Friday, December 5, 2025

Review - Bills Introduced – 12-4-25

Yesterday, with both the House and Senate in Washington, there were 115 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 6429 To establish in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security a program to promote the cybersecurity field to disadvantaged communities, including older individuals, racial and ethnic minorities, people with disabilities, geographically diverse communities, socioeconomically diverse communities, women, individuals from nontraditional educational paths, individuals who are veterans, and individuals who were formerly incarcerated, and for other purposes. Brown, Shontel M. [Rep.-D-OH-11]

HR 6460 To amend title 49, United States Code, to clarify exceptions for limited recreational operations of unmanned aircraft, and for other purposes. Mann, Tracey [Rep.-R-KS-1]

 

For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a brief look at two anti-scam bills, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-12-4-25 - subscription required.

Chemical Transportation Incidents – Week of 11-1-25

Reporting Background

See this post for explanation, with the most recent update here (removed from paywall).

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.

Incidents Summary

• Number of incidents – 497 (464 highway, 29 air, 4 rail, 0 water)

• Serious incidents – 6 (1 Bulk release, 1 evacuation, 1 injury, 0 death, 1 major artery closed, 5 fire/explosion, 28 no release)

• Largest container involved – 28,480-gal DOT 117J100W Railcar {Petroleum Crude Oil} Manway bolts not tool tight.

• Largest amount spilled – 225-gal Plastic IBC {Sulfuric Acid With Not More Than 51% Acid} IBC fell.

• Total amount reported spilled in all incidents – 1619.7-gal

NOTE: Links above are to Form 5800.1 for the described incidents.

Most Interesting Chemical: Petroleum Crude Oil: A complex mixture of aliphatic and aromatic hydrocarbons containing low percentages of sulfur and trace amounts of nitrogen and oxygen compounds. A black sticky liquid with a strong hydrocarbon odor. (Source: CameoChemicals.NOAA.gov).

 


Short Takes – 12-5-25 – Federal Register Edition

Assessment Framework and Organizational Restatement Regarding Preemption for Certain Regulations Issued by the Coast Guard. Federal Register CG NPRM withdrawal. Summary: “The Coast Guard is withdrawing the proposed rule entitled “Assessment Framework and Organizational Restatement Regarding Preemption for Certain Regulations Issued by the Coast Guard,” published [link added] in the Federal Register on December 27, 2013. The Coast Guard is withdrawing the proposed rule because our practice of discussing the preemptive effect of the Coast Guard's legal authorities and regulations in the preamble of our rulemaking documents is sufficient to identify any preemptive effects.”

Request for Information (RFI) on Partnerships for Transformational Artificial Intelligence Models. Federal Register DOE request for information. Summary: “The U.S. Department of Energy (DOE) invites public comment on its Request for Information (RFI) regarding Partnerships for Transformational Artificial Intelligence Models. The purpose of this RFI is to solicit feedback from industry, think tanks, investors, research organizations, and other stakeholders on how DOE should best structure and enable partnerships to curate DOE scientific data across the National Laboratory complex for use in artificial intelligence (AI) models. This RFI also seeks input on using this data to develop self-improving AI models for science and engineering to advance scientific discovery, energy, and national security.” Comments due January 14th, 2026.

Space Modernization for the 21st Century. Federal Register FCC notice of proposed rulemaking. Summary: “In the Notice of Proposed Rulemaking (NPRM), the Federal Communications Commission (Commission or we) proposes to overhaul and modernize the Commission's space and earth station licensing process to help “ensure that new space-based industries, space exploration capabilities, and cutting-edge defense systems are pioneered in America rather than by our adversaries.” In particular, the NPRM proposes to develop a “licensing assembly line” designed so applications can be routed along different paths and segmented for review based on specific aspects of a request. This new process would set the stage for ongoing efficiency gains and would provide greater predictability and flexibility for applicants. In this way, we expect—like actual assembly lines—that the space review processes can be dramatically accelerated while improving the quality of the Commission's space licensing work.” Comments due January 20th, 2026.

Privacy Act of 1974; System of Records. Federal Register NASA notice of a modified system of records. Summary: “In accordance with the requirements of the Privacy Act of 1974, the National Aeronautics and Space Administration is providing public notice of a modification to an existing system of records entitled NASA Core Financial Management Records (CFMR). The notice updates the Routine Use section to include two additional routine uses . The system of records is more fully described in the SUPPLEMENTARY INFORMATION section of this notice.”

Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program. Federal Register FCC notice of proposed rulemaking. Summary: “In this document, the Federal Communications Commission (Commission or FCC) aims to further its actions in strengthening prohibitions on authorization of covered equipment and to clarify the rules and enforcement of such. The Commission seeks additional comment on modular transmitters and component parts in relation to covered equipment. The Commission addresses the partial court remand of the decision in its November 2022 EA Security R&O by proposing a definition of “critical infrastructure” as used on the Covered List and seeking comment on the implementation of that definition. The Commission also seeks comment on whether any modification to an authorized device by an entity identified on the Covered List should require a new application for certification. Finally, the Commission seeks comment on clarifying the scope of activities that constitute marketing of equipment and on measures to strengthen enforcement of marketing prohibitions.” Comments due January 6th, 2026.

Thursday, December 4, 2025

Review – 7 Advisories and 2 Updates Published – 12-4-25

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Advantech, Solis Cloud, Sunbird, Johnson Controls (2), MAXHIB, and Mitsubishi. They also updated advisories for products from Johnson Controls and Consilium.

Advisories

Advantech Advisory - This advisory describes an SQL injection vulnerability in the Advantech iView product.

SolisCloud Advisory - This advisory describes an authorization bypass through a user controlled key vulnerability in the SolisCloud Monitoring Platform.

Sunbird Advisory - This advisory describes two vulnerabilities in the Sunbird DCIM dcTrack and Power IQ products.

Johnson Controls Advisory #1 - This advisory describes an improper validation of certificate expiration vulnerability in the Johnson Controls iStar products.

Johnson Controls Advisory #2 - This advisory describes a forced browsing vulnerability in the Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace.

MAXHUB Advisory - This advisory describes a weak password recovery mechanism for forgotten password vulnerability in the MAXHUB Pivot client.

Mitsubishi Advisory - This advisory describes a cleartext storage of sensitive information vulnerability in the Mitsubishi GX Works2 product.

NOTE: I briefly discussed this vulnerability on November 29th, 2025.

Updates

Johnson Control Update - This update provides additional information on the FX80 and FX90 advisory that was originally published on August 7th, 2025.

Consilium Update - This update provides additional information on the CS5000 Fire Panel advisory that was originally published on May 29th, 2025.

NOTE: The original CISA advisory noted that no fix was planned for these vulnerabilities. See my May 29th, 2025, post for more information.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-67d - subscription required.

Review – HR 2707 Introduced – Anthrax Strategy

Back in April Rep Davis (D,NC) introduced HR 2707, the Protecting American Families and Servicemembers from Anthrax Act. The bill would require the Department of Health and Human Services (HHS) and the DOD to develop a modernized 10-year strategy for ensuring sustained stockpiling of anthrax countermeasures. No new funding is authorized in this legislation.

Moving Forward

Davis, and 13 of his 17 cosponsors, are members of the House Armed Services Committee to which this bill was assigned primary consideration of this bill. This means that there may be sufficient influence to see the bill considered in Committee. I can see nothing in this bill that would engender any organized opposition to the bill, and I suspect that it would receive some level of bipartisan support, perhaps enough to be considered by the full House under the suspension of the rules process.

Commentary

DHS is an integral part of the threat analysis process set forth in 42 U.S.C. 247d–6b(a) that establishes the countermeasure requirements in the Strategic National Stockpile. Thus, the failure to include DHS in the ‘covered Secretaries’ definition seems odd until you realize that including them would have required, in turn, that the House Homeland Security Committee would have to have been added to the list of Committee that would have to sign off on the bill.

 

For more information on the provisions of this bill, and additional commentary on the inclusion of DOD stockpile requirements, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-2707-introduced-anthrax-strategy - subscription required.

CISA Adds OpenPLC ScadaBR vulnerability to KEV Catalog - 12-3-25

Yesterday CISA announced that it had added an unrestricted upload of files with dangerous type vulnerability in the “OpenPLC ScadaBR” product. The vulnerability was previously disclosed by ScadaBR along with a cross-site scripting vulnerability that CISA had already added to the KEV catalog. The vulnerability has been fixed in Scada-LTS, a successor product to ScadaBR. On May 13th, 2025, Fellipe Oliveira published an exploit for this vulnerability.

CISA has directed all federal agencies that use the affected products to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” They have provided a deadline of December 24th, 2025, to accomplish those actions.

Review – PHMSA Publishes HAZMAT via HATS ANPRM

Today the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) published in the Federal Register (90 FR 5836-55844) an advanced notice of proposed rulemaking (ANPRM) on “Hazardous Materials: Modernizing Regulations to Facilitate Transportation of Hazardous Materials Using Highly Automated Transportation Systems” (RIN 2137-AF68). PHMSA is seeking to obtain stakeholder input on potential revisions to the Hazardous Materials Regulations (HMR) to facilitate the safe transportation of hazardous materials using highly automated transportation systems. PHMSA had earlier published a request for information on this topic.

Highly Automated Transportation Systems (HATS)

The ANPRM provides a discussion about the potential types of modal highly automated transportation systems (HAT) that might be used to transport hazardous materials and the hazardous material regulation challenges that they may present. These include:

Highly automated rail transportation systems,

Highly automated air transportation systems,

Highly automated vessel transportation systems, and

Highly automated commercial motor vehicles

Public Comments

PHMSA is soliciting public comments on this ANPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2024-0064). Comments should be submitted by March 4th, 2026.

 

For more information on the information PHMSA is seeking, as well as a brief cybersecurity related discussion, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/phmsa-publishes-hazmat-via-hats-anprm - subscription required.

Wednesday, December 3, 2025

Review - Bills Introduced – 12-2-25

Yesterday, with both the House and Senate in session, there were 52 bills introduced. One of those bills will receive additional coverage in this blog:

S 3315 A bill to require the Secretary of Health and Human Services and the Director of the Cybersecurity and Infrastructure Security Agency to coordinate to improve cybersecurity in the health care and public health sectors, and for other purposes. Cassidy, Bill [Sen.-R-LA]

 

For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a brief look at two bills dealing with individual rights related to ‘computational algorithms’, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-12-2-25 - subscription required.

Short Takes – 12-3-25 - Federal Register Edition

Removing Support for the National Definition of a Zero Emissions Building. Federal Register DOE notice. Summary: “The Department of Energy is removing support for the National Definition of a Zero Emissions Building guidance document to comply with directions provided in various Executive orders.”

Formaldehyde; Updated Draft Risk Calculation Memorandum; Notice of Availability and Request for Comment. Federal Register EPA notice. Summary: “Consistent with statutory obligations and Executive Order 14303, Restoring Gold Standard Science, EPA remains committed to the highest standards of scientific integrity and reliance on the best available scientific information. To that end, and after further consideration of comments raised during the scientific peer review process, EPA is reconsidering the use of certain hazard values in the formaldehyde risk evaluation. This Notice, Draft Memorandum, and the materials included in the docket provide the science and science policy basis for determining how the revised draft inhalation point of departure (POD) impacts the corresponding draft margin of exposure (MOE) estimates and the risk determination for formaldehyde under TSCA.” Comments due February 2nd, 2026.

Agency Information Collection Activities: Requests for Comments; Clearance of Renewed Approval of Information Collection: Financial Responsibility for Licensed Launch Activities. Federal Register FAA 30-day ICR renewal notice. Summary: “This collection is applicable to operators requesting to conduct commercial launch operations as prescribed in 14 CFR parts 401, et al., Commercial Space Transportation Licensing Regulation. A commercial space launch services provider must complete the Launch Operators License, Launch-Specific License or Experimental Permit to gain authorization for conducting commercial launch operations. The information will be collected per 14 CFR part 440 Appendix A. A permit or license applicant is required to provide the FAA information to conduct maximum probable loss determination. Also, it is a mandatory requirement that all commercial permitted and licensed launch applicants obtain financial coverage for claims by a third party for bodily injury or property damage. FAA is responsible for determining the amount of financial responsibility required using maximum probable loss determination.” Comments due January 2nd, 2026.

Notice of Partially Closed Federal Advisory Committee Meeting. Federal Register DHS advisory committee hearing notice. Summary: “The Office of Partnership and Engagement is publishing this notice to announce that the Homeland Security Advisory Council will meet in person on Wednesday, December 10, 2025. This meeting will be partially closed to the public. This meeting will be led by the Secretary of Homeland Security to discuss new taskings for the Council and sensitive DHS Operations.”

Aerospace Safety Advisory Panel; Meeting. Federal Register NASA advisory committee hearing notice. Summary: “In accordance with the Federal Advisory Committee Act, as amended, the National Aeronautics and Space Administration announces a forthcoming meeting of the Aerospace Safety Advisory Panel (ASAP). The ASAP will hold a special meeting to deliberate on new formal recommendations for 2025. This discussion is pursuant to carrying out its statutory duties for which the Panel reviews, identifies, evaluates, and advises on those program activities, systems, procedures, and management activities that can contribute to program risk. Priority is given to those programs that involve the safety of human flight.” Meeting date December 19, 2025.

The Sunset Rule. Federal Register NRC final rule. Summary: “The U.S. Nuclear Regulatory Commission (NRC) is amending its regulations to insert a conditional sunset date into certain regulations in response to Executive Order (E.O.) 14270, “Zero-Based Regulatory Budgeting to Unleash American Energy.”” Comments due January 2nd, 2026. If ‘significant adverse comments’ are received then the associated notice of proposed rulemaking will take effect.

OMB Approves Removal of NEPA Implementing Regulations Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the Council on Environmental Quality (CEQ) on “Removal of National Environmental Policy Act Implementing Regulations”. This final rule was sent to OIRA on August 11th, 2025. The interim final rule was published on February 25th, 2025.

According to the Spring 2025 Unified Agenda entry for this rulemaking:

“This interim final rule removes the Council on Environmental Quality (CEQ) regulations implementing the National Environmental Policy Act (NEPA) from the Code of Federal Regulations.”

I expect that this final rule will be published in the Federal Register next week. I do not plan on providing any detailed analysis of this rule, but I will publish a note in the appropriate Short Takes post when it is published.

PHMSA Sends Pipeline Class Locations Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) on “Pipeline Safety: Class Location Requirements”. The advanced notice of proposed rulemaking (ANPRM) for this rulemaking was published on July 31st, 2018 and the notice of proposed rulemaking (NPRM) was published on October 14th, 2020.

According to the Spring 2025 Unified Agenda entry for this rulemaking:

“This rulemaking action would address class location requirements for natural gas transmission pipelines, specifically as they pertain to actions operators are required to take following class location changes due to population growth near the pipeline. Operators have suggested that performing integrity management measures on pipelines where class locations have changed due to population increases would be an equally safe but less costly alternative to the current requirements of either reducing pressure, pressure testing, or replacing pipe.”

Tuesday, December 2, 2025

Short Takes – 12-2-25

‘Fire amoeba’ survives in hotter conditions than any other complex cell. Nature.com article. Pull quote: “Water samples from the [Lassen Volcanic National Park] stream looked devoid of life under a microscope, but after culturing them with nutrients, the researchers spotted the amoeba growing at 57 °C, within the stream’s temperature range. The scientists slowly raised the temperature, sailing past the previous eukaryote record of 60 °C. I. cascadensis was still able to divide at 63 °C and was still moving around at 64 °C. Even at 70 °C, the cells could form dormant ‘cysts’ that were capable of reactivating at cooler temperatures.”

Shingles vaccine may actually slow down dementia, study finds. WashingtonPost.com article. Pull quote: “Crucially, the study suggests that the shingles vaccine — two doses of which are recommended for adults 50 and older or those 19 and older with a weakened immune system — may help people who already have dementia. Those who got the vaccine were almost 30 percent less likely to die of dementia over nine years, suggesting the vaccine may be slowing the progression of the neurodegenerative syndrome.”

How U.S. Export Controls Risk Undermining Biosecurity. LawFareMedia.org article. Pull quote: “Securing governmental authorizations for such [deemed] exports can take a month or more, but competitive pressures push AI labs to complete evaluations in a matter of weeks. This timing mismatch forces American AI companies into a difficult choice: delay product releases to seek export licenses while competitors forge ahead, limit testing to U.S. citizens only and sacrifice evaluation quality, or risk violating export controls and exposing themselves to significant civil and criminal penalties. Our recent white paper discusses these issues in greater technical and legal depth.”

Changing the rules of global chemicals trade. ChemistryWorld.com commentary. Pull quote: “Facing excess global supply of many basic chemicals, and with little prospect of China’s industry backing off production to raise prices, the US has responded with massive trade tariffs. These are intended to deter imports and allow its own chemicals industry to maintain production and profitability, taking advantage of cheaper feedstocks and lower energy costs than European rivals. That has left Europe, along with other markets like South Korea, and others across southeast Asia, bearing the brunt of the supply glut.”

Using AI in Professional Engineering. SCADAMag.Infracritical.com commentary. Pull quote: “So if you are a professional engineer, and you are thinking of using an AI on your next project, remember this: It cannot take responsibility for its actions. You are essential for review. Are you willing to stand behind something that does not formally reason? Are you willing to approach your classically taught profession with post-modernist practice? For now, my answer is no. Some day, if the concerns I expressed above are addressed, I may change my mind.”

Cyber Threats to Water Infrastructure: Insights from Josh Corman. SecurityLedger.com commentary. Pull quote: “As Josh points out, the lack of mandatory reporting laws for cyber disruptions in critical infrastructure like water utilities means many incidents like those detected in Littleton remain unreported, leaving gaps in our understanding of the risks facing critical infrastructure and our defenses. That amplifies the risks associated with integrating software and internet connectivity into operational technology—advancements that, while beneficial, have opened new avenues for cyber threats.”

Public Safety and Homeland Security Bureau Reminds Broadcasters to Ensure They Comply With Best Practices to Prevent Cyberattacks. Docs.FCC.gov notice. Pull quote: “It appears that these recent hacks were caused by a compromised studio-transmitter link (STL)—the broadcast equipment that carries program content from the studio to remote transmitters—with threat actors often accessing improperly secured Barix equipment and reconfiguring it to receive attacker-controlled audio in lieu of station programming. Affected stations broadcast to the public an attacker-inserted audio stream that includes an actual or simulated Attention Signal and EAS alert tones, as well as obscene language, and other inappropriate material.”

Strengthening Pharma Cybersecurity: A Guide for Manufacturers. ForeScout.com blog post. Pull quote: “This interconnectivity, while enabling benefits like condition monitoring, Overall Equipment Effectiveness (OEE) measurement, predictive maintenance, and digital twin capabilities, also creates new entry points for cyber attackers. The need for scalability across multiple lines and plants, customized applications, and seamless integration between IT and OT systems means more software and firmware components are embedded throughout production lines.”

Backlog List

Manufacturer issues remote kill command to disable smart vacuum after engineer blocks it from collecting data — user revives it with custom hardware and Python scripts to run offline,

Ukraine isn’t just hurling attack drones; they’re waging real robot warfare,

Research roundup: 6 cool science stories we almost missed,

Trump administration tells Congress war law doesn’t apply to cartel strikes,

The mysterious rise of cancer among young adults in the Corn Belt, and

Climate Change Made Hurricane Melissa 4 Times More Likely, Study Suggests.


Review – 3 Advisories and 2 Updates Published – 12-2-25

Today CISA’s NCCIC-ICS published two control system security advisories for products from Iskra and Industrial Video & Control, as well as a medical device security advisory for products from Mirion Medical. They also updated two advisories for products from Mitsubishi Electric.

Advisories

Iskra Advisory - This advisory describes a missing authentication for critical function vulnerability in the Iskra iHUB and iHUB Lite smart metering gateways.

Industrial Video & Control Advisory - This advisory describes a code injection vulnerability in the IVC Longwatch video surveillance and monitoring system.

Mirion Advisory - This advisory describes three vulnerabilities in the Mirion EC2 Software NMIS BioDose.

Updates

Mitsubishi Update #1 - This update provides additional information on the MELSEC iQ-R Series/iQ-F Series advisory that was originally published on June 6th, 2023, and most recently updated on April 25, 2024.

NOTE: I briefly discussed the updated Mitsubishi advisory on Sunday.

Mitsubishi Update #2 - This update provides additional information on the CNC Series advisory that was originally published on July 24th, 2025.

NOTE: I briefly discussed the updated Mitsubishi advisory on Sunday

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-2-updates-published-59b - subscription required.

OMB Sends UAS List of Associated Elements IFR to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an interim final rule (IFR) from the OMB on “American Security Drone Act of 2023; Unmanned Aircraft System List of Associated Elements”. This rulemaking was not listed in the Spring 2025 Unified Agenda. It looks like this rulemaking is implementing the requirement of §1823(a) of the American Security Drone Act of 2023 {Section 1821 et seq, PL 118-31, 137 STAT. 691}.

This requirement in §1823 is placed upon the Federal Acquisition Security Council (FASC). The FASC was established by the Federal Acquisition Security Council Rule. The FASC is an executive branch interagency council chaired by a senior-level official from the Office of Management and Budget. This is the reason that the OMB is authoring this regulation.

The term ‘associated elements’ is used in §1823 to describe those parts of unmanned aircraft systems that are “related to the collection and transmission of sensitive information (consisting of communication links and the components that control the unmanned aircraft) that enable the operator to operate the aircraft in the National Airspace System.” The ‘list of associated elements’ will be used to limit federal agencies from acquiring such elements when they come from a ‘covered foreign entity’ {§1822(1)}.

I do not expect that I will be covering this rulemaking in any detail, but I do expect that I will announce its publication in the appropriate Short Takes post.

STB Sends Regulatory Barriers NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the Surface Transportation Board (STB) on “Eliminating Regulatory Barriers to Competition: Review of 49 CFR Part 1144” [link added]. This rulemaking was not listed in the Spring 2025 Unified Agenda, but it looks like this is the STB’s implementation of the requirements of EO 14267, Reducing Anti-Competitive Regulatory Barriers.

It does not look like this rulemaking will have any specific impact on hazmat transportation issues, so I will probably not be covering this rulemaking in any detail. I would expect to announce it’s publication in the appropriate Short Takes post.

Review - Bills Introduced – 12-1-25

Yesterday, with both the House and Senate in Washington, there were 36 bills introduced. Two of those bills will receive additional coverage in this blog:

S 3290 A bill making appropriations for financial services and general government for the fiscal year ending September 30, 2026, and for other purposes. Hagerty, Bill [Sen.-R-TN]

S 3293 A bill making appropriations for energy and water development and related agencies for the fiscal year ending September 30, 2026, and for other purposes. Kennedy, John [Sen.-R-LA]

 

For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a brief look at an intelligence sharing bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-12-1-25 - subscription required.

Monday, December 1, 2025

Review S 2388 Introduced – Cyber Circuit Rider Program

Back in March Sen Cortez-Masto (D,NV) introduced S 1018, the Cybersecurity for Rural Water Systems Act. The bill would require USDA to establish a rural water and wastewater cybersecurity circuit rider program” similar to the one established in 7 USC 1926(a)(22), but focused on cybersecurity. The bill would authorize $10-million per year through 2028 to support the program.

This bill is essentially the same as S 2388, the Cybersecurity for Rural Water Systems Act, that was introduced by Cortez Masto in July 2023. No action was taken on that bill in the 118th Congress.

Moving Forward

Neither Cortez-Masto nor her sole co-sponsor {Sen Rounds (R,ND)} are members of the Senate Agriculture, Nutrition, and Forestry Committee to which this bill was assigned for consideration. This means that it is unlikely that there is sufficient influence to see the bill considered in Committee. Adding $10-million dollars in spending is sure to draw opposition from many Republicans, but there may still be sufficient bipartisan support in the Committee to see the bill approved if it were considered.

As with most bills, there would not be sufficient interest in this legislation to see the Senate leadership tie up the Senate for the time that it would be necessary to consider this bill under regular order. Because of the added spending involved, it would not be possible to pass this bill under the Senate’s unanimous consent process; it would take just a single Senator to object to passage of the bill to kill consideration.

Commentary

The current circuit rider program has about 147 personnel periodically helping small water systems and small wastewater treatment systems. CISA reports about 153,000 water treatment facilities in the US with the vast majority (93 % by one estimate -pg 3) being small systems that would be covered by the circuit rider program. That means that each circuit rider would have to cover about 1,000 systems. They do not get around very often.

 

For more details about the provisions of this bill, including a brief look at the related NRWA actions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2388-introduced-cyber-circuit-rider - subscription required.

Review – Committee Hearings – Week of 11-30-25

With both the House and Senate back from their Thanksgiving break, there is a moderately busy hearing schedule. Of interest here are two fact-finding hearings on grid security and communications security. There are also two Space Geek hearings.

Grid Security

On Tuesday the Subcommittee on Energy of the House Energy and Commerce Committee will hold a hearing on “Securing America’s Energy Infrastructure: Addressing Cyber and Physical Threats to the Grid”.

Communications Security

On Tuesday the Subcommittee on Telecommunications and Media of the Senate Commerce, Science, and Transportation Committee will hold a hearing on “Signal Under Siege: Defending America’s Communications Networks”.

Space Geek Hearings

On Wednesday the Senate Commerce, Science, and Transportation Committee will hold a nomination hearing  that will bring Jared Isaacman back before the Committee for his renomination to be NASA Administrator.

On Thursday the Subcommittee on Space and Aeronautics of the House Science, Space, and Technology Committee will hold a hearing on “Strategic Trajectories: Assessing China’s Space Rise and the Risks to U.S. Leadership”.

 

For more information on these hearings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/committee-hearings-week-of-11-30 - subscription required.

Review - S 2465 Introduced – FY 2026 THUD Spending

Back in July Sen Hyde-Smith introduced S 2465, the Transportation, Housing and Urban Development, and Related Agencies Appropriations Act, 2026. At the same time the Senate Appropriations Committee published their Report on the Bill. While there is a cyber security mention in the bill, the main focus here will be PHMSA spending in the bill and discussions in the Report, as well as some UAS discussions in the Report.

S 2465 is be similar to S 4796, the Transportation, Housing and Urban Development, and Related Agencies Appropriations Act, 2025, that was introduced by Sen Schatz (D,HI) in July 2024. No action was taken on that bill in the 118th Congress. The related House bill, HR 9028, was also introduced in July 2024, and similarly, no action was taken on that bill in the 118th Congress.

Moving Forward

The plan in the House currently appears to be to add the language of S 2431 to the substitute language for the consideration of HR 4016, the Department of Defense Appropriations Act, 2026. The Senate has not yet held their first cloture vote that would allow actual debate to begin on the bill. This probably indicates that there is still some backroom dealing going on to determine the broad outline of what will end up in the Senate version of the bill. Then further dealing with determining what further amendments will be considered on the floor.

Right now, SA 3951 from Sen Collins (Chair of the Appropriations Committee) is the current candidate for the substitute language to be considered, and it includes the language from S 2431. But a lot can happen in the short legislative month of December.

 

For more information on the provisions of this bill dealing with cybersecurity, PHMSA, and UAS issues, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2465-introduced-fy-2026-thud-spending - subscription required.
 
/* Use this with templates/template-twocol.html */