The European Commission proposed a new Cybersecurity Package that would tighten security requirements for telecommunications networks by mandating the removal of high-risk suppliers from sensitive ICT and mobile network infrastructure and by strengthening EU-wide defenses against state-backed and cybercrime threats targeting critical infrastructure. The proposal would move beyond the uneven, voluntary adoption of the EU’s 2020 5G Security Toolbox by giving the Commission greater authority to coordinate EU-wide risk assessments, support restrictions or bans on certain equipment, and drive joint risk assessments across the EU’s 18 critical sectors, including consideration of suppliers’ countries of origin and national security implications.
Separately, ETSI published ETSI EN 304 223, a new European standard defining baseline cybersecurity requirements for AI models and systems (including deep neural networks and generative AI) intended for real-world deployment. The standard frames AI as a distinct security domain and addresses AI-specific risks such as data poisoning, model obfuscation, and indirect prompt injection, organizing requirements across five lifecycle phases: secure design, development, deployment, maintenance, and end-of-life; it is positioned as a shared baseline for vendors, integrators, and operators across the AI supply chain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The European Commission proposed new EU cybersecurity legislation to strengthen telecom and critical infrastructure security, including measures to remove or restrict high-risk suppliers. The package would expand EU-wide risk assessments, revise the Cybersecurity Act, and broaden ENISA's role in threat alerting, incident reporting, and ransomware response support.
ETSI released European Standard EN 304 223, establishing baseline cybersecurity requirements for AI models and AI systems used in real-world operations. The standard defines 13 principles across secure design, development, deployment, maintenance, and end-of-life, and addresses AI-specific risks such as data poisoning and indirect prompt injection.
The EU introduced the voluntary 5G Security Toolbox, encouraging member states to reduce reliance on high-risk vendors in telecommunications networks. Later reporting said implementation across member states was uneven.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.