Wednesday, September 30, 2026

Short Takes – 9-30-26 - Federal Register Edition

Avian Influenza  

Amendments To Import Requirements for Highly Pathogenic Avian Influenza. APHIS notice of proposed rulemaking. Summary: “Current APHIS regulations specify that live birds and other avian commodities may not be exposed to highly pathogenic avian influenza (HPAI) or sourced from premises quarantined for HPAI within the 90 days immediately preceding export to the United States. We are proposing to reduce this timeframe to 28 days preceding export to the United States. This action is necessary to align APHIS regulations with international standards regarding HPAI transmission. This action would allow foreign regions to resume the export of live birds and other avian commodities to the United States sooner following an outbreak of HPAI, while still providing adequate safeguards that the importation of the birds or other avian commodities does not present a risk of disseminating HPAI within the United States.” 

Medical Device Security  

Robotically-Assisted Surgical Devices-Premarket Submissions; Draft Guidance for Industry and Food and Drug Administration Staff. FDA notice of availability. Summary: “The Food and Drug Administration (FDA or Agency) is announcing the availability of the draft guidance titled “Robotically-Assisted Surgical Devices—Premarket Submissions.” This draft guidance provides draft recommendations for premarket submissions for robotically-assisted surgical devices (RASDs). This draft guidance is not final nor is it for implementation at this time.” NOTE: includes cybersecurity guidance. 

Space Geek  

Name of Information Collection: NASA Small Business Supplier Development Program (Formerly Known as the NASA Mentor-Protégé Program). NASA 30-day ICR revision notice. Summary: “The purpose of the Program is to provide incentives to NASA prime contractors (mentors) to assist small businesses and other protégés to enhance their capabilities and increase their participation in NASA, other Government, and in commercial contracts and subcontracts. Under the Program, mentor-protégé agreements specify the assistance to be provided by the mentor and agreement milestones, as well as reporting requirements for the mentor and protégé firm. This information collection (i.e., application and reports submitted pursuant to mentor-protégé agreements) is required by NASA to monitor the performance and progress of both the mentor and the protégé in this developmental assistance program.” 

Request for Comment on the Draft Environmental Assessment for Blue Origin New Glenn Cadence Increase at Space Launch Complex 36A, Cape Canaveral Space Force Station, Florida. FAA notice of availability. Summary: “In accordance with the National Environmental Policy Act of 1969, as amended (NEPA), DOT Order 5610.1D, DOT's Procedures for Considering Environmental Impacts, and FAA Order 1050.1G, FAA National Environmental Policy Act Implementing Procedures, the FAA is announcing the availability of and requesting comment on the Draft Environmental Assessment Blue Origin New Glenn Cadence Increase at Space Launch Complex 36A, Cape Canaveral Space Force Station, Florida (Draft EA).” 

Notice of Intent To Prepare a Supplemental Environmental Impact Statement (SEIS) and Open a Public Scoping Period for the SpaceX Starship-Super Heavy Operations at Space Launch Complex 37 at Cape Canaveral Space Force Station, Cape Canaveral, Florida. FAA notice of intent. Summary: “In accordance with the National Environmental Policy Act of 1969, as amended (NEPA), FAA Order 1050.1G, FAA National Environmental Policy Act Implementing Procedures, and Department of War (DoW) and Department of the Air Force (DAF) NEPA Implementing Procedures, FAA is announcing its intent to prepare a Supplemental Environmental Impact Statement (SEIS) concerning Space Exploration Technologies Corp.'s (SpaceX) proposal obtain a modification to their existing vehicle operator license from the FAA to authorize commercial Starship-Super Heavy operations at Space Launch Complex 37 (SLC-37) at Cape Canaveral Space Force Station (CCSFS). This SEIS supports FAA's adoption of the Final Environmental Impact Statement for the SpaceX Starship-Super Heavy Cape Canaveral Space Force Station (2025 DAF EIS), EIS Identification Number: EISX-007-057-USF-1730277197. The proposed operations would include up to 76 Starship-Super Heavy launches and up to 152 landings per year (up to 76 Super Heavy Booster and up to 76 Starship vehicle landings), including return-to-launch-site (RTLS) and ocean landings. FAA is requesting comments concerning the scope and content of the SEIS. A Draft SEIS will be released for public review and comment later.” 

Tuesday, September 29, 2026

Review - HR 10430 Introduced – STARS Act

Earlier this month, Rep Donalds (R,FL) introduced HR 10430, the Securing the Advancement of Rising Spacefarers (STARS) Act of 2026. The bill would support EO 14423, Establishing the United States Space Academy. It would establish the US Space Academy within NASA and would require its permanent location to be in Florida. The bill would authorize such sums as may be necessary to carry out this Act. 

According to a press release from Donalds’ office:  

“"Florida is the birthplace of American space exploration and has led the world in spaceflight for decades. The Sunshine State has built an unmatched, fully integrated space ecosystem that bridges operational launch infrastructure, military space command assets, and tier-one research universities. Establishing the Space Academy on Florida's Space Coast forges an immediate talent pipeline and creates an unmatched competitive advantage, offering cadets daily exposure to NASA personnel, Space Force leaders, and private industry innovators," said Congressman Byron Donalds.” 

Moving Forward  

While Donalds is not a member of the House, Science, Space, and Technology Committee to which the bill was assigned for consideration, both of his cosponsors {Rep Haridopolos (R,FL) and Rep Webster (R,FL)} are members. This means that there may be sufficient influence to see the bill considered in that Committee. Unfortunately, State politics can be expected to rear its ugly head here; the Committee Chair is from Texas, as are three other Representatives. At least three other States (Alabama, Colorado, and California) would also be expected to be considered for the location of the Space Academy.  

I do not expect any movement on this (or similar legislation) at least until the Commission’s report to the President is forwarded to the Congress with their recommendations for the site selection. 


For more details about the provisions of this bill and EO 14423, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-10430-introduced-stars-act - subscription required. 

7 Advisories Published – 9-29-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Viidure, MikroTik, Anjvision, Baicells, VIVOTEK, TopTech, and Lantronix. 

Advisories  

Viidure Advisory - This advisory describes two vulnerabilities in the Viidure Dashcam Android Application. The vulnerabilities were reported to CISA by Bugrahan Karahan. CISA notes that: “Viidure did not respond to CISA's coordination attempts.” 

Mikrotik Advisory - This advisory describes an integer underflow vulnerability in the MikroTik RouterOS. The vulnerability was reported to CISA by an anonymous researcher.  

Anjvision Advisory -This advisory describes an initialization of resource with an insecure default vulnerability in the Anjvision YSSD-RTMP-H5 firmware. The vulnerabilities were reported to CISA by Andrew Lee. CISA notes that: “Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities.” 

Baicells Advisory - This advisory describes an uncaught exception vulnerability in the Baicells Technologies Nova 430H eNodeB. The vulnerability was reported to CISA by Qiqing Huang. CISA notes that: “Baicells has not responded to requests to work with CISA to mitigate this vulnerability.” 

VIVOTEK Advisory - This advisory describes a command injection vulnerability in the VIVOTEK Camera Firmware. The vulnerability was originally reported by Larry Cashdollar with proof-of-concept code. 

Toptech Advisory - This advisory describes 10 vulnerabilities in the Toptech Systems TMS7 and Tophat 7 terminal management systems. The vulnerabilities were reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. 

Lantronix Advisory - This advisory describes two vulnerabilities in the Lantronix G520 Series Cellular Gateway. The vulnerabilities were reported to CISA by Ievgen Bondarenko. 

FRA Sends Safety System Info Protection NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOT’s Federal Railroad Administration (FRA) on “Litigation Protections for System Safety Program and Risk Reduction Program Information”. 

According to the 2026 Unified Agenda entry for this rulemaking:  

“This rulemaking would propose revising 49 CFR 270.105 and 271.11 [links added] to broaden the scope of railroad safety risk reduction program information protected from use in litigation.  The rulemaking would do so by removing the limitation that the protected information must have been compiled or collected solely” for a railroad safety risk reduction program purpose.” 

It would appear that this rulemaking is proceeding under the authority of 49 USC 20119. That section required DOT to conduct a study to determine if: 

“(I)t is in the public interest, including public safety and the legal rights of persons injured in railroad accidents, to withhold from discovery or admission into evidence in a Federal or State court proceeding for damages involving personal injury or wrongful death against a carrier any report, survey, schedule, list, or data compiled or collected for the purpose of evaluating, planning, or implementing a railroad safety risk reduction program required under this chapter, including a railroad carrier’s analysis of its safety risks and its statement of the mitigation measures with which it will address those risks” 

Such a study would have been conducted before the two CFR sections were adopted in 2020. It will be interesting to see if the FRA is relying on that original study for this amendment, or if it has conducted a new study. It would seem to me that a firmer foundation for this revision would be a new study. I would expect that victims’ rights and many rail safety organizations would be leery of any expansion of the information protections involved. 

 
/* Use this with templates/template-twocol.html */