Trump's Gold Eagle (an AI-powered toolbox for vulnerability coordination) comes alongside CISA's guide for building coordinated vulnerability disclosure programs.
On July 14th, 2026, the White announced the creation of “Gold Eagle”, an initiative that supports US advancement in artificial intelligence (AI). Gold Eagle will be “a clearinghouse that enables unprecedented cybersecurity vulnerability coordination”, depending on a communication network between open-source software and US critical infrastructure. By finding and patching cyber vulnerabilities, Gold Eagle is meant to strengthen US cybersecurity. The press release praises the program, calling it “a force multiplier, enabling government and industry to collectively identify risks, prioritize action, and strengthen the resilience of the systems that power our economy, national security, and daily life.”
Pete Hegesth added a martial perspective when praising the program: “Under the leadership of President Trump, we are bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities. GOLD EAGLE serves as the vanguard of America's cyber defense. We are leveraging frontier AI alongside top American innovators to safeguard our critical infrastructure and protect the homeland.” Markwayne Mullin, the Secretary at the Department of Homeland Security (DHS), emphasized the collaboration underpinning the operation: “Together with unprecedented coordination and an abundance of tools at the ready, the Trump Administration is defending our nation’s cyber and critical infrastructures through GOLD EAGLE.”
Cooperation is also highlighted in the announcement for Gold Eagle. The Treasury, the DHS through the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of War (DOW) are all credited with developing the initiative with close communication with industry partners. Curiously, almost all leaders of these groups, including the National Cyber Director, Sean Cairncross, were also quoted in the press release - with one notable exception. The Acting Director and the Deputy Director for CISA, Nick Andersen, was not cited in the release. The exclusion may be a reflection of the significant cuts to the agency’s budget and scope - or point to the agency’s work on a separate vulnerability disclosure project that was released around the same time.
On July 15th, 2026, CISA, in coordination with the National Security Agency (NSA), Japan’s Computer Emergency Response Team Coordination Center (JPCERT/CC), the Netherlands’ National Cyber Security Centre (NCSC-NL), and the United Kingdom's National Cyber Security Centre (NCSC-UK), published guidance on creating and upholding a strong coordinated vulnerability disclosure (CVD) program. “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” is aimed at software manufactures and online service providers. In the introduction, the document explains the importance of CVD systems: “A robust CVD program enables organizations to adjust to changes in frequency and quality of vulnerability submissions and provides security researchers clear direction on how to report vulnerabilities without fear of undue legal action or retaliation.”
After establishing the need for CVD networks for security researchers, the guide divulges how to do so - starting with developing a vulnerability disclosure policy with a wide security testing scope and a clear means of reporting vulnerabilities. The manual also encourages the audience to properly define “processes for triaging, remediating, and assigning CVE IDs for reported vulnerabilities that impact products” to “help mitigate customer risk and encourage a proactive approach to cybersecurity.” The last recommendation is to take advantage of intermediaries like CISA to support or substitute a CVD program. The report concludes with more resources around vulnerability disclosure, like the UK’s Vulnerability Disclosure Toolkit.
While there is seemingly little overlap between the organizations creating the CVD program guide and the creators of Gold Eagle, both initiatives demonstrate a national interest in creating strong systems for vulnerability identification and patching. With luck, these projects will encourage stronger cybersecurity in the US and our international partners.