Monday, September 14, 2026

Review - HR 10151 Introduced – Water System Assistance

Last month, Rep Deluzio (D,PA) introduced HR 10151, the Water Authority Cybersecurity Protection Act. The bill would amend 42 USC 300i-2(g), Technical assistance and grants, increasing the amounts available to the EPA for grants under subsections (4) and (5), increasing the amounts authorized for the Drinking Water Infrastructure Risk and Resilience Program, and extend the authorization for that program through 2029. 

This bill is essentially the same as HR 10389, the Water Authority Cybersecurity Protection Act, that was introduced by Deluzio in December 2024. That bill was introduced even later in the 118th Congress, and no action was taken. According to a press release from Deluzio’s office: 

“Any attack on our nation’s critical infrastructure is unacceptable, and the 2023 Iranian hack in Western Pennsylvania should have been a major wake-up call for our federal government,” said Congressman Deluzio. “Especially while the Iran War continues, we need to make sure our local water authorities have the resources and training they need to defend against cyber threats from the Iranians and others. Residents should be able to trust that their drinking water is safe from attacks. I am proud to reintroduce the Water Authority Cybersecurity Protection Act to help local leaders better secure our water system.” 

Moving Forward  

Neither Deluzio nor his sole cosponsor, Rep Finstad (R,MN), are members of the Energy and Commerce Committee to which this bill was assigned for consideration. This means that there will probably not be sufficient influence to see the bill considered by that Committee. While the increased funding would typically be considered an anathema to many Republicans, the recent spate of purported Iranian attacks on public water systems in this country, might outweigh the spending concerns in some members. While I would expect some level of bipartisan support if this bill was considered, I do not think that there would be enough support to allow the bill to be successfully considered under the suspension of the rules process. 


For more information on the provisions of this bill, as well as commentary on EPA grants for water system cybersecurity, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-10151-introduced-water-system - subscription required. 

Saturday, September 12, 2026

Short Takes – 9-12-26 - Federal Register Edition

RCRA Testing  

Request for Information on Test Methods for Evaluating Solid Waste (SW-846), Waste Sampling and Toxicity Characteristic Leaching Procedure (TCLP) Testing. EPA request for information. Summary: “EPA updates test methods and waste sampling guidance as part of routine updates according to the Resource Conservation and Recovery Act (RCRA). To aid in the implementation of these directives, the Office of Resource Conservation and Recovery (ORCR) within the Environmental Protection Agency (EPA) requests information on SW-846 method experiences, needs, and requirements. ORCR is specifically interested in information on the Toxicity Characteristic Leaching Procedure (TCLP) Method 1311, including method challenges, and alternatives. Information is welcome from stakeholders involved in requesting, performing, and evaluating the results from SW-846 methods including, but not limited to, industry stakeholders, researchers, academia, state, Tribal, and local governments. This includes U.S. territories and the District of Columbia, other federal agencies, community groups, non-governmental organizations, the public, and international organizations. The EPA will use the information received in response to this request for information (RFI) to inform what action, if any, it may take. 

Space Geek  

Name of Information Collection: Proposal Submissions and Awards Management System (ProSAMS) for the NASA Small Business Innovation Research/Small Business Technology Transfer (SBIR/STTR) program Solicitations. NASA 30-day new information collection request notice. Summary: “The Small Business Innovation Research (SBIR) program is a highly competitive program that encourages domestic small businesses to engage in Federal Research/Research and Development (R/R&D) that has the potential for commercialization.... The Small Business Technology Transfer (STTR) is another program that expands funding opportunities in the federal innovation research and development (R&D) arena. 

Executive Orders  

EO 14426 - Accelerating Access to Veterans' Benefits and Employment Opportunities. 

EO 14427 - Adjusting Certain Delegations Under the Defense Production Act. 

OMB Approves EPA Facility Response Delay Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had approved a final rule from the EPA on “Clean Water Act Hazardous Substance Facility Response Plans: Compliance Date Delay and Changes to Reflect Administration Policy”. The notice of proposed rulemaking for this action was published on March 5th, 2026. This final rule was sent to OIRA on July 1st, 2026. 

According to the 2026 Unified Agenda entry for this rulemaking:  

“The Clean Water Act (CWA) Section 311(j)(5) provides that regulations shall be issued "which require an owner or operator of a tank vessel or facility ... to prepare and submit ... a plan for responding, to the maximum extent practicable, to a worst-case discharge, and to a substantial threat of such a discharge, of a hazardous substance." The Environmental Protection Agency (EPA) published a final rule in March 2024 to require planning for worst case discharges of CWA hazardous substances under section 311(j)(5)(A). Section 3 of the January 20, 2025, Executive Order 14154 Unleashing American Energy requires an immediate review of agency actions to identify those that may impose an undue burden on the identification, development, or use of domestic energy resources. As EPA considers options, the agency is proposing to extend the compliance date and make administrative changes” 

NOTE: OIRA classifies this as a ‘deregulatory action under EO 14192. 

Friday, September 11, 2026

Chemical Transportation Incidents – Week of 8-8-26

Reporting Background See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

  • Number of incidents – 596 (561 highway, 28 air, 6 rail, 1 water) 
  • Serious incidents – 4 (4 Bulk release, 0 evacuation, 0 injury, 0 death, 0 major artery closed, 2 fire/explosion, 30 no release)  
  • Largest container involved – 33,920-gal DOT 117J100W Railcar {Petroleum Gases, Liquefied or Liquefied Petroleum Gas} B-End liquid valve had been left partially cracked open and the liquid line plug was found to be less than tool-tight. 
  • Largest amount spilled – 2,087.3-gal ISO Tank {Carbon Dioxide, Refrigerated Liquid} Partially open valve. 
  • Total amount reported spilled in all incidents – 6249.4-gal 

NOTE: Links above are to Form 5800.1 for the incident described. 

Most Interesting Chemical: Carbon Dioxide, Refrigerated Liquid: A colorless liquid. Relatively heavier than air and can asphyxiate by the displacement of air. Under prolonged exposure to heat or fire the container may rupture violently and rocket. Used as a refrigerant and in making carbonated beverages. Used to freeze food, to control chemical reactions and as a fire extinguishing agent. (Source: CameoChemicals.NOAA.gov).  



CISA Adds 2 MikroTik Vulnerabilities to KEV Catalog – 9-10-26

Yesterday, CISA announced that it was adding two vulnerabilities in the MikroTik OS to their Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: 

MikroTik reported both vulnerabilities on September 3rd, 2026. The two vulnerabilities were among six initially reported by SÅ‚awomir Rozbicki from CERT Polska, with fixed versions available. CERT Polska subsequently reported active exploitation in the wild on September 5th, citing proof-of-concept code developed by Nick Pratley using version diff analysis. 

Based upon the CERT Polska reports the following vulnerabilities may also end up being added to the KEV catalog: 

  • Improper verification of cryptographic signature - CVE-2026-67276, CVE-2026-67278,  
  • Improper enforcement of behavioral workflow - CVE-2026-67279, and 
  • Path traversal - CVE-2026-67281 

CISA has directed federal agencies using the affected products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

CISA has established a compliance date of September 13th, 2026. 

 
/* Use this with templates/template-twocol.html */