After reading and studying the bill, it's not as cut-and-dry as the EFF/other sources are making it seem, however the implications are still there for what they're saying.
Basically, the bill allows:
* The government to share intelligence with private cybersecurity companies, bypassing all laws of privacy and disclosure.
* Private cybersecurity companies to share intelligence with the government, bypassing all laws of privacy and disclosure.
Information is classified as "‘‘(A) efforts to degrade, disrupt, or destroy such system or network; or theft or misappropriation of private or government information, intellectual property, or personally identifiable information.". Anonymous plots to DDos a server, Wikileaks as a whole (the misappropriation part), and anything regarding internet piracy all fit into this.
* Not only is all of this information exempt from disclosure at the federal, state, or local levels; but it's also exempt from legal liability. If information of a private internet nature is used against you, you can't sue the company/government agency that obtained it.
Major online corporations like facebook or twitter or youtube that employ cybersecurity companies could have *all* of their information sent to the government without any regard for privacy or disclosure. There's no strict definition of what information they send, which is very important -- because it means they could send an entire database dump of tons of secure information to the government because of *one* instance of, say, someone posting a youtube video of copyrighted content. And they would do so without consulting the company they're working for or authorities or anything. And the information the government gleans from the rest of that content can be used against you and you cannot sue them for obtaining it.
Worse, let's consider the Protecting Children from Internet Pornographers bill. With this bill (PCIP), ISP's are required to store subscriber information for a year, including IP addresses and history. The government is also capable of gathering that information with or without probable cause, which under CISPA they can then share with the cybersecurity private sector and be exempt from disclosure and legal liability.
tl;dr this bill is bullshit.