</strong> List any AI components that touch the CDE or cardholder data and check them against the supplement before your next assessment.</p><p>PCI Security Standards Council | PCI SSC Information Supplement | <a href=\"https://blog.pcisecuritystandards.org/just-published-security-considerations-for-ai-systems\">Original advisory</a></p>",
      "date_published": "2026-09-15T06:00:00.000Z",
      "tags": [
        "regulatory",
        "pcidss",
        "guidance",
        "PCI SSC Information Supplement"
      ],
      "_intel": {
        "category": "regulatory",
        "source": "PCI Security Standards Council",
        "framework": "PCI DSS v4.0.1",
        "updateType": "GUIDANCE",
        "reference": "PCI SSC Information Supplement"
      }
    },
    {
      "id": "2026-09-15-2703ba831b",
      "url": "https://intel.gabrieleilardi.com/#2026-09-15-2703ba831b",
      "external_url": "https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/",
      "title": "AWS STS replaces session token limits with a single 4,096-byte limit",
      "content_html": "<p><strong>What changes:</strong> STS replaced the packed policy and session token size limits with one 4,096-byte token limit and now reports token size in API responses. Teams using large session policies or many session tags get more room and a way to monitor it.</p><p><strong>Recommended action:</strong> Review federation and role-assumption flows that previously hit the packed policy limit and add monitoring on the reported token size.</p><p>AWS Security Blog | AWS STS | <a href=\"https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/\">Original advisory</a></p>",
      "date_published": "2026-09-15T06:00:00.000Z",
      "tags": [
        "regulatory",
        "cloudsec",
        "guidance",
        "AWS STS"
      ],
      "_intel": {
        "category": "regulatory",
        "source": "AWS Security Blog",
        "framework": "Cloud Security",
        "updateType": "GUIDANCE",
        "reference": "AWS STS"
      }
    },
    {
      "id": "2026-09-14-fa22718974",
      "url": "https://intel.gabrieleilardi.com/#2026-09-14-fa22718974",
      "external_url": "https://blog.pcisecuritystandards.org/just-published-pci-key-management-operations-kmo-standard-v1.0",
      "title": "New PCI Key Management and Operations (KMO) Standard v1.0",
      "content_html": "<p><strong>What changes:</strong> A new PCI standard with security and test requirements for entities that operate systems using cryptographic keys to protect account data. It is relevant to processors, HSM operators and key custodians.</p><p><strong>Recommended action:</strong> Map your current key management procedures (PCI DSS Requirements 3.6 and 3.7) against KMO v1.0 and list the gaps before your next assessment cycle.</p><p>PCI Security Standards Council | PCI KMO Standard v1.0 | <a href=\"https://blog.pcisecuritystandards.org/just-published-pci-key-management-operations-kmo-standard-v1.0\">Original advisory</a></p>",
      "date_published": "2026-09-14T06:00:00.000Z",
      "tags": [
        "regulatory",
        "pcidss",
        "new_rule",
        "PCI KMO Standard v1.0"
      ],
      "_intel": {
        "category": "regulatory",
        "source": "PCI Security Standards Council",
        "framework": "PCI DSS v4.0.1",
        "updateType": "NEW_RULE",
        "reference": "PCI KMO Standard v1.0"
      }
    }
  ]
}