惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

AI
AI
小众软件
小众软件
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
罗磊的独立博客
爱范儿
爱范儿
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
D
Docker
C
CXSECURITY Database RSS Feed - CXSecurity.com
Spread Privacy
Spread Privacy
Recent Announcements
Recent Announcements
酷 壳 – CoolShell
酷 壳 – CoolShell
G
GRAHAM CLULEY
A
About on SuperTechFans
C
Cisco Blogs
The Register - Security
The Register - Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
Project Zero
Project Zero
V
V2EX
K
Kaspersky official blog
P
Privacy International News Feed
博客园 - 叶小钗
I
Intezer
T
Threatpost
The GitHub Blog
The GitHub Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
Vulnerabilities – Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cybersecurity and Infrastructure Security Agency CISA
Cyberwarzone
Cyberwarzone
Microsoft Azure Blog
Microsoft Azure Blog
N
Netflix TechBlog - Medium
Application and Cybersecurity Blog
Application and Cybersecurity Blog
博客园 - 【当耐特】
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
S
Schneier on Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
F
Full Disclosure
The Cloudflare Blog
P
Palo Alto Networks Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
T
Tenable Blog

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Poisoned truth: The quiet security threat inside enterprise AI Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber Microsoft patched an ‘agent-only’ role that was not AI is reshaping DevSecOps to bring security closer to the code The 'manager of agents': How AI evolves the SOC analyst role 4 Wege aus der Security-Akronymhölle New US House privacy bills raise hard questions about enterprise data collection Scattered Spider co-conspirator pleads guilty Security-KPIs und -KRIs: So messen Sie Cybersicherheit Bitwarden CLI password manager trojanized in supply chain attack 3 practical ways AI threat detection improves enterprise cyber resilience The curious case of Sean Plankey’s derailed CISA nomination Google gets agent-ready for the Mythos age Google drafts AI agents secure systems against AI hackers CNAPP – ein Kaufratgeber Riddled with flaws, serial-to-Ethernet converters endanger critical infrastructure NFC tap-to-pay gets tapped by hackers Anthropic bets on EPSS for the coming bug surge SBOM erklärt: Was ist eine Software Bill of Materials? Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered Prompt injection turned Google’s Antigravity file search into RCE Why identity is the driving force behind digital transformation Top techniques attackers use to infiltrate your systems today The thin gray line: Handala, CyberAv3ngers and Iran’s proxy ops Attackers abuse Microsoft Teams to impersonate the IT helpdesk in a new enterprise intrusion playbook CISOs reshape their roles as business risk strategists Copilot & Agentforce offen für Prompt-Injection-Tricks Claude Mythos – ist der Hype gerechtfertigt? Für Cyberattacken gewappnet – Krisenkommunikation nach Plan Critical sandbox bypass fixed in popular Thymeleaf Java template engine White House moves to give federal agencies access to Anthropic’s Claude Mythos Another Microsoft Defender privilege escalation bug emerges days after patch Palo Alto’s Helmut Reisinger sees a cyber sea change ahead as AI advances Positiv denken für Sicherheitsentscheider: 6 Mindsets, die Sie sofort ablegen sollten NIST cuts down CVE analysis amid vulnerability overload Was bei der Cloud-Konfiguration schiefläuft – und wie es besser geht The endless CISO reporting line debate — and what it says about cybersecurity leadership Behind the Mythos hype, Glasswing has just one confirmed CVE Insurance carriers quietly back away from covering AI outputs RCE by design: MCP architectural choice haunts AI agent ecosystem Critical nginx UI tool vulnerability opens web servers to full compromise Copilot and Agentforce fall to form-based prompt injection tricks The deepfake dilemma: From financial fraud to reputational crisis 7 biggest healthcare security threats The need for a board-level definition of cyber resilience Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action 13 Fragen gegen Drittanbieterrisiken April Patch Tuesday roundup: Zero day vulnerabilities and critical bugs 4 questions to ask before outsourcing MDR 5 trends defining the future of AI-powered cybersecurity EU regulators largely denied access to Anthropic Mythos China-linked cloud credential heist runs on typos and SMTP How AI is transforming threat detection The AI inflection point: What security leaders must do now Cyber-Inspekteur: Hybride Attacken nehmen weiter zu Anthropic’s Mythos signals a structural cybersecurity shift Seven IBM WebSphere Liberty flaws can be chained into full takeover CISOs tackle the AI visibility gap Was ist Federated Identity Management? Old Docker authorization bypass pops up despite previous patch Hacker Unknown now known, named on Europol’s most-wanted list CMMC compliance in the age of AI Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes Was CISOs von Moschusochsen lernen können Hackers have been exploiting an unpatched Adobe Reader vulnerability for months New ClickFix variant bypasses Apple safeguards with one‑click script execution Cloudflare ‘actively adjusting’ quantum priorities in wake of Google warning Patch windows collapse as time-to-exploit accelerates So geht Post-Incident Review 6 Winter 2026 G2 Leader Badges prove this DDoS protection stands out Arelion employs NETSCOUT Arbor DDoS protection products
The cyber winners and losers in Trump’s 2027 budget
2026-04-10 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Federal cybersecurity spending will decline in 2027 under Donald Trump’s proposed budget, with uneven shifts across agencies, as some see sizable increases while others face sharp reductions.

According to the Office of Management and Budget (OMB) crosscut tables released with Trump’s budget, civilian federal cybersecurity spending is expected to fall from $12.455 billion in 2026 to $12.228 billion in 2027, a drop of roughly $227 million. The decrease comes despite targeted increases for some agencies, reflecting uneven changes across the federal cyber landscape rather than a uniform pullback.

The proposed decline follows last year’s budget cycle in which earlier proposed cuts were partially reversed by Congress. Trump’s 2026 budget request last year called for nearly $1 billion in cybersecurity cuts, including steep reductions at the Cybersecurity and Infrastructure Security Agency (CISA).

Congressional appropriators ultimately softened many of those reductions, restoring funding in key areas and preventing a deeper contraction by, for example, restoring $361 million in CISA’s 2026 budget out of the $495 million spending cut that the administration had requested for that agency alone.

Winners: DOJ and State see the largest increases

The biggest beneficiary in the 2027 budget is the Department of Justice, which would see its cyber funding rise by $312 million, or 33%, to $1.27 billion. The increase stands out as the largest single gain across civilian agencies.

The State Department is another major gainer, with a $174 million, or 27% increase to $809 million. The increase aligns with an expanded focus on cyber and emerging technologies, including the department’s new Bureau of Emerging Threats, which is aimed at addressing cyberattacks and risks tied to technologies such as artificial intelligence.

Other agencies seeing increases include:

  • Department of Transportation: +$60 million (+11%)
  • Department of Commerce: +$38 million (+10%)
  • Department of Housing and Urban Development: +$17 million (+10%)
  • Department of Energy: +$11 million (+12%)
Estimated Civilian Federal Cybersecurity Spending By Agency - Winners

Figure 1- Top gainers in Trump’s 2027 budget. Compilation from OMB cross-cut tables.

CSO

Several smaller agencies, including the EPA, Department of Education, Tennessee Valley Authority, Federal Mine Safety and Health Review Commission, and the US Army Corps of Engineers, also stand to post modest gains under the 2027 budget.

Losers: DHS, VA, and research programs face cuts

The largest 2027 budget cut falls on the Department of Homeland Security, where cyber spending would decline by $222 million or 7% to $3.05 billion. DHS remains the government’s largest civilian cyber spender, but the decrease is driven largely by cuts to CISA.

Other notable reductions include:

  • Department of Veterans Affairs: -$165 million (-13%)
  • National Science Foundation: -$132 million (-50%)
  • Department of Health and Human Services: -$94 million (-10%)
  • Department of the Treasury: -$80 million (-10%)

Several independent regulatory agencies, including the Securities and Exchange Commission and Federal Communications Commission, would also inexplicably see their cyber spending reduced to zero in the 2027 proposal. Both the SEC and FCC have been flashpoints for the Trump administration.

The SEC under the previous administration pursued aggressive cybersecurity disclosure rules for public companies, which were unpopular with some corporate stakeholders. The elimination of cyber funding at both agencies raises questions about how those responsibilities would be carried out under the proposal.

The reduction at the National Science Foundation (NSF) is particularly sharp, cutting roughly half of its cyber funding and reflecting a broader effort to reduce the agency’s overall budget. NSF plays a central role in funding academic cybersecurity research, supporting the development of the future cyber workforce, and advancing foundational security technologies, meaning the cuts could have long-term implications that extend well beyond immediate federal operations.

Although not reflected in the crosscut tables, even the White House’s Office of the National Cyber Director (ONCD) is slated to face spending cuts under the 2027 budget.Under the full 1,300-page administration budget, the ONCD is expected to see its budget trimmed by around $3 million, or 18%, to $17 million.

Estimated Civilian Federal Cybersecurity Spending by Agency - Losers

Figure 2- Biggest losers under Trump’s 2027 budget, compilation from OMB crosscut tables.

CSO

CISA: Deeper cuts, ongoing instability

The proposed reductions at CISA extend beyond the topline numbers reflected in the OMB tables.

The budget calls for a $707 million reduction to CISA, described as an effort to refocus the agency on core missions such as Federal network defense and critical infrastructure security while eliminating programs and offices the administration characterizes as duplicative or outside its primary scope, including certain external engagement and misinformation-related activities. The rationale echoes longstanding political criticism of CISA’s past work on misinformation, although the agency has already wound down those efforts.

The 2027 budget is expected to significantly reduce the agency’s workforce, adding to concerns about operational capacity, by eliminating 120 of the agency’s stakeholder engagement program’s 145 positions and cutting the program’s funding by more than $50 million.

The Stakeholder Engagement Division (SED) at CISA leads national and international voluntary partnerships and engagements for information sharing and collaboration.

The FY 2027 budget request said the cuts would eliminate SED’s council management offices, stakeholder engagement activities and offices, and the international affairs external engagement offices. CISA also said it would eliminate 867 agency positions, representing about 766 full-time equivalent employees, from its current staffing level of 3,732 positions.

Reduced cyber spending even as threats grow

The 2027 proposal reduces total federal cyber spending even as threats from nation-state actors and criminal groups continue to advance in their sophistication and level of threat.

“By decreasing spending on cybersecurity at a time when the threats in cybersecurity are accelerating, from both nation-state adversaries and criminal organizations, you’re choosing to increase the nation’s risk,” Michael Daniel, president of the Cybersecurity Threat Alliance, told CSO.

Daniel added that the effects of underinvestment can build over time. “If you underinvest in cybersecurity, it’s one of those issues that tends to compound over the long term. Playing catch-up is always harder than making the investments upfront.”

Lawmakers are also signaling scrutiny of the proposed cuts. House Homeland Security Committee Chairman Andrew Garbarino (R-NY) said in a statement sent to CSO that “CISA has a vital role in fulfilling DHS’s core mission, one that I continue to strongly support,” adding that Congress “has a responsibility to ensure the agency has the resources it needs to succeed.”

The key takeaway for enterprises is that the reduced spending, particularly at CISA, means fewer federal resources available to assist in developing defenses and fending off threats. The upshot is that the implicit expectation that the federal government would serve as an ever-meaningful partner in private sector cyber defense is now structurally weakening.

Enterprise budgets and strategies that assumed a strong private-public sector partnership on cybersecurity likely need revisiting. At a minimum, organizations should consider auditing their CISA dependencies, accelerating private threat intel relationships, and revisiting compliance assumptions around SEC enforcement.

CTA’s Daniel echoes those thoughts in warning that the reduced resources at CISA and elsewhere mean “the federal government’s ability to support and interact with the private sector is going to be reduced. Even if you want to do regulatory reform and you want to reduce the regulatory burden on private sector companies, you still need people there to do the analysis to figure out how to make those changes.”

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.