Friday, October 2, 2026

Chemical Transportation Incidents – Week of 8-29-26

Reporting Background 

See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

  • Number of incidents – 534 (505 highway, 23 air, 6 rail, 0 water) 
  • Serious incidents – 2 (1 Bulk release, 0 evacuation, 0 injury, 0 death, 0 major artery closed, 3 fire/explosion, 20 no release)  
  • Largest container involved – 25,475-gal DOT 111A100W1 Railcar {Sulfur, Molten} Failed rupture disk. 
  • Largest amount spilled – 150-gal Plastic IBC {Organic Peroxide Type F, Liquid} IBC’s damaged in load shift. 
  • Total amount reported spilled in all incidents – 1670.6-gal 

NOTE: Links above are to Form 5800.1 for the incident described. 

Most Interesting Chemical: Trichloroacetic Acid: Trichloroacetic acid, solid is a colorless crystalline solid. It absorbs moisture from air and forms a syrup. It is soluble in water with release of heat. It is corrosive to metals and tissue. (Source: CameoChemicals.NOAA.gov).  



Looking Back – 3-14-10 – SSP Experience

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from March 14th, 2010, “Reader Comment 03-13-10 SSP Experience”. This was part of an ongoing conversation that took place in this blog about the early days of the Chemical Facility Anti-Terrorism Standards (CFATS) program. While that program is dead, and the specific program discussion of mostly historical interest, there is an ongoing hope that the CFATS program in some form may be resurrected int he 120th Congress. Hopefully, a rejuvenated CISA would take a hard look at the lessons learned in standing up a new chemical security program. 

Thursday, October 1, 2026

Review – 6 Advisories and 1 Update Published – 10-1-26

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Meari, Johnson Controls (2), ABB, Monta, and Armatura. They also updated an advisory for products from CISA. 

Advisories  

Meari Advisory - This advisory describes two vulnerabilities in the Meari IoT Cloud Platform OpenAPI. The vulnerabilities were reported to CISA by Gabriel Adams. CISA notes that: “Meari did not respond to CISA's coordination attempts.” 

Johnson Controls Advisory #1 - This advisory describes a cleartext transmission of sensitive information vulnerability in the Johnson Controls EasyIO Neo Series EC and CW Controllers. The vulnerability was reported by Gabriele Gardois. 

Johnson Controls Advisory #2 - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Johnson Controls EasyIO Neo Series EC and CW Controllers. The vulnerability was reported by Gabriele Gardois. 

ABB Advisory - This advisory describes two vulnerabilities in the ABB Protection and Control IED Manager PCM600. The vulnerabilities were reported by Abhinav Agarwal.  

Monta Advisory - This advisory describes four vulnerabilities in the Monta monta.app EV charging application. The vulnerabilities were reported to CISA by an anonymous researcher. 

Armatura Advisory - This advisory describes five vulnerabilities in the Armatura LLC Armatura One web-based security platform. The vulnerabilities were reported to CISA by Andrew Capobianco of RewCon.co. One of the vulnerabilities is included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog. 

Updates  

CISA Update  

This update provides additional information on the Malcolm advisory that was originally published on September 11th, 2026. The new information includes adding self-reference to Web version. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-fd7 - subscription required. 

Review – Bills Introduced – 9-29-26

On Tuesday, with just the Senate in session, there were 44 bills introduced. Two of those bills would receive additional coverage of the blog: 

S 5576 A bill to establish the Artificial Intelligence Safety Board, and for other purposes. Warner, Mark R. [Sen.-D-VA]    

S 5590 A bill to require the Secretary of Defense to submit a plan to identify, prioritize, and remediate the presence of certain equipment and computational facilities owned or controlled by a foreign adversary in the electric grid of the United States, and for other purposes. Banks, Jim [Sen.-R-IN]    


For more information on these bills, including legislative history for similar bills in the 118th Congress, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-29-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */