
Germany's Proposed Reform to Share Zero-Day Vulnerabilities Between BSI and BND
CybersecurityIntelligenceLegislationVulnerabilities
A proposed reform to Germany’s intelligence service laws (Nachrichtendienstrecht-Reform) would require the Federal Office for Information Security (BSI) to forward zero-day vulnerabilities to the Federal Intelligence Service (BND). The draft legislation aims to formalize the sharing of undisclosed security flaws between these agencies. No specific technical details, dates, or CVE IDs related to the vulnerabilities were mentioned in the report. The change is framed as a potential shift in the BSI’s role, traditionally focused on cybersecurity defense, toward intelligence operations. The article highlights concerns about this obligation but does not detail concrete impacts or timelines.