CISA

CISA contemplates whether to hire security software buying help

The Cybersecurity and Infrastructure Security Agency issued a sources sought notice that describes its desire to bring in a company that can help manage enterprise license and materials purchases.

CISA just changed the rules. Is your vulnerability program ready?

COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.

CISA cautions against rigid rules for future of cyber vulnerability program

A top agency official said formal backing from Congress could strengthen the global vulnerability-tracking system but warned against measures that may limit its ability to adapt to ever-changing hacking threats.

Exclusive

CISA still finds water system controls exposed online amid multistate hacks

The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.

Cyber industry coalition urges federal action after suspected Iran-linked water hacks

The group called on CISA to impose baseline security standards across federal operational technology systems and pressed Congress to revive several stalled cyber initiatives.

CISA urges water utilities to take exposed systems down after Minnesota hacks

A memo distributed to water industry members and obtained by Nextgov/FCW makes mention of Iran but does not directly present evidence attributing the latest Minnesota incident to the country.

Russian hackers can steal government emails without victims clicking a link, cyber agencies warn

The Russia-linked Laundry Bear group has compromised more than 10 Western organizations through malicious emails that can trigger an exploit when they are viewed or previewed.

CISA expects to finalize key cyber reporting rule by September

Last month, CISA held additional stakeholder town halls on the forthcoming CIRCIA final rule after a now-resolved DHS funding lapse this spring delayed the meetings.

Exclusive

Top House cyber lawmaker plans to introduce DHS overhaul bill by next year

In an interview, Rep. Delia Ramirez, D-Ill., also said she plans to ask officials about how export control measures would affect government agencies’ access to advanced AI models.

Planned NDAA amendment would codify CISA’s role in cyber vulnerability program

The measure, expected as a proposed add-on to the government’s 2027 defense package, targets a bedrock cybersecurity vulnerability-tracking system after a contracting fiasco last year.

Exclusive

CISA now has full Mythos Preview access, people familiar say

The cyberdefense agency received access around a week ago, but the White House has not yet set clear parameters for how the agency should use the model.

3 priorities for federal CISOs in the agentic era

COMMENTARY | As agentic AI use spreads across government, agencies need to develop security programs, craft playbooks for mitigating incidents and simulate adversarial attacks.

Warner presses CISA on whether staff cuts weakened regional cyber support

The Senate Intelligence Committee’s top Democrat is asking the cyber agency for workforce charts, vacancy details and service data as state and local support comes under strain.

CISA sees leadership shakeup after infrastructure security chief moves to ONCD

The personnel moves come as CISA prepares to hire hundreds of new employees following a year of layoffs, buyouts and internal restructuring.

Exclusive

White House discussions are weighing giving CISA Mythos access

Officials have considered having the Cybersecurity and Infrastructure Security Agency leverage the advanced AI model that was designed to detect previously undiscovered cyber vulnerabilities to scan federal agencies’ networks.

CISA directive revamps how agencies prioritize vulnerable systems

The move is part of CISA’s response “to the current threat landscape where AI software services can assist threat actors to find and exploit vulnerabilities,” the agency says.

Exclusive

Warner proposes overhaul of critical infrastructure cyber plans as AI threats rise

The measure would require CISA to refresh long-outdated sector cybersecurity plans as lawmakers warn that advanced AI tools could accelerate the discovery and exploitation of software flaws.