LIVE · cybersecurity feed
Live wire
cloud

Germany moves to give spy agencies hacking and sabotage powers

Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.

zeroday.news ·

Germany's cabinet has approved a comprehensive legislative overhaul that would grant its intelligence agencies new powers to conduct cyber operations, including hacking foreign systems and sabotaging adversaries' supply chains. The 732-page bill, which still requires parliamentary approval, represents the most significant reform of the country's spy laws since the post-war era.

Chancellery chief Nina Warken indicated that the proposed powers would enable agencies to replace faulty components in deliveries, use cyber tactics to disrupt drone manufacturing facilities or chemical weapons laboratories, and disable servers operated by hostile state-sponsored hackers and disinformation actors. Interior Minister Alexander Dobrindt stated that the government is "expanding the technical capabilities of the intelligence services and granting them active, operational powers" to "take active measures against our attackers and adversaries."

The draft legislation revises the legal frameworks governing both the Bundesnachrichtendienst (BND), Germany's foreign intelligence service, and the Bundesamt für Verfassungsschutz (BfV), its domestic agency for the protection of the constitutional order. It also mandates that telecommunications carriers and digital service providers assist these agencies, with non-compliance potentially resulting in fines or service suspensions.

While the new powers are extensive, they explicitly prohibit measures intended to endanger a person's life or physical safety, distinguishing them from the paramilitary capabilities of some allied intelligence agencies. The BND's disruption operations would require a formal declaration from its president, stating that a named foreign power is consistently and systematically threatening German interests. This declaration would be valid for 12 months and subject to review every six months. Operations must target the responsible state rather than individuals and be conducted outside Germany if equally effective.

The BfV, traditionally an intelligence-gathering agency, would gain a new set of operational powers. These include the ability to block or reroute data traffic, alter transmissions in transit, corrupt data intended for use in plots, and disable equipment about to be used in an attack. Notably, the BfV could also feed false information to individuals involved in domestic plots, a power for which there is no direct statutory equivalent in British, French, or American law.

The bill also introduces new regulations for the use of artificial intelligence in intelligence analysis. It authorizes self-learning systems for data analysis but prohibits discriminatory algorithms and requires human oversight, with machine-generated outputs subject to spot-checks by an officer qualified to serve as a judge. Certain conclusions generated by these systems, such as movement profiles, behavioral assessments, and personalized predictions, would be treated as intrusions themselves, requiring additional justification for retrieval based on their revealing nature. A new oversight body would be tasked with reviewing every two years whether new categories of machine-generated output have become similarly revealing, triggering automatic application of stricter rules.

The reforms are partly a response to a Federal Constitutional Court ruling that invalidated a state intelligence law, emphasizing that surveillance powers must be proportional to their intrusiveness. While civil liberties groups have indicated plans to challenge the draft legislation, its passage through parliament is anticipated given the governing coalition's majority and its aim to enact the law next year.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.