Thursday, August 20, 2026

FCC Sends Satellite Spectrum Abundance Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the Federa Communications Commission (FCC) on “Satellite Spectrum Abundance (SB Docket No. 25-180)”. The notice of proposed rulemaking for this action was published on June 27th, 2025.  

According to the 2026 Unified Agenda Entry for this rulemaking: 

“On May 22, 2025, the Commission adopted a Notice of Proposed Rulemaking to seek further comment on ways to use the 12.7-13.25 GHz band (12.7 GHz band) and the 42.0-42.5 GHz band (42 GHz band) more efficiently and intensively. Specifically, the item seeks comment on the possibility of achieving more intensive use of the 12.7 GHz band by satellite communications through the removal of existing regulatory restrictions and the opening of the band to a wider range of satellite operations. Likewise, it seeks comment on the potential for more intensive use of the 42 GHz band by adding for the first time an allocation for fixed-satellite service (FSS). In both instances, the item seeks comment on ways to protect any incumbent spectrum users in the bands, as well as ways to protect spectrum users, particularly Federal operators, in adjacent bands.” 

Wednesday, August 19, 2026

Review - ChemLock Fact Sheets – August 2026

For those of you familiar with my “Looking Back” series of blog posts (latest here), there was almost one today about a post of mine from December 2021 on “Review - ChemLock Fact Sheets”. However, after reviewing the CISA ChemLock web site, I decided that it was probably more appropriate to do a new blog post on the topic. 

Fact Sheets 

Early in the CFATS program, DHS started producing a number of short informational brochures about various chemical security topics. Typically just two pages, these Fact Sheets provided a brief look at a specific topic and provided links to other, more detailed information about the topics. They were never designed to make someone a chemical security expert, but they did form a valuable library for chemical professionals to become more aware of security issues. 

When I wrote that first blog post (CFSN version here) there were just seven fact sheets on the ChemLock web site. Now there are three separate pages listing listing 14 separate ChemLock Fact Sheets: 

Commentary  

The Office of Chemical Security continues to have a problem publicly sharing information on the ChemLock Program. While there have been training announcements from @CISAgov for various ChemLock classes (here is the most recent), I have not seen any other outreach efforts and no mentions of these new fact sheets. I understand that CISA is still recovering from the emasculation of the agency that occurred last year, but if they want to keep the ChemLock program going, they are going to have to start making more of an effort to bring facilities into the fold. Publicly talking about the program is an important part of that effort. 


For more information on these fact sheets, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-fact-sheets-august-2026 - subscription required. 

Tuesday, August 18, 2026

CISA Adds VMware Vulnerability to KEV Catalog – 8-18-26

Today, CISA announced that it had added a path traversal vulnerability in the VMware vCenter (multiple VMware products are affected by the vulnerability) product to their Known Exploited Vulnerabilities (KEV) catalog. Broadcom previously disclosed the vulnerability and updated their advisory on August 3rd, 2026; they provide additional information here. The vulnerability was reported to Broadcom by Phil Brass and Matt South of Atredis Partners. Two separate Medium articles have reported public exploitation of the vulnerability:  

CISA has directed federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. 

A compliance deadline of August 21st, 2026, has been established. 

Review – 2 Advisories Published – 8-18-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Siemens and CISA. I also take a down-the-rabbit-hole look at the Github advisories for the CISA Malcom vulnerabilities. 

Advisories  

  • Siemens Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Simcenter Nastran FEM modeling tool. The vulnerability was reported to Siemens by Michael Heinzl. 
  • CISA Advisory - This advisory describes six vulnerabilities in the CISA Malcom network traffic analysis tool. The vulnerabilities were reported to CISA separately by pavanchow, kah-ja, DeathRipper21, and tinb0y. 


For more information on these advisories, as well as a DTRH look at CISA vulnerability reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-8-18-26 - subscription required. 

Review - S 4565 Introduced – Chinese Cyber Threats

Back in May, Sen Scott (R,FL) introduced S 4565, the Strengthening Cyber Resilience Against State-Sponsored Threats Act. The bill would require CISA to establish an interagency task force to “detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China”. The task force would submit annual classified reports to Congress. No new funding is authorized by this legislation. 

A nearly identical bill, HR 2659, the Strengthening Cyber Resilience Against State-Sponsored Threats Act, was introduced by Rep Ogles (R,TN) in April 2025. On April 9th, 2025, the House Homeland Security Committee held a business meeting where HR 2659 was considered; the bill was ordered reported favorably by a voice vote. The Committee Report was published on August 15th, 2025. On November 17th, the full House took up the bill under the suspension of the rules process; the bill passed by a vote of 402 to 8. No action has been taken on the bill in the Senate. 

A press release from Scott’s office notes that:  

“Senator Rick Scott said, “As the world’s leading digital economy, America has the most to lose in a cyberattack. If we don’t secure our digital infrastructure, hackers could cut power to your house, empty your bank account, or disable life support for a loved one in the hospital. Americans shouldn’t worry about a cyber threat from the CCP, which is why I’m proud to be introducing this legislation with Rep. Ogles. The House has done its job in passing this bill, now we need the Senate to do ours.”” 

Moving Forward  

Both Scott and his sole cosponsor, Sen Fetterman (D,PA), are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there may be adequate influence to see the bill considered by the Committee. I do not see anything in the bill that would engender any organized opposition, though there is a real possibility that the Chair, Sen Paul (R,TN), might have some objections to the bill. I do expect that there would be some level of bipartisan support for this bill. The bill, however, is not politically important enough to take up the limited amount of time left in the session that needs to be expended to be considered under regular order. 


For more information on the provisions of this bill, including a commentary on the lack of participation by the intelligence community, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4565-introduced-chinese-cyber-threats - subscription required. 

 
/* Use this with templates/template-twocol.html */