The Cybersecurity and Infrastructure Security Agency (CISA), which is part of the Department of Homeland Security, is responsible for cybersecurity and infrastructure security throughout the federal government, to improve cybersecurity protection against private and nation-state hackers.

CISA has been without a director since the beginning of President Trump’s second term, when the then-director resigned. In addition, the Trump administration cut funding to the agency and, through the budget cuts, furloughs, and layoffs, the agency lost about one-third of its workforce. On top of that, in March 2025, Defense Secretary Pete Hegseth ordered U.S. Cyber Command to “halt cyber-offense operations against Russia” and “ordered the unit to stand down panning against Russian cybersecurity threats.”

Russia has always been one of our top cyber adversaries and there is no indication that offensive planning has taken place in the past year.

With the layoffs, budget cuts, furloughs, and resignations, CISA has been embattled in fulfilling its mission. The strain became abundantly clear recently when GitGuardian security researcher Guillaume Valadon found “reams of exposed plaintext credentials listed in spreadsheets, which had been made publicly accessible in a GitHub repository by an employee working for a CISA contractor.”

The researcher contacted security reporter Brian Krebs on May 15, 2026, who reported that the CISA contractor “maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems” which “included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.”

The repository was named “Private-CISA” and included “a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.”

The GitHub account has been taken offline. It was created in September 2018, and the Private-CISA repository was created in November 2025.

It is unknown whether anyone, including a foreign adversary such as Russia, found, accessed or used the credentials. CISA has confirmed that it is aware of the reported exposure and is continuing to investigate the situation. The question is what other lapses will occur as a result of the agency’s decimation.

The Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Tuesday, March 11, 2025, that the Multi-State Information Sharing and Analysis Center (MS-ISAC) will lose its federal funding and cooperative agreement with the Center for Internet Security. MS-ISAC’s mission “is to improve the overall cybersecurity posture of U.S. State, Local, Tribal, and Territorial (SLTT) government organizations through coordination, collaboration, cooperation, and increased communication.”

According to its website, MS-ISAC is a cybersecurity partner for 17,000 State, Local, Tribal, and Territorial (SLTT) government organizations, and  offers its “members incident response and remediation support through our team of security experts” and develops “tactical, strategic, and operational intelligence, and advisories that offer actionable information for improving cyber maturity.” The services also include a Security Operations Center, webinars addressing recent threats, evaluations of cybersecurity maturity, advisories and notifications, and weekly top malicious domain reports.

All of these services assist governmental organizations that do not have adequate resources to respond to cybersecurity threats. Information sharing has been essential to prevent government entities from becoming victims. State and local governments have relied on this information sharing for resilience. Dismantling MS-ISAC will make it harder for governmental entities to obtain timely information about cybersecurity threats for preparedness. It is an organized place for governmental entities to share information about cyber threats and attacks and to learn from others’ experiences.

According to CISA, the dismantling of MS-ISAC will save $10 million. State representatives rely on the information shared by MS-ISAC. It may save the federal government minimal dollars, but when state and local governments are adversely affected and become victims of cyberattacks, this savings will be dwarfed by the amount spent on future attacks without MS-ISAC’s assistance. Responding to state and local government cyberattacks still expends taxpayer dollars. This shift is an unhelpful one that will leave state and local governments in the dark and at increased risk. This is a short-sighted strategy by the administration.

The bi-partisan infrastructure bill presently being debated in the U.S. Senate includes up to $1 billion in funding to state and local governments to enhance cybersecurity measures over four years.

The proposed funding would create a grant program to benefit state and local cybersecurity programs, which would be administered by the Federal Emergency Management Agency with in-put from the Cybersecurity and Infrastructure Security Agency. In order to receive the grant funding, programs will have to submit a plan to CISA on how the grant funding will be used to bolster the cybersecurity program.

The bill would also earmark up to $21 million in funding for the newly created Office of the National Cyber Director in the Executive Office of the President.

I apologize that this post is not light reading. It’s critically important to know what the threats are so you can avoid becoming a victim.

Although disconcerting, it is crucial to know what has happened in the first half of this year. TechCrunch recently issued a report outlining the worst breaches of 2026—so far:

  • DOGE’s massive swipe of Social Security data (I’ve discussed this  in numerous posts)
  • Hackers increased targeting of water systems and energy grids (discussed here)
  • Iranian government hackers attacking Stryker with a destructive device hack (ditto)
  • ShinyHunters’ disruptive hacking campaign against Instructure, among other targets (ShinyHunters has been a frequent subject of our posts)
  • The supply chain under attack, targeting open-source projects and big tech companies
  • FBI’s surveillance system breach, sparking a “major cyber incident“
  • Hasbro’s hack leading to weeks of downtime
  • Exposure of millions of passports and driver licenses

What can we learn from these trends?

According to TechCrunch, “the attacks are getting bolder, more destructive, and harder to contain.” The trends confirm that as technology advances, so must defenses equally. Cybersecurity measures must be sophisticated enough to block attackers so they will move on to the next victim. A mature cybersecurity posture, both personally and professionally, must be a priority to prevent becoming victimized. In a world of geopolitical discontent, cyber attackers serve as warriors for nation states, and at the same time, our own government is failing to protect our data and our warriors’ data. Unfortunately, the Cybersecurity and Infrastructure Security Agency’s funding has been decimated, so we are left to our own devices (pardon the pun).

We need to take greater responsibility for protecting our own information while demanding stronger safeguards from our government, especially for the sensitive data of current and veteran military personnel. Additionally, private companies must also do more to prevent exposure. Robust cybersecurity programs across individuals, government, and the private sector are essential. This is no longer a future concern; it is reality. Without collective action, the second half of 2026 will bring more of the same.

Threat actors had another banner year in 2025. As we head into 2026, looking back on the five top security threats of 2025 may inform our strategy and budgeting for 2026 to prepare for the continued onslaught of attacks.

According to Dark Reading, the top five security threats from 2025 include:

  1. Salt Typhoon

Salt Typhoon, also known as Operator Panda, is a Chinese state-sponsored threat actor best known for targeting telecom giants and the systems used by police for court-authorized wiretapping. The group uses sophisticated techniques to conduct espionage against targets and to pre-position itself for longer-term attacks.

  • CISA Layoffs and Budget Cuts

Early in the year, the Trump administration cut all advisory committee members within the Cyber Safety Review Board (CSRB), a group run by public and private sector experts to research and make judgments about cybersecurity issues affecting all industries. At the very time the CSRB was dismantled, it was working on a report about Salt Typhoon. (Recall that Salt Typhoon is listed as the #1 threat from 2025).

In addition to the dismantling of CSRB, the Cybersecurity Infrastructure and Security Agency (CISA) faced layoffs and budget cuts throughout the year, in part due to the Department of Government Efficiency’s slashing of government spending.

CISA has provided a wide range of services for organizations, including vulnerability guidance, physical and cyber security assessments, election security, and incident response support, including for state and municipal governments and smaller organizations. The cuts have hampered entities’ efforts to protect themselves despite threat actors continuing to target them, which will continue into 2026.

  •  React2Shell / Log4Shell

React2Shell (CVE-2025-55182), is a vulnerability that was disclosed in early December that affects the React Server Components (RSC) open-source protocol. “Caused by unsafe deserialization, vulnerability was considered easily exploitable and highly dangerous, earning it a maximum CVSS score of 10. Even worse, React is fairly ubiquitous, and at the time of disclosure it was thought that a third of cloud providers were vulnerable. The vulnerability was named React2Shell in apparent reference to Log4Shell, a similarly dangerous bug from late 2021 that impacted environments with Log4j.” Nation-state actors were among the first to exploit the vulnerability, but within days, the vulnerability was being exploited by run-of-the-mill threat actors.

  •  Self-Replicating Malware Shai-Hulud

In September 2025, a self-replicating malware emerged known as Shai-Hulud appeared on the scene. Shai-Hulud is an infostealer that infects open-source software components. “When a user downloads a package infected by the worm, Shai-Hulud infects other packages maintained by the user and publishes poisoned versions, automatically and without much direct attacker input. The cycle continues.” The infostealer “uses defenders’ own automation to …corrupt the open source ‘well’ that thousands of companies draw from daily. This creates a significant danger because the threat isn’t just common vulnerabilities; it’s deeply nested, multilayer dependencies,” according to Unit 42’s Justin Moore. “This creates a massive, multilayered attack surface where a single compromise deep in the stack can cascade across thousands of companies simultaneously.”

  • Threat Campaigns Targeting Salesforce Customers

Earlier in 2025, a threat actor compromised Salesloft’s GitHub account to leverage the access to steal OAuth tokens associated with Salesloft Drift’s Salesforce integration. This led to downstream attacks against hundreds of Salesforce customers’ instances. This attack emphasizes threat actors’ continued attack against prominent supply chain companies, where a successful attack provides access to hundreds or thousands of upstream customers.

These significant security events of 2025 are worthy of consideration when determining a cybersecurity strategy, shoring up vendor management, and budgeting for 2026.

Colonial Pipeline, a company that transports more than 100 million gallons of gasoline and other fuel daily across 14 states from Houston to New York Harbor, shut down the pipeline last Friday after discovering ransomware on its computer systems.  The FBI has blamed the attack on a ransomware group called DarkSide.

The hack reportedly began last Thursday when hackers stole about 100 gigabytes of data as part of a double extortion scheme.  After stealing the data, the hackers then locked Colonial’s computers. Darkside threatened to publish the stolen data online and to keep the computers locked unless Colonial paid an unknown ransom amount.

Colonial Pipeline notified the FBI of the attack on Friday morning and is cooperating with the investigation. The FBI also brought into the investigation the Cybersecurity and Infrastructure Security Agency (CISA) and other government agencies that regulate energy and infrastructure.  The FBI and other government agencies are still awaiting access to the company’s security protocols to determine how hackers pulled off the crippling ransomware attack.

U.S. critical infrastructure has been the target of an increasing number of cyberattacks. Earlier this year, an unknown hacker breached the access controls at the Oldsmar, Florida, water treatment plant, in an attempt to poison the city’s water supply with lye. In 2020, an unnamed natural gas compressor facility was shut down for two days due to a cyberattack.  Several natural gas pipeline operators had service interruptions in 2018, when a technology vendor that facilitated electronic communications between the operators was hacked.

Many members of Congress and the Biden Administration agree that making cybersecurity improvements is essential for the nation’s critical infrastructure, including our electric grid, local energy and utility companies, water treatment plants, and wastewater facilities. All of these operators face significant challenges to make such improvements, including sufficient funding, staffing and training.  In addition, even though the federal government adopted cybersecurity requirements for certain infrastructure operators, funding shortages can result in very little oversight and inspection to make sure operators are complying with the requirements. Some states, like Connecticut, have adopted requirements for certain infrastructure as well as provided funding to make sure operators in the state are complying.

In addition, it is recognized that our cybersecurity standards need updating.  The Biden Administration has proposed significant funding for the National Institute of Standards and Technology (NIST) to work with industry, science, and government to evaluate and improve the standards for our critical infrastructure.