- Artificial Intelligence
- Cybersecurity
Gold Eagle Aims to Bring ‘Machine Speed’ to Cyber Defense
The federal AI cybersecurity clearinghouse aims to accelerate vulnerability sharing and remediation as AI increases the pace of discovery.
The federal government’s new AI cybersecurity clearinghouse could help defenders keep pace with a growing volume of AI-discovered vulnerabilities, but its success depends on whether industry trusts the system enough to share what it finds.
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Treasury Department, released Gold Eagle to process and coordinate vulnerability reports at scale as AI accelerates vulnerability discovery. The capability is designed to help defenders triage and prioritize vulnerabilities faster, but cybersecurity experts say its effectiveness will hinge on widespread industry participation.
Bob Costello, former CISA CIO, told GovCIO Media & Research that Gold Eagle is a step in the right direction as government and industry confront a scale and speed of vulnerability discovery that traditional processes may struggle to match. Cybersecurity experts across government and industry have called for more automated solutions to aid vulnerability discovery, prioritization and remediation.
“Threat discovery is increasing at a level we haven’t seen before because … AI can do things that hackers could never do. Now we need to get to the point where we can take information, synthesize it, bring a lot of context to those vulnerabilities and then prioritize how we patch. All of that has to happen at machine speed,” Costello said.
How Gold Eagle Works
Gold Eagle was established in response to a June 2 executive order and is part of a broader initiative announced in July to increase threat information sharing and strengthen national cybersecurity against AI-enabled threats.
The clearinghouse works within CISA’s existing Vulnerability Information and Coordination Environment (VINCE) platform. It is designed to streamline the initial triage of vulnerability reports submitted through the Coordinated Vulnerability Disclosure program, helping CISA manage a growing volume of vulnerabilities discovered with AI.
CISA said Gold Eagle is intended to supplement, rather than replace, existing private-sector and community-driven vulnerability management efforts.
“With the increased volume of AI-discovered vulnerabilities, we will adapt and create new tooling that supports the core VINCE platform. Gold Eagle serves as a powerful additionalse
Costello, who is now chief digital and information officer at Merlin Group, said stronger information sharing could be particularly valuable for smaller critical infrastructure operators, including local governments and municipalities, that may lack the resources to independently identify and respond to emerging vulnerabilities.
“This is a way to share information, level the playing field, and gain a lot of context around what these AIs are discovering in software, and then share that information back out to the broader cyber community,” Costello said.
Industry Participation Could Determine Gold Eagle’s Success
While Gold Eagle could provide the technical infrastructure to process vulnerability information at greater speed and scale, experts said its effectiveness will depend on whether private-sector organizations are willing to contribute what they discover.
Shane Barney, former CISO at U.S. Citizenship and Immigration Services (USCIS), told GovCIO Media & Research that industry participation could be one of the clearinghouse’s biggest challenges.
Barney said information sharing is critical to helping industry identify vulnerabilities and active exploitation, but there is limited detail about what protections companies would receive when voluntarily reporting vulnerabilities.
That could make organizations hesitant to disclose vulnerabilities to the federal government, particularly when a vulnerability does not yet have a fix. Barney said clearer protections could give companies greater confidence that voluntarily sharing information will not expose them to additional legal or regulatory risks.
“In my view, some amendments to build data protection layers for the industry partners. If they self-report and try to do the right thing, then their reward is not only a safer, secure environment for everyone, but you as a company are protected from those other legal aspects,” Barney said.
Barney, who is now CISO at Keeper Security, pointed to lessons from the SolarWinds cyberattack to illustrate the risks companies can face when deciding whether and when to share sensitive cybersecurity information. He said organizations need greater confidence that disclosing potential threats or vulnerabilities will not leave them exposed to additional consequences.
“Cybersecurity is a team sport, and the bigger and better team you have, the better off you are. Sometimes to incentivize people you need to use the carrot and the stick, not just the carrot,” Barney said.
This is a carousel with manually rotating slides.
Use Next and Previous buttons to navigate
or jump to a slide with the slide dots
