LIVE · cybersecurity feed
Live wire
security

Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill

A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.

zeroday.news · 10d ago

The U.S. House of Representatives has passed an annual defense policy bill that includes a provision to extend a key cybersecurity information-sharing law for another decade. The 2027 National Defense Authorization Act (NDAA), approved by a vote of 216-212, contains language that would reauthorize the 2015 Cybersecurity and Information Sharing Act (CISA 2015) until 2035.

CISA 2015 provides legal protections for the private sector and federal government to exchange data concerning criminal and nation-state hacking threats. The statute had briefly lapsed last year, which federal officials indicated left them without a full understanding of digital threats to critical U.S. infrastructure. It was subsequently extended temporarily through September 30 of the current year.

The House's reauthorization effort is formally known as the Widespread Information Management for the Welfare of Infrastructure and Government Act (WIMWIG Act). This act was previously approved by the House Homeland Security Committee but has not yet received a floor vote and faces opposition in the Senate.

A significant hurdle to reauthorization comes from Senator Rand Paul (R-KY), who chairs the Senate Homeland Security Committee. Senator Paul has publicly stated his intention to block any extension of CISA 2015 unless it includes language prohibiting the Cybersecurity and Infrastructure Security Agency (CISA, the agency created in 2018) from engaging in work to counter online disinformation. It is noted that CISA 2015 and CISA the agency are not directly linked by law.

The Senate's draft of the NDAA does not currently include a matching extension for CISA 2015, although it is anticipated that the issue may arise during the amendment process. Furthermore, the Senate's consideration of the NDAA has encountered resistance from Democrats, who have been engaged in a prolonged dispute regarding presidential authority on Iran.

Should the CISA 2015 extension ultimately be included in both chambers' versions, it would still require successful negotiation and agreement between the House and Senate to be incorporated into a final compromise bill. In a separate legislative effort in May, a bipartisan group of House members also introduced a proposal on artificial intelligence that contained a similar provision to reauthorize CISA 2015 through 2035, though this package has not gained significant momentum.

Beyond the CISA 2015 extension, the House's NDAA also differs from the Senate's version on Pentagon cyber roles. The House bill calls for a "review and realignment" of all Pentagon cyber positions. In contrast, the Senate's draft proposes merging the Pentagon's two primary cyber leadership roles into a single post, creating a new "undersecretary of Defense for cyber, information, and networks." This new role would serve as both the department's chief information officer and the principal cyber adviser to the secretary of Defense, an initiative intended to address existing tensions between the CIO and the assistant secretary of defense for cyber policy regarding responsibility for digital operations, particularly offensive measures. This Senate provision, if enacted, would take effect in two years.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.