Germany’s cabinet approved a draft intelligence reform bill that would significantly expand the powers of the foreign intelligence service BND and the domestic intelligence agency BfV, giving them authority to move beyond passive collection into active cyber operations. The proposal would allow longer retention and analysis of communications data, online searches of devices, covert home entry by the BfV, and limited manipulation of data on compromised systems in imminent-danger cases. It would also authorize action against clearly identified attacker-controlled IT systems such as command-and-control infrastructure, while shifting approval for the most intrusive measures to the Unabhängiger Kontrollrat.
The overhaul would additionally permit hacking foreign systems, disrupting hostile supply chains, disabling infrastructure, and conducting deception operations, while requiring telecommunications carriers and digital service providers to assist intelligence activities. The government says the changes are needed to counter hybrid threats, terrorism, hostile state activity, and other modern IT-based dangers; critics argue the bill marks a major expansion of surveillance and offensive state powers that could face constitutional challenges. A provision that would have required the BSI to share security vulnerabilities with intelligence agencies was removed before the draft was submitted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Germany’s cabinet approved draft legislation described as a sweeping overhaul of spy laws, granting the BND and BfV new active cyber and disruption powers. The bill would allow actions such as hacking foreign systems, sabotaging hostile supply chains, disabling hostile infrastructure, and conducting deception operations under statutory limits and oversight provisions.
Before the reform draft was finally submitted, a provision that would have required Germany’s BSI to pass security vulnerabilities to intelligence services was removed. The clause was politically sensitive because it could have indirectly funneled reported flaws to the BND.
Interior Minister Alexander Dobrindt and Chancellery Minister Nina Warken presented proposed amendments to the BND Act and the Verfassungsschutz Act that would significantly expand the powers of Germany’s intelligence services. The proposal includes broader retention and analysis of communications data, online searches of devices, and more intrusive cyber measures against attacker-controlled systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetherecord.media
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.