LIVE · cybersecurity feed
Live wire
security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

zeroday.news ·

Members of Congress have formally requested that the Government Accountability Office (GAO) investigate the impact of significant staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA) on its operational capabilities and mission fulfillment. The request, spearheaded by Representative Bennie Thompson (D-MS), ranking member of the House Committee on Homeland Security, and several other Democratic representatives, highlights concerns that CISA's ability to protect critical infrastructure and respond to evolving cyber and physical threats has been compromised.

The congressional letter states that CISA has lost nearly one-third of its workforce since the beginning of the Trump administration, with approximately 1,000 employees having either been fired or voluntarily departed. This reduction raises serious questions about the agency's capacity at a time when adversaries are reportedly escalating attacks against critical infrastructure.

Despite acting director Nick Andersen's earlier announcement of plans to hire 300 new employees to address staffing gaps, the lawmakers expressed confusion regarding the administration's strategy. They noted that the fiscal year 2027 budget proposal includes the elimination of nearly 900 additional positions and a budget cut of over $700 million for CISA.

The letter also points out that little information is available on how the staffing cuts have affected CISA's operations and how the lost institutional knowledge has been replaced. Several key CISA leaders have departed in the past year, including David Stern, who was instrumental in a significant ransomware notification initiative.

Industry leaders and state and local officials have reportedly communicated to at least one Senator that they have experienced "reduced responsiveness and support" from CISA, indicating that "staffing turbulence at CISA has disrupted its service delivery and operations." These concerns are particularly salient ahead of the November election season, given the potential impact on municipal cybersecurity nationwide.

The congressional request references recent advisories from CISA, the FBI, and other federal agencies that underscore the increasing cyber threats targeting critical infrastructure organizations. These advisories have highlighted an "active threat" utilizing AI-generated exploit scripts, described as an "evolution" in attacker capabilities.

A GAO spokesperson, Sarah Kaczmarek, confirmed receipt of the congressional request, stating that the office is currently following its process to determine whether and when to undertake the requested work.

CISA has not had a confirmed director since Jen Easterly's departure at the end of the Biden administration. Nick Andersen recently assumed the acting director role after Madhu Gottumukkala was removed from the position in February following a series of undisclosed scandals. Shyam Sankar, a senior official at Palantir, has been identified as a leading contender for the permanent director role.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

security

Your Shredded Visa Card May Still Work at the Checkout

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

phishing

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

ai

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.

ai

AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the mode