Wednesday, August 19, 2026

Review - ChemLock Fact Sheets – August 2026

For those of you familiar with my “Looking Back” series of blog posts (latest here), there was almost one today about a post of mine from December 2021 on “Review - ChemLock Fact Sheets”. However, after reviewing the CISA ChemLock web site, I decided that it was probably more appropriate to do a new blog post on the topic. 

Fact Sheets 

Early in the CFATS program, DHS started producing a number of short informational brochures about various chemical security topics. Typically just two pages, these Fact Sheets provided a brief look at a specific topic and provided links to other, more detailed information about the topics. They were never designed to make someone a chemical security expert, but they did form a valuable library for chemical professionals to become more aware of security issues. 

When I wrote that first blog post (CFSN version here) there were just seven fact sheets on the ChemLock web site. Now there are three separate pages listing listing 14 separate ChemLock Fact Sheets: 

Commentary  

The Office of Chemical Security continues to have a problem publicly sharing information on the ChemLock Program. While there have been training announcements from @CISAgov for various ChemLock classes (here is the most recent), I have not seen any other outreach efforts and no mentions of these new fact sheets. I understand that CISA is still recovering from the emasculation of the agency that occurred last year, but if they want to keep the ChemLock program going, they are going to have to start making more of an effort to bring facilities into the fold. Publicly talking about the program is an important part of that effort. 


For more information on these fact sheets, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-fact-sheets-august-2026 - subscription required. 

Tuesday, August 18, 2026

CISA Adds VMware Vulnerability to KEV Catalog – 8-18-26

Today, CISA announced that it had added a path traversal vulnerability in the VMware vCenter (multiple VMware products are affected by the vulnerability) product to their Known Exploited Vulnerabilities (KEV) catalog. Broadcom previously disclosed the vulnerability and updated their advisory on August 3rd, 2026; they provide additional information here. The vulnerability was reported to Broadcom by Phil Brass and Matt South of Atredis Partners. Two separate Medium articles have reported public exploitation of the vulnerability:  

CISA has directed federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. 

A compliance deadline of August 21st, 2026, has been established. 

Review – 2 Advisories Published – 8-18-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Siemens and CISA. I also take a down-the-rabbit-hole look at the Github advisories for the CISA Malcom vulnerabilities. 

Advisories  

  • Siemens Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Simcenter Nastran FEM modeling tool. The vulnerability was reported to Siemens by Michael Heinzl. 
  • CISA Advisory - This advisory describes six vulnerabilities in the CISA Malcom network traffic analysis tool. The vulnerabilities were reported to CISA separately by pavanchow, kah-ja, DeathRipper21, and tinb0y. 


For more information on these advisories, as well as a DTRH look at CISA vulnerability reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-8-18-26 - subscription required. 

Review - S 4565 Introduced – Chinese Cyber Threats

Back in May, Sen Scott (R,FL) introduced S 4565, the Strengthening Cyber Resilience Against State-Sponsored Threats Act. The bill would require CISA to establish an interagency task force to “detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China”. The task force would submit annual classified reports to Congress. No new funding is authorized by this legislation. 

A nearly identical bill, HR 2659, the Strengthening Cyber Resilience Against State-Sponsored Threats Act, was introduced by Rep Ogles (R,TN) in April 2025. On April 9th, 2025, the House Homeland Security Committee held a business meeting where HR 2659 was considered; the bill was ordered reported favorably by a voice vote. The Committee Report was published on August 15th, 2025. On November 17th, the full House took up the bill under the suspension of the rules process; the bill passed by a vote of 402 to 8. No action has been taken on the bill in the Senate. 

A press release from Scott’s office notes that:  

“Senator Rick Scott said, “As the world’s leading digital economy, America has the most to lose in a cyberattack. If we don’t secure our digital infrastructure, hackers could cut power to your house, empty your bank account, or disable life support for a loved one in the hospital. Americans shouldn’t worry about a cyber threat from the CCP, which is why I’m proud to be introducing this legislation with Rep. Ogles. The House has done its job in passing this bill, now we need the Senate to do ours.”” 

Moving Forward  

Both Scott and his sole cosponsor, Sen Fetterman (D,PA), are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there may be adequate influence to see the bill considered by the Committee. I do not see anything in the bill that would engender any organized opposition, though there is a real possibility that the Chair, Sen Paul (R,TN), might have some objections to the bill. I do expect that there would be some level of bipartisan support for this bill. The bill, however, is not politically important enough to take up the limited amount of time left in the session that needs to be expended to be considered under regular order. 


For more information on the provisions of this bill, including a commentary on the lack of participation by the intelligence community, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4565-introduced-chinese-cyber-threats - subscription required. 

 
/* Use this with templates/template-twocol.html */