Policy Pulse - Issue #25 | Week of July 18, 2026
CISA, NSA, and allied agencies from the UK, Netherlands, and Japan jointly tell vendors how to run a VDP, safe-harbor language included. Plus: AI-scale disclosure overwhelms maintainers, and the White House launches Gold Eagle.
Policy Pulse - Issue #25 | Week of July 18, 2026
Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.
Top Story
Five Governments, One Playbook: CISA, NSA, and Allied Agencies Tell the World How to Run a VDP
On July 15, CISA, the NSA, Japan's JPCERT/CC, the Netherlands' NCSC-NL, and the UK's NCSC-UK jointly published "Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers," a Cybersecurity Information Sheet released under CISA's Secure by Design initiative (CISA; Help Net Security). The guidance is not subtle about what it wants software makers to do: publish a public VDP, use "safe-harbor language assuring researchers their good-faith work is authorized under anti-hacking statutes," adopt security.txt (RFC 9116) so researchers can find a contact without guessing, assign a CVE even to bugs found internally, publish advisories via CSAF, acknowledge incoming reports within two to three business days, and drop NDA terms that block a researcher from ever disclosing.
Four governments across three continents just told every vendor that reads it, in writing, to build the exact program shape disclose.io has spent years arguing for: a public intake channel, an explicit authorization promise, and a documented disclosure path that treats researchers as collaborators rather than intruders. It arrives as soft law, a best-practices sheet, not a rule with teeth, but it gives practitioners something concrete: a citable, five-government reference to hand a vendor that has no VDP or, worse, threatens researchers who report to it in good faith.
Why it matters for VDP: This is as close to an international consensus statement on disclosure program design as the field has produced. It does not change the CFAA, the Computer Misuse Act, or any other statute a researcher could still be prosecuted under, so the gap between "recommended safe harbor" and "statutory protection" remains exactly where it was last week. But it moves the Overton window on what a defensible VDP looks like, and it gives program operators a government-backed checklist to benchmark against.
Throwback: In Issue #24, we covered the UK's Cyber Security and Resilience Bill advancing through the Lords while stopping well short of the Computer Misuse Act reform researchers actually want; this week's joint guidance is the inverse move, four allied governments delivering the practice-level substance of good-faith protection through agency guidance while the harder statutory fixes stay stuck.
Upcoming Deadlines & Events
| Date | Agency | Event/Deadline | Action Required | Link |
|---|---|---|---|---|
| Jul 22-23, 2026 | NIST | Virtual workshop: "Securing AI Data Center: Architecture, Security Posture, and Emerging Standards" | Register (ZoomGov, no listed deadline) | NIST event page |
| Jul 31, 2026 | NIST | SP 800-38D Rev. 1 (Second Pre-Draft: GCM/GMAC plus new wGCM variant) comment period closes | Submit comments per the pub page instructions | CSRC |
| Jul 31, 2026 | NIST NCCoE | "Asset Management as a Foundation for OT Cybersecurity" project description comment period closes | Submit comments | NIST CSRC drafts open for comment |
| Aug 1, 2026 | Treasury / NSA / CISA / ONCD / NIST | Classified benchmarking framework due, designating "covered frontier models" by cyber capability (EO 14409) | None for public; sets the threshold that governs future model gating | White House EO 14409 |
| Aug 14, 2026 | NIST | SP 800-219 Rev. 2 (macOS Security Compliance Project) comment period closes | Submit comments | NIST CSRC drafts open for comment |
| Aug 15, 2026 | Netherlands | Cyberbeveiligingswet (NIS2 transposition) enters into force, no grace period | Confirm CVD/incident-reporting readiness if you operate in-scope infrastructure | Houthoff |
| Aug 24, 2026 | US Copyright Office | Tenth triennial DMCA Section 1201 petitions due (new and renewed exemptions, including security research) | File or support a petition | copyright.gov/1201/2027 |
| Sep 11, 2026 | ENISA / EU | Cyber Resilience Act vulnerability and incident reporting obligations go live | Confirm your CVD process meets 24hr/72hr/14-day reporting clocks | Crowell client alert |
| Sep 28, 2026 | US Copyright Office | DMCA Section 1201: comments on renewal petitions due | Submit comments | copyright.gov/1201/2027 |
This Week in Policy
AI & Emerging Tech Security
- AI-scale disclosure is now overwhelming the maintainers on the receiving end. Anthropic's Glasswing program has surfaced 6,202 high- or critical-severity vulnerabilities across more than 1,000 open-source projects, with a 90.6% true-positive rate on the triaged subset, and Epoch AI independently measured roughly 1,500 high/critical CVEs disclosed in June, more than 3.5 times the prior monthly record (Anthropic; Epoch AI). Anthropic says "several maintainers have told us they're severely capacity constrained, and some have even asked us to slow down our rate of disclosures because they need more time to design patches." Why it matters for VDP: this is the practical, already-arrived version of the AI-scale submission-volume problem: a coordinated, high-validity pipeline is still outrunning maintainer patch capacity, which means rate-limiting and validity-gating on intake are no longer theoretical design questions.
- UK AISI: cheap open-weight models are closing in on the frontier's cyber capability. A July 17 evaluation found leading open-weight models (GLM-5.2, DeepSeek V4-Pro) now perform comparably to closed frontier models released four to five months earlier (GLM-5.2 within four months of its comparison point, DeepSeek V4-Pro within five), a narrower gap than the six to ten months AISI measured internally through 2025, at a fraction of the inference cost (UK AISI). AISI calls this "a persistent and irreversible risk of misuse" and warns defenders have a shrinking window before today's frontier cyber capability ships without frontier-lab safeguards attached. Why it matters for VDP: the safety tooling wrapped around hosted frontier models does not travel with open weights, so expect a rising share of AI-assisted submissions to come from tooling with no lab-side CVD process standing behind it.
- China's agentic-AI rules take legal effect, an early dedicated regulatory category for AI agents. New rules governing AI agents entered into force in China on July 15, establishing a three-tier decision-authorization framework that scales required human-approval thresholds to an agent action's consequence level, plus mandatory regulatory filing for agents deployed in designated high-risk sectors (AI Governance). Why it matters for VDP: this is one of the first governments treating agentic AI as its own governance object rather than a feature of an existing application, and it lands while the US approach stays fragmented across state-level rules like Illinois's SB 315.
Federal Strategy & Regulation
- The White House launches Gold Eagle, a federal-industry vulnerability-coordination clearinghouse. National Cyber Director Sean Cairncross, alongside Treasury, DHS/CISA, and the Department of War, announced Gold Eagle on July 14: a voluntary clearinghouse where open-source software partners and critical-infrastructure operators coordinate vulnerability scanning, validate findings, de-duplicate scanning effort across participants, and prioritize patch distribution, standing up the coordination layer that Executive Order 14409 called for (White House). Why it matters for VDP: this is a government-run coordination mechanism operating adjacent to established VDP and CVD channels, in the same week as the joint CVD guidance in this issue's top story, so it directly shapes how federally-relevant findings get routed and prioritized going forward.
- CISA pushes emergency SharePoint hardening guidance amid active exploitation. CISA warned on July 14 of active exploitation against on-premises SharePoint Server, urging AMSI integration and close monitoring, alongside a same-day KEV addition for the underlying flaw (CISA). Why it matters for VDP: a live coordinated-response case study in the gap between disclosure and exploitation, and a reminder of why timely patch prioritization on internet-exposed enterprise software stays the sharpest edge of this work.
CVE & Vulnerability Programs
- CISA adds seven vulnerabilities to the KEV catalog, July 13-15. New additions: CVE-2008-4128 (Cisco IOS CSRF, July 13); CVE-2026-15409 and CVE-2026-15410 (SonicWall SMA1000, SSRF and code injection), CVE-2026-56164 (Microsoft SharePoint, missing authentication), and CVE-2026-56155 (Microsoft AD FS, access-control privilege escalation), all July 14; CVE-2023-4346 (KNX Association KNX protocol) and CVE-2026-46817 (Oracle E-Business Suite, improper privilege management), July 15 (CISA, Jul 13; CISA, Jul 14; CISA, Jul 15). The SonicWall and SharePoint entries carry a July 17 remediation deadline, AD FS a July 28 deadline, under CISA's BOD 26-04 risk-based remediation regime. Why it matters for VDP: a 2008-era Cisco flaw sitting alongside a 2026 SharePoint zero-day in the same week's KEV additions is a reminder that disclosure value does not decay on a tidy timeline.
- Cisco's "umbrella CVE" model, live this month, cuts against the week's own disclosure guidance. Cisco's risk-based disclosure model, now operational, consolidates related bugs sharing a CWE into single "umbrella" CVEs scored at worst-case severity and deprioritizes low-risk individual advisories, while shifting to a twice-monthly publication cadence; Adobe made a similar twice-monthly shift effective July 14 (Cisco). Why it matters for VDP: this runs directly counter to this issue's top story, which recommends assigning a CVE to every finding. As AI-accelerated discovery floods pipelines, a major vendor is deliberately shrinking CVE granularity, which means CVE counts increasingly under-represent true finding volume and per-researcher credit gets harder to track.
Legal & Researcher Protections
- UK's CMA reform stays parked, on the record, at the Lords Second Reading. At the July 14 House of Lords Second Reading of the Cyber Security and Resilience Bill, peers including Lord Clement-Jones pressed the absence of Computer Misuse Act reform; the government reiterated its position that a CMA statutory defence belongs in the still-unpublished National Security Bill, not this resilience-focused legislation (Lord Clement-Jones; CyberUp Campaign). Why it matters for VDP and UK-based researchers specifically: this confirms Issue #24's read. The bill actually moving through Parliament this month is not the one that changes researcher liability exposure, and the promised defence, when it eventually arrives, has been reported as narrowly drawn.
- DMCA Section 1201's tenth triennial rulemaking is open, with the security-research exemption's renewal on the table. The Copyright Office's proceeding for the 2027 cycle is underway; new and renewal petitions, including for the good-faith security-research circumvention exemption, are due August 24, 2026, with comments on renewals due September 28 (Copyright Office). Why it matters for VDP: this is a concrete, fileable action for anyone whose research depends on circumventing access controls, and it is exactly the kind of proceeding the disclose.io community should be commenting on rather than watching from the sidelines.
International Developments
- US, UK, and EU run coordinated sanctions against ransomware infrastructure on the same day. On July 13, the US Treasury and State Department, coordinated with the UK's FCDO, sanctioned First VPN Service, its administrator Dmytro Rashevskyi, and cryptor-seller Yegeniy Silayev, marking the first US sanctioning of both a VPN provider and a malware "cryptor" seller (US State Department; The Hacker News). The same day, the Council of the EU sanctioned nine individuals and four entities over Russian cyberattacks, including bulletproof-hosting provider Media Land and its owner Alexander Volosovik (Council of the EU). Why it matters for VDP: three governments moved against the infrastructure layer, not just operators, on the same day. Watch for the same over-broad-tooling concern that shadows the UN cybercrime treaty debate: "cryptor" and anonymization-tooling sanctions sit close to categories legitimate researchers and pentesters also rely on.
- The Netherlands' NIS2 transposition clears its last legislative hurdle. The Dutch Senate adopted the Cyberbeveiligingswet on July 7; it enters into force August 15 with no grace period (a three-year transition applies only to higher-education institutions), bringing organizations with 50+ employees or €10 million+ turnover into scope for governance, risk-management, and incident-reporting duties (Houthoff). Why it matters for VDP: this closes the loop on Issue #24's story of the European Commission referring the Netherlands to the CJEU one day after this Senate vote, for a transposition that technically hadn't taken legal effect yet. The timing gap between "voted" and "in force" is exactly what's driving Brussels's enforcement wave.
Worth Reading
- How Far Behind the Frontier Are Leading Open-Weight Models on Cyber? (UK AISI): The full evaluation behind this issue's open-weight item, worth reading for the methodology behind the four-to-seven-month gap estimate and AISI's misuse-risk framing.
- Cyber Security and Resilience Bill "Lacking in Ambition" (Lord Clement-Jones): A peer's first-hand account of the July 14 Lords debate, useful for the specific language used to press the government on CMA reform.
- CVE Severity Spike (Epoch AI): The independent data analysis behind the June disclosure-surge figures cited in this issue's AI section, with methodology notes on how the 3.5x monthly-record claim was derived.
Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.
Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!