Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

Members of Congress have formally requested that the Government Accountability Office (GAO) investigate the impact of significant staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA) on its operational capabilities and mission fulfillment. The request, spearheaded by Representative Bennie Thompson (D-MS), ranking member of the House Committee on Homeland Security, and several other Democratic representatives, highlights concerns that CISA's ability to protect critical infrastructure and respond to evolving cyber and physical threats has been compromised.
The congressional letter states that CISA has lost nearly one-third of its workforce since the beginning of the Trump administration, with approximately 1,000 employees having either been fired or voluntarily departed. This reduction raises serious questions about the agency's capacity at a time when adversaries are reportedly escalating attacks against critical infrastructure.
Despite acting director Nick Andersen's earlier announcement of plans to hire 300 new employees to address staffing gaps, the lawmakers expressed confusion regarding the administration's strategy. They noted that the fiscal year 2027 budget proposal includes the elimination of nearly 900 additional positions and a budget cut of over $700 million for CISA.
The letter also points out that little information is available on how the staffing cuts have affected CISA's operations and how the lost institutional knowledge has been replaced. Several key CISA leaders have departed in the past year, including David Stern, who was instrumental in a significant ransomware notification initiative.
Industry leaders and state and local officials have reportedly communicated to at least one Senator that they have experienced "reduced responsiveness and support" from CISA, indicating that "staffing turbulence at CISA has disrupted its service delivery and operations." These concerns are particularly salient ahead of the November election season, given the potential impact on municipal cybersecurity nationwide.
The congressional request references recent advisories from CISA, the FBI, and other federal agencies that underscore the increasing cyber threats targeting critical infrastructure organizations. These advisories have highlighted an "active threat" utilizing AI-generated exploit scripts, described as an "evolution" in attacker capabilities.
A GAO spokesperson, Sarah Kaczmarek, confirmed receipt of the congressional request, stating that the office is currently following its process to determine whether and when to undertake the requested work.
CISA has not had a confirmed director since Jen Easterly's departure at the end of the Biden administration. Nick Andersen recently assumed the acting director role after Madhu Gottumukkala was removed from the position in February following a series of undisclosed scandals. Shyam Sankar, a senior official at Palantir, has been identified as a leading contender for the permanent director role.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.