The Continuing Appropriations and Extensions Act, 2027 has been signed into law, funding most federal agencies at fiscal 2026 levels through December 11, 2026, pending enactment of full-year appropriations. The stopgap measure also temporarily renews the Cybersecurity Information Sharing Act of 2015, the Federal Cybersecurity Enhancement Act of 2015, and the Technology Modernization Fund.
Renewal of the 2015 information-sharing law preserves liability protections for private entities that voluntarily provide cyber-threat intelligence to the government and maintains authorities supporting the National Cybersecurity Protection System. A permanent reauthorization remains unresolved; industry and government stakeholders have warned that an expiration could suppress private-sector reporting and disrupt real-time threat-intelligence sharing.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. House passed the continuing-resolution measure by a 370-48 vote. It funded most federal programs at FY 2026 levels and temporarily extended CISA 2015 and other federal cybersecurity authorities.
The U.S. Senate passed the Continuing Appropriations and Extensions Act, 2027 by a 90-6 vote. The measure included temporary extensions for the Cybersecurity Information Sharing Act of 2015, the Technology Modernization Fund, and the Federal Cybersecurity Enhancement Act of 2015.
The Continuing Appropriations and Extensions Act, 2027 was signed into law, funding federal agencies through December 11, 2026. The law extended the Cybersecurity Information Sharing Act of 2015, Technology Modernization Fund, and Federal Cybersecurity Enhancement Act of 2015 through that period.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.