<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Regulatory &amp; Compliance Intelligence Desk</title>
    <link>https://intel.gabrieleilardi.com/</link>
    <atom:link href="https://intel.gabrieleilardi.com/feeds/en/all.xml" rel="self" type="application/rss+xml" />
    <description>Regulatory updates for NIS2, ISO 27001, PCI DSS and cloud security, plus critical vulnerabilities, from official sources.</description>
    <language>en-GB</language>
    <lastBuildDate>Mon, 28 Sep 2026 08:00:00 GMT</lastBuildDate>
    <ttl>360</ttl>
    <item>
      <title>[DEADLINE] NIS2 Italy: baseline security measures due by October 2026</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-28-a114e09a72</link>
      <guid isPermaLink="false">2026-09-28-a114e09a72</guid>
      <pubDate>Mon, 28 Sep 2026 06:00:00 GMT</pubDate>
      <category>regulatory</category>
      <category>NIS2 &amp; D.Lgs. 138/2024</category>
      <description>&lt;p&gt;&lt;strong&gt;What changes:&lt;/strong&gt; ACN set October 2026 as the deadline for NIS entities to complete the baseline cybersecurity measures, after incident notification obligations started in January 2026. It applies to every entity that received the NIS designation from ACN.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Run a gap check of your controls against the ACN baseline measures now and document the evidence for each one before the deadline.&lt;/p&gt;&lt;p&gt;ACN (Agenzia per la Cybersicurezza Nazionale) | D.Lgs. 138/2024 Art. 24 | &lt;a href=&quot;https://www.acn.gov.it/portale/en/w/normativa-nis-date-e-informazioni-utili-per-un-implementazione-efficace&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[CRITICAL VULNERABILITY] Citrix NetScaler ADC and Gateway: 8 vulnerabilities fixed, 2 already exploited</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-27-52d2acb2d8</link>
      <guid isPermaLink="false">2026-09-27-52d2acb2d8</guid>
      <pubDate>Sun, 27 Sep 2026 06:00:00 GMT</pubDate>
      <category>vulnerability</category>
      <category>CRITICAL</category>
      <description>&lt;p&gt;&lt;strong&gt;Impact:&lt;/strong&gt; Citrix reports exploitation of CVE-2026-88771 and CVE-2026-88772 on unpatched NetScaler appliances. These devices usually sit on the internet edge and handle remote access.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Apply the Citrix updates to every ADC and Gateway instance, then review appliance logs and active sessions for signs of access before the patch date.&lt;/p&gt;&lt;p&gt;CSIRT Italia (ACN) | CVE-2026-88771, CVE-2026-88772 | &lt;a href=&quot;https://www.acn.gov.it/portale/w/vulnerabilita-in-prodotti-citrix-netscaler&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[CRITICAL VULNERABILITY] Microsoft SharePoint code injection exploited in the wild</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-25-9267975d95</link>
      <guid isPermaLink="false">2026-09-25-9267975d95</guid>
      <pubDate>Fri, 25 Sep 2026 06:00:00 GMT</pubDate>
      <category>vulnerability</category>
      <category>CRITICAL</category>
      <description>&lt;p&gt;&lt;strong&gt;Impact:&lt;/strong&gt; CISA confirms active exploitation: an authorized attacker can execute code over the network on SharePoint servers.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Apply the Microsoft mitigations to all on-premises SharePoint farms and check whether any farm is reachable from the internet.&lt;/p&gt;&lt;p&gt;CISA Known Exploited Vulnerabilities | CVE-2026-65660 | &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-65660&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[CRITICAL VULNERABILITY] Adobe Commerce and Magento authorization flaw exploited in the wild</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-24-1c3d1f403b</link>
      <guid isPermaLink="false">2026-09-24-1c3d1f403b</guid>
      <pubDate>Thu, 24 Sep 2026 06:00:00 GMT</pubDate>
      <category>vulnerability</category>
      <category>CRITICAL</category>
      <description>&lt;p&gt;&lt;strong&gt;Impact:&lt;/strong&gt; An unauthenticated attacker can gain elevated access to sensitive resources without user interaction.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Patch per the Adobe bulletin, then check the storefront and checkout pages for unexpected script changes.&lt;/p&gt;&lt;p&gt;CISA Known Exploited Vulnerabilities | CVE-2026-71362 | &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-71362&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[CRITICAL VULNERABILITY] F5 BIG-IP APM: unauthenticated remote code execution with OAuth profiles</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-22-78e62c2680</link>
      <guid isPermaLink="false">2026-09-22-78e62c2680</guid>
      <pubDate>Tue, 22 Sep 2026 06:00:00 GMT</pubDate>
      <category>vulnerability</category>
      <category>CRITICAL</category>
      <description>&lt;p&gt;&lt;strong&gt;Impact:&lt;/strong&gt; Heap overflow exploitable without credentials when an access policy and an OAuth profile are configured on a virtual server. BIG-IP APM usually fronts VPN and SSO.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Identify virtual servers with both an access policy and an OAuth profile and apply the F5 fix or mitigation.&lt;/p&gt;&lt;p&gt;CISA Known Exploited Vulnerabilities | CVE-2026-94127 | &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-94127&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[HIGH VULNERABILITY] containerd CRI plugin: 5 vulnerabilities affecting EKS, ECS, Fargate and Bottlerocket</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-22-fffdfafbdb</link>
      <guid isPermaLink="false">2026-09-22-fffdfafbdb</guid>
      <pubDate>Tue, 22 Sep 2026 06:00:00 GMT</pubDate>
      <category>vulnerability</category>
      <category>HIGH</category>
      <description>&lt;p&gt;&lt;strong&gt;Impact:&lt;/strong&gt; The issues in containerd 1.7 to 2.3 include image cache poisoning and command execution, with CVSS up to 8.8. AWS patches managed runtimes; self-managed nodes and custom AMIs are the customer&apos;s responsibility.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Inventory containerd versions on self-managed EKS node groups and custom AMIs, upgrade to the patched upstream release, and roll the nodes.&lt;/p&gt;&lt;p&gt;AWS Security Bulletins | CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262 | &lt;a href=&quot;https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[GUIDANCE] AWS guidance for a secure landing zone in the European Sovereign Cloud</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-16-5dd58e4e05</link>
      <guid isPermaLink="false">2026-09-16-5dd58e4e05</guid>
      <pubDate>Wed, 16 Sep 2026 06:00:00 GMT</pubDate>
      <category>regulatory</category>
      <category>Cloud Security</category>
      <description>&lt;p&gt;&lt;strong&gt;What changes:&lt;/strong&gt; The European Sovereign Cloud is a separate AWS partition (aws-eusc) operated in the EU, with its own control plane and IAM. Accounts, policies and tooling built for commercial Regions do not carry over automatically.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; If you plan EU sovereign workloads, design the account structure, SCPs and logging for the aws-eusc partition from scratch instead of copying the commercial setup.&lt;/p&gt;&lt;p&gt;AWS Security Blog | AWS European Sovereign Cloud | &lt;a href=&quot;https://aws.amazon.com/blogs/security/architecting-a-secure-landing-zone-in-the-aws-european-sovereign-cloud/&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[GUIDANCE] PCI SSC publishes an information supplement on AI system security</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-15-1cc9c281ff</link>
      <guid isPermaLink="false">2026-09-15-1cc9c281ff</guid>
      <pubDate>Tue, 15 Sep 2026 06:00:00 GMT</pubDate>
      <category>regulatory</category>
      <category>PCI DSS v4.0.1</category>
      <description>&lt;p&gt;&lt;strong&gt;What changes:&lt;/strong&gt; The supplement covers the security of AI used inside payment environments and the defence of traditional systems against AI-assisted attacks. It is guidance, not a new requirement, but assessors are likely to use it as a reference.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; List any AI components that touch the CDE or cardholder data and check them against the supplement before your next assessment.&lt;/p&gt;&lt;p&gt;PCI Security Standards Council | PCI SSC Information Supplement | &lt;a href=&quot;https://blog.pcisecuritystandards.org/just-published-security-considerations-for-ai-systems&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[GUIDANCE] AWS STS replaces session token limits with a single 4,096-byte limit</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-15-2703ba831b</link>
      <guid isPermaLink="false">2026-09-15-2703ba831b</guid>
      <pubDate>Tue, 15 Sep 2026 06:00:00 GMT</pubDate>
      <category>regulatory</category>
      <category>Cloud Security</category>
      <description>&lt;p&gt;&lt;strong&gt;What changes:&lt;/strong&gt; STS replaced the packed policy and session token size limits with one 4,096-byte token limit and now reports token size in API responses. Teams using large session policies or many session tags get more room and a way to monitor it.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Review federation and role-assumption flows that previously hit the packed policy limit and add monitoring on the reported token size.&lt;/p&gt;&lt;p&gt;AWS Security Blog | AWS STS | &lt;a href=&quot;https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[NEW RULE] New PCI Key Management and Operations (KMO) Standard v1.0</title>
      <link>https://intel.gabrieleilardi.com/#2026-09-14-fa22718974</link>
      <guid isPermaLink="false">2026-09-14-fa22718974</guid>
      <pubDate>Mon, 14 Sep 2026 06:00:00 GMT</pubDate>
      <category>regulatory</category>
      <category>PCI DSS v4.0.1</category>
      <description>&lt;p&gt;&lt;strong&gt;What changes:&lt;/strong&gt; A new PCI standard with security and test requirements for entities that operate systems using cryptographic keys to protect account data. It is relevant to processors, HSM operators and key custodians.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Recommended action:&lt;/strong&gt; Map your current key management procedures (PCI DSS Requirements 3.6 and 3.7) against KMO v1.0 and list the gaps before your next assessment cycle.&lt;/p&gt;&lt;p&gt;PCI Security Standards Council | PCI KMO Standard v1.0 | &lt;a href=&quot;https://blog.pcisecuritystandards.org/just-published-pci-key-management-operations-kmo-standard-v1.0&quot;&gt;Original advisory&lt;/a&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
