Friday, September 11, 2026

Chemical Transportation Incidents – Week of 8-8-26

Reporting Background See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

  • Number of incidents – 596 (561 highway, 28 air, 6 rail, 1 water) 
  • Serious incidents – 4 (4 Bulk release, 0 evacuation, 0 injury, 0 death, 0 major artery closed, 2 fire/explosion, 30 no release)  
  • Largest container involved – 33,920-gal DOT 117J100W Railcar {Petroleum Gases, Liquefied or Liquefied Petroleum Gas} B-End liquid valve had been left partially cracked open and the liquid line plug was found to be less than tool-tight. 
  • Largest amount spilled – 2,087.3-gal ISO Tank {Carbon Dioxide, Refrigerated Liquid} Partially open valve. 
  • Total amount reported spilled in all incidents – 6249.4-gal 

NOTE: Links above are to Form 5800.1 for the incident described. 

Most Interesting Chemical: Carbon Dioxide, Refrigerated Liquid: A colorless liquid. Relatively heavier than air and can asphyxiate by the displacement of air. Under prolonged exposure to heat or fire the container may rupture violently and rocket. Used as a refrigerant and in making carbonated beverages. Used to freeze food, to control chemical reactions and as a fire extinguishing agent. (Source: CameoChemicals.NOAA.gov).  



CISA Adds 2 MikroTik Vulnerabilities to KEV Catalog – 9-10-26

Yesterday, CISA announced that it was adding two vulnerabilities in the MikroTik OS to their Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: 

MikroTik reported both vulnerabilities on September 3rd, 2026. The two vulnerabilities were among six initially reported by SÅ‚awomir Rozbicki from CERT Polska, with fixed versions available. CERT Polska subsequently reported active exploitation in the wild on September 5th, citing proof-of-concept code developed by Nick Pratley using version diff analysis. 

Based upon the CERT Polska reports the following vulnerabilities may also end up being added to the KEV catalog: 

  • Improper verification of cryptographic signature - CVE-2026-67276, CVE-2026-67278,  
  • Improper enforcement of behavioral workflow - CVE-2026-67279, and 
  • Path traversal - CVE-2026-67281 

CISA has directed federal agencies using the affected products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

CISA has established a compliance date of September 13th, 2026. 

Thursday, September 10, 2026

Review – 3 Advisories and 1 Update Published – 9-10-26

Today CISA’s NCCIC-ICS published one control system security advisory for products from AVEVA, and two medical device security advisories for products from Orthanc and NextGen. They also updated a control system advisory for products from ST Engineering. 

Advisories  

Aveva Advisory - This advisory describes four vulnerabilities in the AVEVA Pipeline Integrity Monitor. Two of the vulnerabilities were reported by Adham Khairy Ramadan via HackerOne. 

Orthanc Advisory - This advisory describes an integer overflow or wraparound vulnerability in the Orthanc DICOM Server. The vulnerability was reported to CISA by Andrej Tomci 

NextGen Advisory - This advisory describes three vulnerabilities in the NextGen Healthcare Mirth Connect. The vulnerabilities were reported to CISA by Abhinav Agarwal  

Updates  

ST Engineering Update - This update provides additional information on the iDirect iQ-Series Terminals advisory that was originally on July 2nd, 2026. The new information includes adding two vulnerabilities. 


For more information on these advisories, including DTRH looks at exploits in the wild and POC, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-091 - subscription required. 

Review - S 5067 Introduced – Cybersecurity Training

Back in July, Sen Hassan (D,NH) introduced S 5067, the Federal Cybersecurity Workforce Expansion Act. It would require CISA to establish an apprenticeship program that would lead to cybersecurity related employment with CISA or other Federal entity. The bill would also require the Veterans Administration to establish a pilot program providing cyber-specific training for eligible individuals. There is no funding authorized in the legislation. 

S 5067 is very similar to S 2256, the Federal Cybersecurity Workforce Expansion Act, that was introduced by Hassan in July 2023. The Senate Homeland Security and Governmental Affairs Committee held a business meeting on July 26th, 2023, and ordered the bill reported favorably by a vote of 7 to 1 {Sen Paul (R,KY) voting NAY}. No further action was taken on the bill in the 118th Congress. A similar bill, HR 6524, was introduced in the Housse by Rep Houlahan (D,PA) in November of 2023. No action was taken on that bill in the House. 

Moving Forward 

Hassan is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. That means that there may be enough influence to see this bill considered by the Committee. Having said that, because the current Chair of the Committee, Sen Paul (R,KY), voted against a nearly identical bill last session, it is unlikely that S 5067 will be considered in this session. 

Commentary 

While this bill does not directly address control system security issues, increasing the cybersecurity qualified staffing of CISA is certainly of interest to the ICS security community. While the training programs established under this bill would be targeted at future CISA employment, they should result in a net increase to the nation’s cybersecurity workforce. 


For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5067-introduced-cybersecurity-training-b39 - subscription required. 

 
/* Use this with templates/template-twocol.html */