German intelligence services gain statutory authority to actively penetrate foreign attackers’ IT systems, copy and delete data, and deliberately spread disinformation under strict conditions.
The NIS2 Directive requires approximately 30,000 German businesses to implement uniform IT security standards and establishes binding notification requirements for security incidents.
From July 2025, companies must train all employees in cybersecurity and AI governance under NIS2 and the EU AI Act, with documented programs and penalty risks for non-compliance.
Attackers used a stolen OIDC token to distribute counterfeit TanStack packages on npm, enabling the exfiltration of cloud credentials and authentication tokens.
71 percent of households see cyberattack risks in power grids; digital transformation is supported by the majority but must be coupled with high security and data protection standards.