Thursday, August 27, 2026

Review – 5 Advisories and 2 Updates Published – 8-27-26

 Today CISA’s NCCIC-ICS published five control system security advisories for products from Ebyte, Applied Systems Engineering, Rockwell Automation, All-Line Equipment, and Xiiaozet. They also updated two advisories for products from Mitsubishi. 

Advisories  

Ebyte Advisory - This advisory describes 13 vulnerabilities in the Ebyte NA111-M serial port server. The vulnerabilities were reported to CISA by Jithin Nambiar. 

Applied Systems Advisory - This advisory describes two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set. The vulnerabilities were reported to CISA by Enoch Wang. 

Rockwell Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Rockwell OTTO Fleet Manager. The vulnerability was self-reported. 

All-Line Equipment Advisory - This advisory discusses two vulnerabilities (both with public exploits) in the All-Line Fuel-Boss. These vulnerabilities were reported to CISA anonymously. 

Xiiaozet Advisory - This advisory describes three vulnerabilities in the Xiiaozet LK100W wireless print server. The vulnerabilities were reported to CISA by Byron Guernsey of Okachobi, LLC. 

Updates  

Mitsubishi Update #1 - This update provides additional information on the CNC Series advisory that was originally published on March 19th, 2026. 

Mitsubishi Update #2 - This update provides additional information on the Multiple FA Products advisory that was originally published on April 25th, 2025, and most recently updated on April 30th, 2026. 


For more information on these advisories, including a DTRH look at 3rd party exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-b0d - subscription required. 

Review - S 5067 Introduced – Cybersecurity Training

Last month, Sen Hassan introduced S 5067, the Federal Cybersecurity Workforce Expansion Act. It would require CISA to establish an apprenticeship program that would lead to cybersecurity related employment with CISA or other Federal entity. The bill would also require the Veterans Administration to establish a pilot program providing cyber-specific training for eligible individuals. There is no funding authorized in the legislation. 

S 5067 is essentially the same as to S 2256, the Federal Cybersecurity Workforce Expansion Act, that was introduced by Hassan in July 2023. The Senate Homeland Security and Governmental Affairs Committee held a business meeting on July 26th, 2023, and ordered the bill reported favorably by a vote of 7 to 1 {Sen Paul (R,KY) voting NAY}. No further action was taken on the bill in the 118th Congress. A similar bill, HR 6524, was introduced in the Housse by Rep Houlahan (D,PA) in November of 2023. No action was taken on that bill in the House. 

Moving Forward  

Hassan is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered by that Committee. Unfortunately, Paul’s (now Chair of the Committee) opposition to the earlier version of this bill will probably ensure that the bill is not considered.  

If the Committee were to consider the bill (and Paul has brought the occasional bill before the Committee to which he objected), I suspect that it would receive substantial bipartisan support. Unfortunately, this bill is not politically important enough to consume the time necessary for this bill to be considered by the full Senate under regular order. And Paul’s opposition would almost certainly prevent the bill from being considered under the unanimous consent process. 

Commentary 

While this bill does not directly address control system security issues, increasing the cybersecurity qualified staffing of CISA is certainly of interest to the ICS security community. While the training programs established under this bill would be targeted at future CISA employment, they should result in a net increase to the nation’s cybersecurity workforce. 


For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5067-introduced-cybersecurity-training - subscription required. 

Short Takes – 8-27-26 - Federal Register Edition

 TSCA Risk Evaluation  

trans-1,2-Dichloroethylene Draft Risk Evaluation Under the Toxic Substances Control Act (TSCA); Notice of Availability and Request for Comment. EPA notice of availability. Summary: “The Environmental Protection Agency (EPA or Agency) is announcing the availability of and seeking public comment on the draft risk evaluation under the Toxic Substances Control Act (TSCA) for trans-1,2-dichloroethylene. The purpose of risk evaluations under TSCA is to determine whether a chemical substance presents an unreasonable risk of injury to health or the environment under the conditions of use (COUs), including unreasonable risk to potentially exposed or susceptible subpopulations identified as relevant to the risk evaluation by EPA, and without consideration of costs or non-risk factors. EPA is seeking comment on the draft risk evaluation for trans-1,2-dichloroethylene. 

ICR Notices  

Comment Request; Emergency Planning and Community Right-to-Know Act (EPCRA) Hazardous Chemical Inventory Reporting. EPA 30-day ICR extension notice. Summary: “EPCRA section 312 requires owners and operators of facilities subject to the OSHA HCS to submit an inventory form (for those chemicals that exceed the thresholds, specified in 40 CFR part 370) to the SERC (or TERC), LEPC (or TEPC), and LFD with jurisdiction over their facility. This inventory form, the Tier II Emergency and Hazardous Chemical Inventory Form, is to be submitted on or before March 1 of each year and must include the inventory of hazardous chemicals present at the facility in the previous calendar year. Currently, all states require facilities to submit the Federal Tier II form or the state-equivalent, including electronic submission. 

Request for Comment; Novel Human-Machine Interface Designs. NHTSA 30-day new ICR notice. Summary: “This ICR is to request approval to conduct seven new voluntary information collections as part of a one-time research study of drivers' interactions with commercially available vehicles with different HMI features/designs. NHTSA of the DOT is seeking to conduct the research study involving up to 35 licensed drivers between the ages of 18 and 55 from the greater Phoenix, Arizona area. The information collections involve reporting and include: (1) an eligibility questionnaire to be administered to up to 100 potential research respondents; (2) an informed consent form to be administered to up to 35 research participants; (3, 4, 5) study drives with vehicles 1, 2, and 3; (6) the same vehicle technology questionnaire after each study drive; and (7) an exit interview (including the time for a debrief).” 

Wednesday, August 26, 2026

CSB Releases Fatal Nitrogen Gas Release Safety Video

Yesterday, the Chemical Safety Board (CSB) announced that it had released a new chemical safety video, Fatal Fog: Liquid Nitrogen Release at Foundation Food Group, based upon its investigation of the January 28th, 2021, fatal Foundation Food Group liquid nitrogen release in Gainesville, GA. Six people died of asphyxiation during the incident where a bent bubbler tube failed to properly control the level of liquid nitrogen in an emersion freezer. 


BIS Sends CBWC Sudan Sanctions Final Rule to OMB

Yesterday, OMB’s Office of Information and Regulatory Affairs announced that it had received a final rule from DOC’s Bureau of Industry and Security on “Sudan: Implementation of Chemical and Biological Weapons Control and Warfare Elimination Act of 1991 Sanctions in the EAR; Additional Restrictions”. 

According to the 2026 Unified Agenda Entry for this rulemaking: 

“The Department of State, acting under authority delegated pursuant to Executive Order 12851, has determined pursuant to the Chemical and Biological Weapons Control and Warfare Elimination Act of 1991 (CBW Act) that the Government of Sudan has used chemical or biological weapons in violation of international law or lethal chemical or biological weapons against its own nationals. The sanctions imposed on Sudan in connection with this determination include a prohibition, subject to partial waiver, on the export, reexport, or transfer (in-country) to Sudan of national security-controlled items subject to the Export Administration Regulations (EAR). With this final rule, consistent with BIS’s implementation of the CBW Act sanctions, Sudan is being removed from Country Group B and most license applications for exports, reexports, or transfers (in-country) of national security-controlled items destined for Sudan will be reviewed under a presumption of denial. Additionally, pursuant to its authority under the Export Control Reform Act of 2018, BIS is adding Sudan to column Country Group D:3 of the Commerce Country Chart and is tightening its license application review policy for items controlled for chemical and biological reasons by adopting the same presumption of denial policy.” 

Side Note: While the 2026 Unified Agenda entry for this rulemaking notes that this was previously published in the Unified Agenda, the Spring 2025 Unified Agenda entry for RIN 0694-AK21 appears to have been a generic placeholder rulemaking entitled: “Revisions to EAR” with an equally generic abstract listing of “In this rule, the Bureau of Industry and Security (BIS) amends the Export Administration Regulations (EAR).” A similar placeholder entry, RIN 0694-AK42, can be found in the 2026 Unified Agenda. 

 
/* Use this with templates/template-twocol.html */