The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

A recent report from the Government Accountability Office (GAO) has found that a significant majority of federal cybersecurity reporting requirements are duplicative. The study, conducted at the request of House Homeland Security Chairman Andrew Garbarino and Senate Homeland Security and Governmental Affairs Committee ranking member Gary Peters, examined 117 rules across 37 federal agencies.
The GAO determined that 80 of these 117 rules, or approximately 70%, contained reporting requirements that either applied the same kind of reporting to a specific sector or were identical to requirements found in at least one other regulation. This widespread overlap creates a complex and often redundant compliance landscape for the private sector.
The report specifically scrutinized regulations that mandate private companies to submit cybersecurity incident reports, plans, and reviews to federal agencies. The GAO highlighted that efforts to harmonize these conflicting rules have largely been delayed or have made limited progress.
For instance, the Cybersecurity and Infrastructure Security Agency (CISA) is currently developing a regulation under the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This forthcoming rule will require critical infrastructure owners and operators to report major cyberattacks and ransomware payments. However, the GAO noted that elements of the financial services sector, for example, could already be subject to up to 15 existing cybersecurity reporting rules, depending on their oversight agency, in addition to the impending CIRCIA requirements.
The Biden administration had initiated a push to regulate cybersecurity more aggressively and to harmonize conflicting regulations. A 2024 national security memorandum specifically tasked the Office of the National Cyber Director (ONCD) and the Department of Homeland Security (DHS) with addressing these overlaps. While both agencies made some progress, these harmonization efforts were subsequently paused after the Trump administration issued an executive order in March of the previous year to conduct a study of the 2024 memo. This study was still ongoing as of last month, according to the GAO.
The GAO's findings underscore a persistent challenge in federal cybersecurity policy, where numerous agencies have independently developed reporting requirements, leading to a fragmented and often burdensome system for regulated entities. The report focused exclusively on federal regulations, though other analyses have also considered the impact of state-level and other reporting obligations.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a