Senate Stalemate Delays Cybersecurity Information-Sharing Law Reauthorization
Article Content
- •CISA 2015 expired in fiscal 2025, with no permanent reauthorization in sight.
- •Senator Rand Paul's amendment proposal is a key point of contention in negotiations.
- •Bipartisan bills to extend CISA 2015 through fiscal 2035 are stalled due to Senate leadership disputes.
The Cybersecurity Information Sharing Act of 2015 (CISA 2015) has not been permanently reauthorized since its expiration at the end of fiscal 2025. Bipartisan support exists for a long-term extension, but Senate Homeland Security Chairman Rand Paul is blocking progress. Paul has proposed an amendment to protect free speech that he claims is necessary for his support. Ranking member Sen. Gary Peters has accused Paul of being the main obstacle to reauthorization. Peters has introduced two bipartisan bills to extend CISA 2015 through fiscal 2035, one of which includes retroactive liability protections. The program has only been temporarily renewed through continuing resolutions, making it vulnerable to lapses. The situation remains unresolved as both parties seek a compromise that addresses concerns related to artificial intelligence's impact on cybersecurity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What is the current status of CISA 2015?
What are the main points of contention in the Senate?
What are the implications of the stalled negotiations?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…