Saturday, September 26, 2026

CISA Adds Mikrotik Vulnerability to KEV Catalog – 9-25-26

Yesterday, CISA announced that it had added an improper enforcement of behavioral Workflow vulnerability in the Mikrotik RouterOS to their Known Exploited Vulnerabilities (KEV) catalog. CERT-PL announced this vulnerability (along with five others) on September 5th, 2026. Mikrotik released three new versions (here, here, and here) that mitigate the vulnerability on September 3rd, 2026, with further updates released on September 22nd.  

On September 4th, Nick Pratley published a technical analysis of the Mikrotik vulnerability based upon his version differential analysis (using AI tools to speed the analysis); includes a limited effect proof-of-concept code. On September 17th, Bishop Fox published an article describing evidence that the six vulnerabilities were being exploited in the wild before Mikrotik published their updated versions, confirming a similar report from CERT.PL published on September 5th, 2026. 

CISA is requiring federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements” [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” A compliance deadline of September 28th, 2026, has been established. 

Review – Bills Introduced – 9-24-26

 On Thursday, with the Senate in Washington (and preparing to leave for the weekend) and the House meeting in pro forma session, there were 188 bills introduced. Four of those bills may receive additional coverage in this blog:  

HR 10569 To amend the Homeland Security Act of 2002 to provide for the protection of biotechnology and biomanufacturing infrastructure by the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Khanna, Ro [Rep.-D-CA-17]    

S 5502 A bill to amend the Homeland Security Act of 2002 to provide for the protection of biotechnology and biomanufacturing infrastructure by the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Hassan, Margaret Wood [Sen.-D-NH]    

S 5508 A bill to establish a public-private working group to develop cybersecurity best practices for telecommunications carriers and related supply chain participants, and for other purposes. Warner, Mark R. [Sen.-D-VA]    

S 5541 A bill to establish the Cybersecurity and AI Board of Investigations, and for other purposes. Markey, Edward J. [Sen.-D-MA]     


For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a mention in passing of a bill to address the latest supply chain cybersecurity issue, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-24-26 - subscription required. 

Friday, September 25, 2026

S 3404 Passed in Senate - Satellite Cybersecurity 

On Wednesday, the Senate considered S 3404, the Satellite Cybersecurity Act of 2025, under the Senate’s unanimous consent process. No objection was raised, and the bill was passed as amended by the Senate Commerce, Science, and Transportation Committee in their business meeting on April 14th, 2026. 

The bill would require the GAO to publish a report on government actions to support cybersecurity of commercial satellite systems. It also outlines new responsibilities for the Department of Commerce (DOC) on satellite cybersecurity. No new funding is authorized by this legislation. 

Short Takes – 9-25-26 - Federal Register Edition

HSAR  

Homeland Security Acquisition Regulation, Make Personal Protective Equipment in America Act Restrictions on Foreign Acquisition (HSAR Case 2024-003). DHS final rule. Summary: “DHS is issuing a final rule to amend the Homeland Security Acquisition Regulation (HSAR) codifying how DHS complies with the requirements of the Make Personal Protective Equipment (PPE) in America Act. These changes are intended to ensure the sustainment and expansion of domestic manufacturing for certain types of PPE critical to the United States' national response to a public health crisis.” 

Public Health  

Amendments To Import Requirements for Highly Pathogenic Avian Influenza. APHIS notice of proposed rulemaking. Summary: “Current APHIS regulations specify that live birds and other avian commodities may not be exposed to highly pathogenic avian influenza (HPAI) or sourced from premises quarantined for HPAI within the 90 days immediately preceding export to the United States. We are proposing to reduce this timeframe to 28 days preceding export to the United States. This action is necessary to align APHIS regulations with international standards regarding HPAI transmission. This action would allow foreign regions to resume the export of live birds and other avian commodities to the United States sooner following an outbreak of HPAI, while still providing adequate safeguards that the importation of the birds or other avian commodities does not present a risk of disseminating HPAI within the United States.” 

Explosives Safety  

Rule Annual Notices on Explosive Materials Storage Facilities to Local Fire Authority. BATFE final rule. Summary: “The Bureau of Alcohol, Tobacco, Firearms, and Explosives (“ATF”) is amending Department of Justice (“Department”) regulations on reporting explosive materials storage. Currently, any person who stores explosive materials subject to ATF's explosives regulations must notify the authority having jurisdiction for fire safety in that locality when they begin storing explosives at that site. This rule adds a requirement to also submit written notices every 12 months thereafter and when the person ceases storing explosives at that location and to retain copies of the notices for five years. These changes are intended to increase public safety, particularly for first responders.” 

Implementing the Safe Explosives Act. BATFE final rule. Summary: “The Bureau of Alcohol, Tobacco, Firearms, and Explosives (“ATF”) is finalizing two Department of Justice (“Department”) interim final rules (“IFRs”) implementing the Safe Explosives Act. This rule formally ends those rules' interim status, responds to public comments from 2003 on the IFRs, rescinds ATF Ruling 2003-5 issued in response to IFR comments, and makes certain revisions to IFR provisions in response to the comments. They clarify when federal licensees/permittees must report changes in responsible persons and authorized employees; eliminate verifying identity of persons accepting delivery on behalf of distributees; and amend regulatory exemption language governing aspects of transporting explosive materials.” 

 
/* Use this with templates/template-twocol.html */