Friday, August 14, 2026

CSB Publishes Update for Catalyst Refiners Hydrogen Sulfide Release – 8-13-26

 Yesterday, the Chemical Safety Board announced the publication of an update on their investigation of the April 22nd, 2026, fatal hydrogen sulfide release at the Catalyst Refiners facility in Institute, West Virginia. That incident killed two and seriously injured four others during decommissioning activities at the facility. Three incompatible chemicals were sequentially added to the wastewater processing tank, resulting in a chemical reaction that produced the toxic hydrogen sulfide gas. 

The update provides background information on the facility operations at the time of the incident, a description of the incident timeline, and information on the facilities personal protective measures policies at the time of the incident. The report closes with the following list of investigatory items remaining to be resolved: 

  • Analysis of onsite chemicals 
  • “Decommissioning hazard analysis 
  • “Use of personal protective equipment 
  • “Corporate governance and oversight 

Chemical Transportation Incidents – Week of 7-11-26

Reporting Background 

See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

  • Number of incidents – 635 (604 highway, 25 air, 6 rail, 0 water) 
  • Serious incidents – 3 (2 Bulk release, 2 evacuation, 0 injury, 0 death, 0 major artery closed, 2 fire/explosion, 39 no release)  
  • Largest container involved – 30,500-gal Railcar {Alcohols, N.O.S.} Loose manway bolts. 
  • Largest amount spilled – 120-gal Plastic IBC {Zinc Chloride, Solution} Forklift strike. 
  • Total amount reported spilled in all incidents – 1903.8-gal 

NOTE: Links above are to Form 5800.1 for the incident described. 

Most Interesting Chemical: 2-Bromo-2-nitropropane-1,3-diol: White crystals. Ignite easily and burn readily. May detonate under strong shock. Decomposes when heated, evolving toxic gases. Toxic by skin absorption, inhalation, or ingestion. (Source: CameoChemicals.NOAA.gov).  



Review – Bills Introduced – 8-13-26

Yesterday, with both the House and Senate meeting in pro forma session, there were 30 bills introduced. Two of those bills will receive additional coverage in this blog: 

  • HR 10108 To direct the Secretary of Defense to establish guidance governing community engagement and emergency preparedness for defense industrial facilities, and for other purposes. Tran, Derek [Rep.-D-CA-45]    
  • HR 10083 To reauthorize appropriations for the advanced drinking water technology grant program under the Safe Drinking Water Act, and for other purposes. Cisneros, Gilbert Ray [Rep.-D-CA-31]    


For more information on these bills, including legislative history for similar bills in the 118th Congress, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-8-13-26 - subscription required. 

Thursday, August 13, 2026

15 Advisories Published – 8-13-26

Today, CISA’s NCCIC-ICS published 14 control systems security advisories for products from Johnson Controls (2), Siemens (8), ANDRITZ, Hitachi Energy, Haiwell, and AVEVA. They also published a medical device security advisory for products from Flow Neuroscience. 

Advisories  

Johnson Control Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Johnson Controls Metasys UI. 

Johnson Control Advisory #2 - This advisory describes two vulnerabilities in the Johnson Controls Airwall product. 

Siemens Advisory #1 - This advisory describes two vulnerabilities in the Siemens LOGO! Soft Comfort product. The vulnerability was reported to Siemens by Jeroen Slobbe. 

Siemens Advisory #2 - This advisory describes 7 vulnerabilities in the Siemens Solid Edge products. The vulnerabilities were reported to Siemens by Yutao Wang from YunShangHuaAn and Yu Zhou from Southeast University. 

Siemens Advisory #3 - This advisory describes two vulnerabilities in the Siemens Simcenter Femap product. The vulnerabilities were reported to Siemens by Michael Heinzl. 

Siemens Advisory #4 - This advisory describes an out-of-bounds read vulnerability in the Siemens Parasolid product. The vulnerability was reported to Siemens by Michael Heinzl. 

Siemens Advisory #5 - This advisory discusses an OS command injection vulnerability in the  Siemens Siveillance Video products. This is a third-party (Milestone) vulnerability. 

Siemens Advisory #6 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Siemens Desigo DXR and PXC Controllers. The vulnerability was reported to Siemens by Thomas EBI from Sauter.  

Siemens Advisory #7 - This advisory describes two vulnerabilities in the Siemens License Server. The vulnerabilities were reported to Siemens by Intel PSIRT. 

Siemens Advisory #8 - This advisory discusses two vulnerabilities in the Siemens RUGGEDCOM APE1808 products. These are third-party (FortiGuard) vulnerabilities. 

ANDRITZ Advisory - This advisory describes four vulnerabilities in the ANDRITZ HIPASE-250 and 250 SCALA products. The vulnerabilities were reported to CISA by Duc Anh Nguyen and Ta Duc Thien of NTCS OT Penetration Testing Team. 

Hitachi Energy Advisory - This advisory discusses the Dirty Frag vulnerabilities in the Hitachi Energy APM Edge Product. 

Haiwell Advisory - This advisory describes an OS command injection vulnerability in the Haiwell Haiwell IoT Cloud HMI Gateway. The vulnerability was reported to CISA by Fiqram Akmal. 

AVEVA Advisory - This advisory describes a deserialization of untrusted data vulnerability in the AVEVA Enterprise SCADA.  

Flow Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Flow Neuroscience FL-100 neuromodulation device. The vulnerability was reported to CISA by A.C. Buglione. 

 
/* Use this with templates/template-twocol.html */