Tuesday, September 15, 2026

Review – 8 Advisories Published – 9-15-26

Today CISA’s NCCIC-ICS published eight control systems security advisories for products from CareCam, Siemens (3), Schneider Electric, myScada, Wärtsilä, and Digital Watchdog. 

Advisories  

CareCam Advisory - This advisory describes eight vulnerabilities in the CareCam CM2507. The vulnerabilities were reported to CISA by Ben Law. CISA notes that: “CareCam has not responded to CISA's attempts to coordinate.” 

Siemens Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Siemens Teamcenter. The vulnerability was reported by Enzo Alvarez from Bishop Fox. 

Siemens Advisory #2 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Mendix SAML. The vulnerability was self-reported. 

Siemens Advisory #3 - This advisory discusses 14 vulnerabilities in the Siemens Reyrolle 7SR5 motor protection relay. Five of these are third-party (Cesanta Mongoose Web Server) vulnerabilities. 

Schneider Advisory - This advisory describes an insufficiently protected credentials vulnerability in the Schneider Electric SCADAPack x70 Products. The vulnerability was reported to CISA by Abhinav Agarwal. 

MyScada Advisory - This advisory describes two missing authorization vulnerabilities in the mySCADA myPRO Manager. These vulnerabilities were reported to CISA by Shirshak of Secnora OÜ. 

Wärtsilä Advisory - This advisory describes two use of hard-coded cryptographic key vulnerabilities in the Wärtsilä FOS-Onboard fleet optimization software. The vulnerabilities were reported by Cydome Security Ltd. 

Digital Watchdog - This advisory describes six vulnerabilities in the Digital Watchdog VMAX DVR and NVR Product Lineups. The vulnerabilities were reported to CISA by Scot Berner of TrustedSec. 


For more information on these advisories, as well as a DTRH looks at a POC and missing Siemens and Schneider advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-9-15-26  - subscription required. 

Monday, September 14, 2026

Review - HR 10151 Introduced – Water System Assistance

Last month, Rep Deluzio (D,PA) introduced HR 10151, the Water Authority Cybersecurity Protection Act. The bill would amend 42 USC 300i-2(g), Technical assistance and grants, increasing the amounts available to the EPA for grants under subsections (4) and (5), increasing the amounts authorized for the Drinking Water Infrastructure Risk and Resilience Program, and extend the authorization for that program through 2029. 

This bill is essentially the same as HR 10389, the Water Authority Cybersecurity Protection Act, that was introduced by Deluzio in December 2024. That bill was introduced even later in the 118th Congress, and no action was taken. According to a press release from Deluzio’s office: 

“Any attack on our nation’s critical infrastructure is unacceptable, and the 2023 Iranian hack in Western Pennsylvania should have been a major wake-up call for our federal government,” said Congressman Deluzio. “Especially while the Iran War continues, we need to make sure our local water authorities have the resources and training they need to defend against cyber threats from the Iranians and others. Residents should be able to trust that their drinking water is safe from attacks. I am proud to reintroduce the Water Authority Cybersecurity Protection Act to help local leaders better secure our water system.” 

Moving Forward  

Neither Deluzio nor his sole cosponsor, Rep Finstad (R,MN), are members of the Energy and Commerce Committee to which this bill was assigned for consideration. This means that there will probably not be sufficient influence to see the bill considered by that Committee. While the increased funding would typically be considered an anathema to many Republicans, the recent spate of purported Iranian attacks on public water systems in this country, might outweigh the spending concerns in some members. While I would expect some level of bipartisan support if this bill was considered, I do not think that there would be enough support to allow the bill to be successfully considered under the suspension of the rules process. 


For more information on the provisions of this bill, as well as commentary on EPA grants for water system cybersecurity, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-10151-introduced-water-system - subscription required. 

Saturday, September 12, 2026

Short Takes – 9-12-26 - Federal Register Edition

RCRA Testing  

Request for Information on Test Methods for Evaluating Solid Waste (SW-846), Waste Sampling and Toxicity Characteristic Leaching Procedure (TCLP) Testing. EPA request for information. Summary: “EPA updates test methods and waste sampling guidance as part of routine updates according to the Resource Conservation and Recovery Act (RCRA). To aid in the implementation of these directives, the Office of Resource Conservation and Recovery (ORCR) within the Environmental Protection Agency (EPA) requests information on SW-846 method experiences, needs, and requirements. ORCR is specifically interested in information on the Toxicity Characteristic Leaching Procedure (TCLP) Method 1311, including method challenges, and alternatives. Information is welcome from stakeholders involved in requesting, performing, and evaluating the results from SW-846 methods including, but not limited to, industry stakeholders, researchers, academia, state, Tribal, and local governments. This includes U.S. territories and the District of Columbia, other federal agencies, community groups, non-governmental organizations, the public, and international organizations. The EPA will use the information received in response to this request for information (RFI) to inform what action, if any, it may take. 

Space Geek  

Name of Information Collection: Proposal Submissions and Awards Management System (ProSAMS) for the NASA Small Business Innovation Research/Small Business Technology Transfer (SBIR/STTR) program Solicitations. NASA 30-day new information collection request notice. Summary: “The Small Business Innovation Research (SBIR) program is a highly competitive program that encourages domestic small businesses to engage in Federal Research/Research and Development (R/R&D) that has the potential for commercialization.... The Small Business Technology Transfer (STTR) is another program that expands funding opportunities in the federal innovation research and development (R&D) arena. 

Executive Orders  

EO 14426 - Accelerating Access to Veterans' Benefits and Employment Opportunities. 

EO 14427 - Adjusting Certain Delegations Under the Defense Production Act. 

OMB Approves EPA Facility Response Delay Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had approved a final rule from the EPA on “Clean Water Act Hazardous Substance Facility Response Plans: Compliance Date Delay and Changes to Reflect Administration Policy”. The notice of proposed rulemaking for this action was published on March 5th, 2026. This final rule was sent to OIRA on July 1st, 2026. 

According to the 2026 Unified Agenda entry for this rulemaking:  

“The Clean Water Act (CWA) Section 311(j)(5) provides that regulations shall be issued "which require an owner or operator of a tank vessel or facility ... to prepare and submit ... a plan for responding, to the maximum extent practicable, to a worst-case discharge, and to a substantial threat of such a discharge, of a hazardous substance." The Environmental Protection Agency (EPA) published a final rule in March 2024 to require planning for worst case discharges of CWA hazardous substances under section 311(j)(5)(A). Section 3 of the January 20, 2025, Executive Order 14154 Unleashing American Energy requires an immediate review of agency actions to identify those that may impose an undue burden on the identification, development, or use of domestic energy resources. As EPA considers options, the agency is proposing to extend the compliance date and make administrative changes” 

NOTE: OIRA classifies this as a ‘deregulatory action under EO 14192. 

 
/* Use this with templates/template-twocol.html */