Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.

Germany's cabinet has approved a comprehensive legislative overhaul that would grant its intelligence agencies new powers to conduct cyber operations, including hacking foreign systems and sabotaging adversaries' supply chains. The 732-page bill, which still requires parliamentary approval, represents the most significant reform of the country's spy laws since the post-war era.
Chancellery chief Nina Warken indicated that the proposed powers would enable agencies to replace faulty components in deliveries, use cyber tactics to disrupt drone manufacturing facilities or chemical weapons laboratories, and disable servers operated by hostile state-sponsored hackers and disinformation actors. Interior Minister Alexander Dobrindt stated that the government is "expanding the technical capabilities of the intelligence services and granting them active, operational powers" to "take active measures against our attackers and adversaries."
The draft legislation revises the legal frameworks governing both the Bundesnachrichtendienst (BND), Germany's foreign intelligence service, and the Bundesamt für Verfassungsschutz (BfV), its domestic agency for the protection of the constitutional order. It also mandates that telecommunications carriers and digital service providers assist these agencies, with non-compliance potentially resulting in fines or service suspensions.
While the new powers are extensive, they explicitly prohibit measures intended to endanger a person's life or physical safety, distinguishing them from the paramilitary capabilities of some allied intelligence agencies. The BND's disruption operations would require a formal declaration from its president, stating that a named foreign power is consistently and systematically threatening German interests. This declaration would be valid for 12 months and subject to review every six months. Operations must target the responsible state rather than individuals and be conducted outside Germany if equally effective.
The BfV, traditionally an intelligence-gathering agency, would gain a new set of operational powers. These include the ability to block or reroute data traffic, alter transmissions in transit, corrupt data intended for use in plots, and disable equipment about to be used in an attack. Notably, the BfV could also feed false information to individuals involved in domestic plots, a power for which there is no direct statutory equivalent in British, French, or American law.
The bill also introduces new regulations for the use of artificial intelligence in intelligence analysis. It authorizes self-learning systems for data analysis but prohibits discriminatory algorithms and requires human oversight, with machine-generated outputs subject to spot-checks by an officer qualified to serve as a judge. Certain conclusions generated by these systems, such as movement profiles, behavioral assessments, and personalized predictions, would be treated as intrusions themselves, requiring additional justification for retrieval based on their revealing nature. A new oversight body would be tasked with reviewing every two years whether new categories of machine-generated output have become similarly revealing, triggering automatic application of stricter rules.
The reforms are partly a response to a Federal Constitutional Court ruling that invalidated a state intelligence law, emphasizing that surveillance powers must be proportional to their intrusiveness. While civil liberties groups have indicated plans to challenge the draft legislation, its passage through parliament is anticipated given the governing coalition's majority and its aim to enact the law next year.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early