Tuesday, July 28, 2026

Review – 7 Advisories Published – 7-28-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from ABB, igloohome, MikroTik, and Siemens (4). 

Advisories  

ABB Advisory - This advisory describes a missing support for integrity check vulnerability in the ABB KNX Update Tool. The ABB advisory reports that: “As classic KNX technology did not include built-in encryption, this vulnerability is not specific to ABB products and cannot be addressed through a software update.” 

Igloohome Advisory - This advisory describes an inclusion of sensitive information in source code vulnerability in the igloohome Smart Lock Mobile Application (Android). 

MikroTik Advisory - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the MikroTik RouterOS and MikroTik Cloud Hosted Router. 

Siemens Advisory #1 - This advisory discusses more than 353 GNU/Linux vulnerabilities in the Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. 

Siemens Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Siemens SIMATIC S7-PLCSIM Advanced. 

Siemens Advisory #3 - This advisory describes an insecure inherited permissions vulnerability in the Siemens Mendix Runtime product. 

Siemens Advisory #4 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Desigo CC products. 


For more information on these advisories, including DTRH looks at the Mendix vulnerability and Desigo CC exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-28-26 - subscription required. 

Review - HR 9697 Introduced – Cyber Letters of Marque

Earlier this month Rep Burchett introduced HR 9697, the Cyber Letters of Marque and Reprisal Act. The bill would authorize the President to issue cyber letters of marque and reprisal to commission private persons and entities to conduct limited cyberspace operations. No new funding is authorized by this legislation. 

A press release from Burchett’s office notes that: 

“The Cyber Letters of Marque and Reprisal Act authorizes the President to commission private contractors and entities for the purpose of conducting limited cyberspace operations. Deputizing American patriots will bolster our ability to protect the U.S. against cyber criminals.” 

Moving Forward  

Burchett is a member of the House Foreign Affairs Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see the bill considered in that Committee. While there would be some level of institutional concern about the potential for international retaliatory actions, I suspect that there would be some level of bipartisan support for this legislation. Whether it would be sufficient for the Committee to favorably report the bill, I do not expect it to be sufficient for the bill to be considered by the full House under the suspension of the rules process. 


For more information on the provisions of the bill, including suggested language for designating cyberthreats, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9697-introduced-cyber-letters - subscription required. 

FCC Sends Space Modernization Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the FCC on “Space Modernization for the 21st Century (SB Docket No. 25.306)”. The FCC published the notice of proposed rulemaking on December 5th, 2025. 

According to the 2026 Unified Agenda entry for this rulemaking: 

“In this Notice of Proposed Rulemaking (Notice), the Federal Communications Commission (Commission) proposes to modernize the Commission’s space and earth station licensing process to allow space companies to more freely and successfully compete in the marketplace to serve the American people. In particular, the Notice proposes to develop a licensing assembly line” designed to route applications for efficient review based on specific aspects of a request. It further proposes to change the public notice timelines to allow for faster application processing; proposes reforms to bonds, processing rounds, license terms, and milestones; and substantially updates the earth station licensing regime.” 

This comes from the Long-Term Actions portion of the Agenda, which should have indicated that the FCC did not intend to take any action on the rulemaking in the next 12 months. This might explain why the dates provided in the entry for the ANPRM and NPRM were not reflective of the dates such documents were published in the Federal Register; apparently being reflective of publication dates in the FCC’s SB Docket (for example here). 

Monday, July 27, 2026

CISA Adds FortiGuard Advisory to KEV Catalog – 7-27-26

This afternoon, CISA announced that it had added an exposure of sensitive information to an unauthorized actor vulnerability in the FortiGuard FortiOS product to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard reported the vulnerability on February 10th, 2026, and updated that advisory on March 12th, 2026. That advisory notes that: “Products that never had SSL-VPN enabled, are not impacted by this issue.”  

The vulnerability was originally reported by Peter Gabaldon from ITRESIT; that report includes proof-of-concept code. Gabaldon published additional information on the vulnerability discovery here. A separate exploit for the vulnerability was published by indoushka on February 16th, 2026. 

CISA has directed federal agencies using the affected FortiOS products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [Links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” A compliance deadline of August 10th, 2026, has been set. 

Review - SLTT cUAS Authority IFR – Authorized Personnel

This is the third in a series of blog posts about the interim final rule (IFR) published last week by DHS and DOJ on “Counter-UAS [cUAS] Authority for State, Local, Tribal, and Territorial Law Enforcement and Correctional [SLTT] Agencies”. This post will look at the personnel that would be authorized by this rule to take cUAS actions. 

Previous posts include:  

SLTT Level Authority 

Section 124.3 provides authority for SLTT law enforcement or correctional agencies to take detection, warning, and mitigation actions “that are necessary to address or eliminate a credible threat that a UAS or unmanned aircraft poses to the safety or security of people, a facility, or an asset; a venue or set of venues used for large-scale public gatherings or events; critical infrastructure; or a correctional facility.” 

Authorized Personnel  

Section 124.4 establishes the requirement that cUAS activities authorized under 6 USC 124n(a)(2) may only be conducted by employees of an SLTT agency. It specifically prohibits contractors from operating cUAS detection or mitigation systems that require relief from limitations under section 46502 of title 49 or sections 32, 1030, 1367 and chapters 119 and 206 of title 18, notwithstanding the laws of any particular State, local, Tribal, or territorial jurisdiction. 

Training and Certification  

Section 124.5 establishes the training and certification requirements for conducting cUAS mitigation operations under 6 USC 124n(b)(1) including disrupting control, seizing or exercising control, and use of reasonable force. Possession of Detection and Warning Certification is a prerequisite for mitigation training and certification. Personnel holding a Mitigation Certification issued by the NCUTC before the effective date of this part must complete the detection and warning curriculum by September 29, 2026. 

Mitigation training will be conducted in person at the NCUTC operated by the FBI. A basic Mitigation Certification training course is required, and additional training at the NCUTC may extend the scope of that certification to additional mitigation technology categories. The certification training will include instruction on the legal, operational, and technological aspects of C-UAS operations. 

 
/* Use this with templates/template-twocol.html */