← Back

Wire · regulatory

Comment: The BSI must not become the BND's zero-day supplier

Published

11 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

Germany

Source

Read at heise.de

Verified

Fusion42 · 11 July 2026 · Fusion42 review

Germany's draft intelligence service reform would require the BSI (Federal Office for Information Security) to disclose zero-day vulnerabilities to the BND intelligence agency before patches exist, fundamentally contradicting the BSI's core mandate to secure national infrastructure and undermining trust with security researchers and critical infrastructure operators.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you sell vulnerability disclosure, threat intelligence, or critical infrastructure monitoring to German operators or public authorities, this law just made them your unreliable partner—the BSI will soon be required to hand zero-days to intelligence services rather than patch them, and operators will stop reporting problems they can't trust will be fixed.

Coverage

1 source · 11 Jul 2026

Related on Wire

Topics

Cybersecurityzero-day-disclosureintelligence-reformcybersecurity-mandateregulatory-conflictcritical-infrastructuretrust-erosion