Wednesday, August 12, 2026

OMB Approves Direct-to-Device NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the FCC on “Unleashing Unlicensed Spectrum for Direct-to-Device”. The NPRM was sent to OMB yesterday. 

According to the 2026 Unified Agenda entry for this rulemaking: 

“As space launches and satellite deployment continue to increase, companies with space-based operations are increasingly looking to expand capacity, reduce cost, and increase the utility of their operations.  The increase in space launches, coupled with the growing diversity of non-satellite spacecraft, has resulted in a growing need to support communication in space and between Earth and space. To meet this growing need, the Commission begins this proceeding to explore unlicensed device use in space.” 

I do not expect to cover this rulemaking in any detail, but it will get mentioned in the appropriate Short Takes post as part of my limited Space Geek coverage. 

Tuesday, August 11, 2026

S 5329 Introduced – Space Domain Control

Last week, Sen Cortez Masto (D,NV) introduced S 5329, the Space Superiority Readiness Act of 2026. The bill would require DOD to expand the capacity of the Space Force to conduct wargaming, modeling, and simulation of peer conflict scenarios in the space domain, and to develop training programs for space operators focused on tactics, techniques, and procedures necessary for space control operations. No new funding would be authorized by this bill. 

Moving Forward  

Neither Cortez Masto, nor her sole cosponsor, Sen Britt (R,AL) are members of the Senate Armed Services Committee to which this bill is assigned for consideration. Typically, this means that there will probably not be sufficient influence to see this bill covered in the Committee. I do not see anything in this short bill that would engender any organized opposition. I suspect that if it were to be considered by the Committee, there would be substantial bipartisan support for the bill. 

Review – 2 Advisories and 1 Update Published – 8-11-26

Today CISA’s NCCIC-ICS published two medical device security advisories for products from Mira and Pulsetto. They also updated a control system security advisory for products from Johnson Controls. 

Advisories  

Mira Advisory - This advisory describes eight vulnerabilities in the (Quanovate Tech) Mira Hormone Monitor and Mira Android App. 

Pulsetto Advisory - This advisory describes a hidden functionality vulnerability in the Pulsetto Vagus Nerve Stimulator. 

Updates 

Johnson Controls Update - This update provides addition information on the C-CURE 9000 advisory that was originally published on July 23rd, 2026 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-4db - subscription required. 

Short Takes – 8-11-26 - Federal Register Edition

Information Collection Requests  

Proposed Renewal Collection and Request for Comment; Generic Clearance for TSCA Section 4 Test Rules, Test Orders, Enforceable Consent Agreements (ECAs), Voluntary Data Submissions, and Exemptions From Testing Requirement (Renewal). EPA 60-day ICR renewal. Summary: “This ICR covers the information collection activities associated with the submission of information to EPA pursuant to TSCA section 4 regulatory actions. (15 U.S.C. 2603). Under TSCA, EPA has the authority to issue regulatory actions designed to gather or develop health and safety information and exposure information on chemical substances and mixtures, and to control unreasonable risks associated with new and existing chemical substances. TSCA section 4 authorities allow EPA to require the development of information related to chemicals and the use of prescribed “protocols and methodologies” in order to inform EPA and other federal agencies about chemical risks, which in turn will inform decision makers for purposes of prioritization for risk evaluation, risk evaluation and risk management of those chemicals as necessary. 

Submission to the Office of Management and Budget for Review and Approval; Comment Request; Cybersecurity and Infrastructure Security Agency Vulnerability Assessments. CISA 60-day ICR renewal. Summary: “The information will be voluntarily provided by the organizations to Cybersecurity and Infrastructure Security Agency Protective Security Advisors and Cybersecurity Security Advisors. The Protective Security Advisors and Cybersecurity Advisors will then visit the site and perform the assessment, as requested. They then return to complete the vulnerability assessment and input the data into the system where the data is then accessible by the system users. Once available, the organization and other relevant system users can then review the data and use it for planning, risk identification, mitigation, and decision making.” 

Executive Orders  

EO 14418 - Continuing to Protect the Meaning and Value of American Citizenship. 

EO 14419 - Ending Birth Tourism. 

Monday, August 10, 2026

Looking Back – 12-29-14 - Damn Vulnerable Chemical Process

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from December 2014, Damn Vulnerable Chemical Process, showed up on the list. It looks at an important presentation made by a young Ukrainian [not German as I said in the post] researcher, Marina Krotofil. The original video link is, of course, dead, but there is a new You-tube video up of the presentation. Her presentation still holds up today. 

I have an interesting follow-up post about the discussion that resulted from that presentation. 

I met Marina at a meeting in Atlanta a few years ago. She was a delightful young lady and had a bright future in the OT Cybersecurity field. Unfortunately, in 2022, she found it necessary to defer her cybersecurity work, to help her homeland resist the Russian invaders. I wish her well and hope she is able to return to her international cybersecurity work. 

Saturday, August 8, 2026

Review – Bills Introduced – 8-7-26

Yesterday, with the Senate in Washington and preparing to leave for 5 weeks, there were 32 bills introduced. Two of those bills may receive additional coverage in this blog:  

  • S 5360 A bill to amend the Infrastructure Investment and Jobs Act to reauthorize the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program, and for other purposes. McCormick, David [Sen.-R-PA]    
  • S 5368 A bill to amend the Safe Drinking Water Act and the Federal Water Pollution Control Act to establish or modify cybersecurity requirements for drinking water and wastewater systems, and for other purposes. Schiff, Adam B. [Sen.-D-CA]    


For more information on these bills, including legislative history for similar bills in the 118th Congress, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-8-7-26 - subscription required. 

S 434 Passed in Senate - Space Commerce Advisory Committee Act

 On Thursday, the Senate took up S 434, the Space Commerce Advisory Committee Act, under the unanimous consent process. After adopting substitute language, the amended bill was passed by unanimous consent. The bill would require the DOC’s Office of Space Commerce to establish a Commercial Space Activity Advisory Committee. 


 
/* Use this with templates/template-twocol.html */