Congress is facing challenges in passing a long-term renewal of the Cybersecurity Information Sharing Act of 2015, a foundational law that provides legal protections for companies sharing cyber threat data with the federal government and each other. House Homeland Security Chairman Andrew Garbarino has emphasized the importance of renewing the act, which recently received a short-term extension after lapsing in October, but faces opposition from various factions in both the House and Senate. Disagreements center on whether to pass a 'clean' 10-year reauthorization or to introduce changes addressing concerns about the Cybersecurity and Infrastructure Security Agency (CISA) and free speech protections.
The ongoing debate has led to uncertainty about the future of the law, with the possibility of another short-term extension being considered as negotiations continue. Garbarino has also called for the Senate to renew a cyber grant program for state and local governments and highlighted the need for a comprehensive national cyber strategy. The legislative impasse reflects broader divisions in Congress over the direction of federal cybersecurity policy and the role of CISA in protecting critical infrastructure and managing information sharing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Lawmakers highlighted upcoming hearings on AI and cybersecurity after reports that Chinese hackers used Anthropic's Claude Code tool in global cyberattacks. Garbarino described the case as the first reported fully automated digital assault and said AI would be central to future cyber defense discussions.
House Homeland Security Committee Chairman Andrew Garbarino said political divisions were complicating a long-term renewal of the 2015 Cybersecurity Information Sharing Act. He indicated Congress would likely need another short-term extension while competing proposals remained unresolved.
The House Homeland Security Committee continued efforts to obtain more information about the federal response to the Chinese state-backed hacking groups Salt Typhoon and Volt Typhoon. The committee also worked with the House China Select Committee on possible legislative responses to Chinese cyber threats.
Congress put in place a short-term extension of the Cybersecurity Information Sharing Act rather than completing a long-term reauthorization. The extension was set to run through January 30 alongside government funding.
After the Salt Typhoon breach of telecommunications networks, the Federal Communications Commission enacted cybersecurity rules in response. Those rules later became a point of criticism when some were rolled back.
The Cybersecurity Information Sharing Act of 2015 was enacted, creating legal protections for companies that share cyber threat information with the government. Its scheduled expiration later became the focus of reauthorization efforts in Congress.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.