The Point: A planned intelligence services law would require the BSI to report previously unknown security vulnerabilities to the BND — a practice that cybersecurity experts view critically.
The draft amendment to the Intelligence Services Act provides that the BSI must mandatorily pass zero-day vulnerabilities to the BND. Experts warn of fundamental security risks posed by this regulation.
The draft law reforming intelligence services legislation requires that the Federal Office for Information Security (BSI) systematically forward zero-day vulnerabilities to the Federal Intelligence Service (BND). Zero-days are security flaws that software manufacturers do not yet know about and therefore cannot patch — they are considered particularly valuable for attack operations and critical to the security of systems worldwide.
Criticism of this regulation targets the fundamental tension between intelligence services mandate and protective mandate. As the state’s cybersecurity agency, the BSI has the task of protecting German critical infrastructure and government systems. Systematic forwarding of zero-days to the BND, even if the BND intends to use the vulnerabilities itself, creates conflicts of use and control: vulnerabilities known to the BND cannot be promptly patched, and the long-term security of the systems that the BSI is supposed to protect could suffer as a result.
There is also the risk from a security policy perspective: if zero-days in the possession of intelligence services are not patched or are held back too long, there is a danger that adversaries or unauthorized actors could discover and exploit the same vulnerabilities — with incalculable consequences for the security of critical systems at home and abroad. In this scenario, the BSI would be degraded from a protective institution to a mere supplier of offensive capability.
Source: www.heise.de · Published July 11, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.