Friday, October 9, 2026

Review- HR 10671 Introduced – Vulnerability Warning

Last week, Rep Gottheimer (D,NJ) introduced HR 10671, the Securing Our Critical Infrastructure Act. The bill would reinstate and revise a recently expired CISA ransomware notification program to turn it into a program to notify small water utilities of known vulnerabilities. No new funding is authorized. 

This bill would amend §105, Ransomware Vulnerability Warning Pilot Program, of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Division Y of PL 117-103, 136 STAT. 1055). The authorization for that program {§105(g)} terminated on March 15th, 2026. That program was codified at 6 USC 652 Note. 

Moving Forward  

Neither Gottheimer, nor any of his four cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for consideration. This means that it is unlikely that there will be sufficient influence to see the bill considered by that Committee. Without additional spending for CISA to fund this new program, there is no way that the Agency would have enough personnel to support these new requirements. I suspect that common knowledge of that fact will ensure that there would be minimal Republican support for this legislation, if it were to be considered. 

Commentary 

This is an unusual solution to the problem of vulnerabilities in water treatment facilities. It assumes that the problem facing these facilities is lack of knowledge about the vulnerabilities in their systems. However, even if that is true (a topic for another day), I am pretty sure that setting up this program in CISA is not the way to go. Most importantly, why should CISA focus such efforts on water systems when they are not the Sector Specific Agency responsible for that sector. The appropriate SSA would be the Environmental Protection Agency (EPA). 


For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-10671-introduced-vulnerability - subscription required. 

Chemical Transportation Incidents – Week of 9-5-26

Reporting Background 

See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

  • Number of incidents – 461 (430 highway, 30 air, 1 rail, 0 water) 
  • Serious incidents – 1 (0 Bulk release, 1 evacuation, 1 injury, 0 death, 0 major artery closed, 1 fire/explosion, 26 no release)  
  • Largest container involved – 33,894-gal DOT 111A100W1 Railcar {Sodium Hydroxide, Solution} Liquid (top?) valve open, cap not tool tight. 
  • Largest amount spilled – 75-gal Plastic IBC {Toxic Liquids, Organic, N.O.S.} Reaction during transit caused heat and overpressure in one IBC. 
  • Total amount reported spilled in all incidents – 1012.4-gal 

NOTE: Links above are to Form 5800.1 for the incident described. 

Most Interesting Chemical: Isophoronediamine: A clear to light-yellow liquid. Highly soluble though slightly denser than water. May be toxic by inhalation and skin absorption. Corrosive to skin. Used to make other chemicals. (Source: CameoChemicals.NOAA.gov).  


INSERT UN 2289 Placard 

Thursday, October 8, 2026

Review – 3 Advisories and 3 Updates Published – 10-8-26

Today CISA’s NCCIC-ICS published three control system security advisories for products from Satel, Grid Protection Alliance, and Red Lion. They also updated two control system advisories for products from Hitachi Energy and Lantronix, as well as a medical device advisory for products from Pulsetto. 

Advisories  

Satel Advisory - This advisory describes four vulnerabilities in the Satel Netco Design software tool. The vulnerability was reported to CISA by Alex Williams of Pellera Technologies. 

Grid Protection Advisory - This advisory describes six vulnerabilities in the Grid Protection Alliance openPDC and openHistorian products. The vulnerabilities were reported to CISA by Shubham Raj (Cipher) of Causal Security. 

Red Lion Advisory - This advisory describes seven vulnerabilities in the Red Lion Controls N-Tron 700 Series. The vulnerabilities were reported to CISA by Gabrianna (Ria) Milloway of Idaho National Laboratory. 

Updates  

Hitachi Energy Update - This update provides additional information on the RTU500 Series advisory that was originally published on September 16th, 2025. The new information included updating fixed version 12.7.8. 

Lantronix Update - This update provides additional information on the EDS3000PS advisory that was originally published on March 10th, 2026, and most recently updated on August 25th, 2026. The new information includes updating CVE information. 

Pulsetto Update - This update provides additional information on the Vagus Nerve Stimulator advisory that was originally published on August 11th, 2026. The new information includes updating Risk Evaluation, Affected Products and versions, and mitigation information. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-3-updates-published-ee4 - subscription required. 

Short Takes – 10-8-26 – Federal Register Edition

Advisory Committee Meetings  

Office of Science Advisory Committee. DOE open meeting notice. Summary: “The purpose of the committee is to provide advice and guidance on a continuing basis to the Under Secretary for Science, the Office of Science (SC), and the Department of Energy on a variety of complex scientific and technical issues that arise in the planning, management, and implementation of the Office of Science research programs.” 

Public Meeting of the Clean Air Scientific Advisory Committee (CASAC) on Oxides of Nitrogen. EPA meeting notice. Summary: “The CASAC shall also: advise the EPA Administrator of areas in which additional knowledge is required to appraise the adequacy and basis of existing, new, or revised NAAQS; describe the research efforts necessary to provide the required information; advise the EPA Administrator on the relative contribution to air pollution concentrations of natural as well as anthropogenic activity; and advise the EPA Administrator of any adverse public health, welfare, social, economic, or energy effects which may result from various strategies for attainment and maintenance of such NAAQS. As amended, 5 U.S.C., App. Section 109(d)(1) of the Clean Air Act (CAA) requires that EPA carry out a periodic review and revision, as appropriate, of the air quality criteria and the NAAQS for the six “criteria” air pollutants, including oxides of nitrogen.” 

Automated Driving Systems  

NHTSA Safety Research Portfolio Public Meeting: Fall 2026, and Automated Driving Systems Workshop. NHTSA meeting notice. Summary: “The National Highway Traffic Safety Administration (NHTSA) will hold a public meeting on December 1-2, 2026, to provide updates and insights into ongoing activities across NHTSA's safety research programs. The meeting will be held in-person and will feature panel presentations and research posters by representatives from the Offices of Vehicle Safety Research and Behavioral Safety Research. Each research panel will conclude with an opportunity for the audience to ask technical questions related to the presented materials. Visual slides used in presentations and posters will be made available in the public docket following the public meeting. The event will not be live streamed; however, panel presentations will be recorded and made available on the NHTSA website after the event. On the afternoon of the first day, Tuesday, December 1, the Agency will also convene an Automated Driving Systems (ADS) Workshop organized by the Office of Automation Safety. The ADS Workshop will not be recorded.” 

Area Maritime Security 

Area Maritime Security Advisory Committee (AMSC), Eastern Great Lakes, Western New York; Sub-Committee Vacancy. CG vacancy announcement. Summary: “The Coast Guard is accepting applications to fill one vacancy on the Area Maritime Security Committee, Eastern Great Lakes, Western New York Region Sub-Committee (Sub-Committee). The Area Maritime Security Committee assists the Captain of the Port as the Federal Maritime Security Coordinator (FMSC), Buffalo, in developing, reviewing, and updating the Area Maritime Security Plan for their area of responsibility.” 

 
/* Use this with templates/template-twocol.html */