A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.

The U.S. House of Representatives has passed an annual defense policy bill that includes a provision to extend a key cybersecurity information-sharing law for another decade. The 2027 National Defense Authorization Act (NDAA), approved by a vote of 216-212, contains language that would reauthorize the 2015 Cybersecurity and Information Sharing Act (CISA 2015) until 2035.
CISA 2015 provides legal protections for the private sector and federal government to exchange data concerning criminal and nation-state hacking threats. The statute had briefly lapsed last year, which federal officials indicated left them without a full understanding of digital threats to critical U.S. infrastructure. It was subsequently extended temporarily through September 30 of the current year.
The House's reauthorization effort is formally known as the Widespread Information Management for the Welfare of Infrastructure and Government Act (WIMWIG Act). This act was previously approved by the House Homeland Security Committee but has not yet received a floor vote and faces opposition in the Senate.
A significant hurdle to reauthorization comes from Senator Rand Paul (R-KY), who chairs the Senate Homeland Security Committee. Senator Paul has publicly stated his intention to block any extension of CISA 2015 unless it includes language prohibiting the Cybersecurity and Infrastructure Security Agency (CISA, the agency created in 2018) from engaging in work to counter online disinformation. It is noted that CISA 2015 and CISA the agency are not directly linked by law.
The Senate's draft of the NDAA does not currently include a matching extension for CISA 2015, although it is anticipated that the issue may arise during the amendment process. Furthermore, the Senate's consideration of the NDAA has encountered resistance from Democrats, who have been engaged in a prolonged dispute regarding presidential authority on Iran.
Should the CISA 2015 extension ultimately be included in both chambers' versions, it would still require successful negotiation and agreement between the House and Senate to be incorporated into a final compromise bill. In a separate legislative effort in May, a bipartisan group of House members also introduced a proposal on artificial intelligence that contained a similar provision to reauthorize CISA 2015 through 2035, though this package has not gained significant momentum.
Beyond the CISA 2015 extension, the House's NDAA also differs from the Senate's version on Pentagon cyber roles. The House bill calls for a "review and realignment" of all Pentagon cyber positions. In contrast, the Senate's draft proposes merging the Pentagon's two primary cyber leadership roles into a single post, creating a new "undersecretary of Defense for cyber, information, and networks." This new role would serve as both the department's chief information officer and the principal cyber adviser to the secretary of Defense, an initiative intended to address existing tensions between the CIO and the assistant secretary of defense for cyber policy regarding responsibility for digital operations, particularly offensive measures. This Senate provision, if enacted, would take effect in two years.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed