Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Friday, July 24, 2026

Review – Bills Introduced – 7-23-26

Yesterday, with both the House and Senate in session (and the House leaving for summer break), there were 111 bills introduced. One of those bills may receive additional coverage in this blog:  

HR 9908 To require the development of a comprehensive rural hospital cybersecurity workforce development strategy, and for other purposes. Houchin, Erin [Rep.-R-IN-9]    


For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a mention-in-passing of two additional cybersecurity bills, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-7-23-26 - subscription required. 

Wednesday, June 24, 2026

HR 8880 Passed in House – Cybersecurity Assistance Report

 Yesterday, the House took up HR 8880, the Small Business Cybersecurity Assistance Evaluation Act of 2026, under the suspension of the rules process. After just 11 minutes of debate, the bill was passed by a voice vote. 

The bill would require the GAO to conduct a study of current Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns. No new funding is authorized by this legislation. 

As this legislation moves to the Senate, it will almost certainly not be considered under regular order; the bill is not politically important enough for that time consuming process. The lack of opposition in the House may mean that it could pass in the Senate under their unanimous consent process. A more likely possibility is that the language could be added to another, more politically important, bill, either in committee consideration or as part of the floor consideration process. 

Tuesday, June 23, 2026

HR 8880 Introduced - Small Business Cybersecurity Assistance Report

Last month, Rep Simon (D,CA) introduced HR 8880, the Small Business Cybersecurity Assistance Evaluation Act of 2026. The bill would require the GAO to conduct a study of current Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns. No new funding is authorized by this legislation. 

I can find no legislation in the 118th Congress that would appear to be similar to HR 8880. 

Moving Forward  

On May 20th, 2026, the House Small Business Committee held a business meeting where nine bills were considered, including HR 8880. By a vote of 23 to 0, the Committee adopted the bill as introduced. On June 3rd, 2026, the Committee Report on the bill was published. HR 8880 is currently scheduled to be considered by the House today under the suspension of the rules process. Strong, bipartisan support for the bill is expected. 


For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-8880-introduced-small-business - subscription required. 

Wednesday, May 13, 2026

Looking Back – 2-22-13 Honeywell EBI Advisory

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 17 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from February 22nd, 2013, made the list. It describes an ICS-CERT advisory for an ActiveX vulnerability in the Honeywell Enterprise Buildings Integrator. Two interesting items were included in the discussion. First, the researchers (Rapid7) announced that they would be publishing a Metasploit module for the vulnerability, much less common back then. Second, I discussed the fact that the researcher had requested that Microsoft “issue a kill bit for the HscRemoteDeploy.dll in a future monthly Microsoft Windows security update”. That .dll was the heart of the Honeywell vulnerability. 

Wednesday, April 29, 2026

Looking Back – 4-16-21

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from March 16th, 2021, CISA Publishes CFATS Cybersecurity Letter, made the list. It briefly discusses a notification letter that the CFATS folks sent out to chemical facilities about widespread exploitation of the Microsoft Exchange Server Vulnerabilities. The interesting thing was that CISA sent that letter to not just the 3,000+ CFATS regulated facilities, but also to over 33,000 other chemical facilities that had sent Top Screen information to CISA. The odd thing was that the letter was little more than a warning about the vulnerabilities and only recommended that facilities report “evidence of threat actor activity”. 

Monday, April 27, 2026

Review – Committee Hearings – Week of 4-26-26

 This week, with both the House and Senate in Washington, there is an almost moderately busy hearing schedule. Budget hearings are a large part of the load (some of interest here) and the House Appropriations Committee continues to work on spending bills. There is a CISA SMRA hearing in the House (with a touch of Space Geek thrown in) and a space defense hearing. 

Cybersecurity Hearings  

On Wednesday, the Subcommittee on Cybersecurity and Infrastructure Protection of the House Homeland Security Committee will hold a hearing on “Data Centers, Telecommunications Networks, and Space-Based Systems: Modernizing DHS’s SRMA [Sector Risk Management Agency] Role for the Communications and IT Sectors”. 

Space Defense Hearings  

On Wednesday the Subcommittee on Europe of the House Foreign Affairs Committee will hold a hearing on “Orbits of Influence: Emerging Threats to U.S. Space Security and Foreign Policy Implications”.   


For more information on these hearings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/committee-hearings-week-of-4-26-26 - subscription required. 

Advisory Follow-Up – Researcher Follow Through

 I have written an unknown number of posts over the years about cybersecurity vulnerabilities and the advisories published about those vulnerabilities. Most often those posts get written, posted, and mostly forgotten. All of the response takes place at facilities that use the affected products. Every once-in-a-while, however, a researcher decides that there is more to the story that needs to be shared with the public. Here is a brief look at one of those; vulnerabilities in products from Gardyn, and further follow-up by Michael Groberman, the researcher who identified the vulnerabilities. 

Background Information  

CISA Advisory (ICSA-26-055-03published February 24th, 2026.3 

CISA Advisory updated April 2nd, 2026. 

Groberman exploit published April 3rd, 2026. 

New Information  

Groberman has established a web site that addresses the published vulnerabilities and the various responses to issues involved. I do not imagine that every set of reported vulnerabilities deserves this level of dedication, but it is interesting to see how far a committed researcher is willing to go to share information about a problem that is reported to be corrected.  

 
/* Use this with templates/template-twocol.html */