Thursday, August 13, 2026

Review - CSB Updated the Status of 6 Investigation Recommendations – 8-6-26

Yesterday, the Chemical Safety Board (CSB) updated their Recent Recommendation Status Updates page, closing three recommendations with acceptable action, one with exceeds recommended actions, and one with acceptable alternative actions. These actions left 127 of 1059 recommendations open. Additionally, the CSB updated the open status of one recommendation. The CSB took all of these actions on August 6th, 2026. The previous update was published on July 10th, 2026. 

The number recently closed recommendations are: 

  • Foundation Food Group Fatal Chemical Release - 2021-03-I-GA-R2 - Messer LLC, 
  • Foundation Food Group Fatal Chemical Release - 2021-03-I-GA-R3 - Messer LLC, 
  • Didion Milling Company Explosion and Fire - 2017-07-I-WI-R3 - Didion Milling, Inc., 
  • Didion Milling Company Explosion and Fire - 2017-07-I-WI-R8 - Didion Milling, Inc., and 
  • Givaudan Sense Colour Explosion - 2024-06-I-KY-R12 - Corn Refiners Association. 

The Board separately reported that Didion Milling has now implemented all nine of the recommendations made in the Board’s report on their investigation of the fatal May 2017 explosion at Didion’s Cambria, Wisconsin, facility. 


For more information on the investigation responses, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/csb-updated-the-status-of-6-investigation-22f - subscription required. 

Wednesday, August 12, 2026

Review - NIST Publishes RFI for Updating NVD for AI

Today, DOC’s National Institute of Standards and Technology (NIST) published a request for information (RFI) on “Modernizing the National Vulnerability Database in the Age of Artificial Intelligence”. NIST is looking for input from the cybersecurity community on how the NVD can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility. 

According to the document summary: 

“The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.” 

Public Feedback  

NIST is requesting public feedback on, and answers to, the provided questions. NIST is requesting that those public responses be submitted via the Federal eRulemaking Portal (www.Regulations.gov; docket # NIST-2026-0100). Comments should be submitted by October 13th, 2026. 


For more details about the questions proposed, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-rfi-for-updating-nvd - subscription required. 

OMB Approves Direct-to-Device NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the FCC on “Unleashing Unlicensed Spectrum for Direct-to-Device”. The NPRM was sent to OMB yesterday. 

According to the 2026 Unified Agenda entry for this rulemaking: 

“As space launches and satellite deployment continue to increase, companies with space-based operations are increasingly looking to expand capacity, reduce cost, and increase the utility of their operations.  The increase in space launches, coupled with the growing diversity of non-satellite spacecraft, has resulted in a growing need to support communication in space and between Earth and space. To meet this growing need, the Commission begins this proceeding to explore unlicensed device use in space.” 

I do not expect to cover this rulemaking in any detail, but it will get mentioned in the appropriate Short Takes post as part of my limited Space Geek coverage. 

Tuesday, August 11, 2026

S 5329 Introduced – Space Domain Control

Last week, Sen Cortez Masto (D,NV) introduced S 5329, the Space Superiority Readiness Act of 2026. The bill would require DOD to expand the capacity of the Space Force to conduct wargaming, modeling, and simulation of peer conflict scenarios in the space domain, and to develop training programs for space operators focused on tactics, techniques, and procedures necessary for space control operations. No new funding would be authorized by this bill. 

Moving Forward  

Neither Cortez Masto, nor her sole cosponsor, Sen Britt (R,AL) are members of the Senate Armed Services Committee to which this bill is assigned for consideration. Typically, this means that there will probably not be sufficient influence to see this bill covered in the Committee. I do not see anything in this short bill that would engender any organized opposition. I suspect that if it were to be considered by the Committee, there would be substantial bipartisan support for the bill. 

Review – 2 Advisories and 1 Update Published – 8-11-26

Today CISA’s NCCIC-ICS published two medical device security advisories for products from Mira and Pulsetto. They also updated a control system security advisory for products from Johnson Controls. 

Advisories  

Mira Advisory - This advisory describes eight vulnerabilities in the (Quanovate Tech) Mira Hormone Monitor and Mira Android App. 

Pulsetto Advisory - This advisory describes a hidden functionality vulnerability in the Pulsetto Vagus Nerve Stimulator. 

Updates 

Johnson Controls Update - This update provides addition information on the C-CURE 9000 advisory that was originally published on July 23rd, 2026 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-4db - subscription required. 

Short Takes – 8-11-26 - Federal Register Edition

Information Collection Requests  

Proposed Renewal Collection and Request for Comment; Generic Clearance for TSCA Section 4 Test Rules, Test Orders, Enforceable Consent Agreements (ECAs), Voluntary Data Submissions, and Exemptions From Testing Requirement (Renewal). EPA 60-day ICR renewal. Summary: “This ICR covers the information collection activities associated with the submission of information to EPA pursuant to TSCA section 4 regulatory actions. (15 U.S.C. 2603). Under TSCA, EPA has the authority to issue regulatory actions designed to gather or develop health and safety information and exposure information on chemical substances and mixtures, and to control unreasonable risks associated with new and existing chemical substances. TSCA section 4 authorities allow EPA to require the development of information related to chemicals and the use of prescribed “protocols and methodologies” in order to inform EPA and other federal agencies about chemical risks, which in turn will inform decision makers for purposes of prioritization for risk evaluation, risk evaluation and risk management of those chemicals as necessary. 

Submission to the Office of Management and Budget for Review and Approval; Comment Request; Cybersecurity and Infrastructure Security Agency Vulnerability Assessments. CISA 60-day ICR renewal. Summary: “The information will be voluntarily provided by the organizations to Cybersecurity and Infrastructure Security Agency Protective Security Advisors and Cybersecurity Security Advisors. The Protective Security Advisors and Cybersecurity Advisors will then visit the site and perform the assessment, as requested. They then return to complete the vulnerability assessment and input the data into the system where the data is then accessible by the system users. Once available, the organization and other relevant system users can then review the data and use it for planning, risk identification, mitigation, and decision making.” 

Executive Orders  

EO 14418 - Continuing to Protect the Meaning and Value of American Citizenship. 

EO 14419 - Ending Birth Tourism. 

 
/* Use this with templates/template-twocol.html */