Friday, February 17, 2023

Short Takes – 2-17-23 – Ohio Train Wreck Version

EPA chief visits Ohio and vows support after train derailment. TheHill.com article. Reminder, NTSB is investigative agency for the accident. Pull quote: “The EPA head said the federal agency’s air monitoring efforts have not detected anything to prompt health concerns in the area thus far. Of more than 480 voluntary home screenings, he said, the EPA has not detected vinyl chloride or hydrogen chloride in any of them.”

NTSB: Video shows Ohio train wheel bearing in ‘final stage of overheat failure’ before derailment. TheHill.com article. Pull quote: “The NTSB has identified the initial rail car to blame for the incident, and said in a statement on Tuesday that a video from a residence showed the car’s wheel bearing was “in the final stage of overheat failure moments before the derailment.” Investigators said that they collected the wheel set from the railcar as well as the wheel bearing to be examined by engineers from NTSB Materials Laboratory in Washington, D.C.”

High-profile chemical spills on rails, roads prompt transport concerns. WashingtonPost.com article. Pull quote: “While images of flames and overturned rail cars near the Pennsylvania border highlighted the consequences of crashes, transportation officials and experts say there’s no indication of a rise in such events. Despite the high-profile spills, federal data shows chemical leaks while in transit are happening less often. The number of hazmat incidents resulting from crashes or derailments across all modes of transportation fell to 80 last year, down from more than 360 a decade ago.”

‘Chernobyl 2.0’? Ohio Train Derailment Spurs Wild Speculation. NYTimes.com article. Pull quote: “On social media like Twitter and Telegram, commentators have called the situation the “largest environmental disaster in history” or simply “Chernobyl 2.0,” invoking the 1986 nuclear disaster. They warned, without evidence, that vital water reservoirs serving states downriver could be badly contaminated. And they suggested that the authorities, railroad companies and mainstream news media were purposefully obscuring the full toll of the crisis.”

EPA says Ohio derailment site is safe, as locals report rashes, worries. WashingtonPost.com article. Pull quote: “Johnson and Sen. Sherrod Brown (D-Ohio) said they are examining federal regulations for trains carrying hazardous chemicals. Brown said he would push for better labeling of trains carrying hazardous materials, which he said may require a change in federal law.”

Bills Introduced – 2-16-23

Yesterday, with just the Senate in Washington and preparing to leave for their Presidents Day recess, there were 79 bills introduced. Two of those bills will receive additional attention in this blog:

S 473 A bill to provide for drone security. Scott, Rick [Sen.-R-FL] 

S 513 A bill to require the Assistant Secretary of Commerce for Communications and Information to establish a working group on cyber insurance, to require dissemination of informative resources for issuers and customers of cyber insurance, and for other purposes. Hickenlooper, John W. [Sen.-D-CO] 

I would also like to mention one bill in passing:

S 515 A bill to require the Secretary of Energy to conduct a study to determine the feasibility and effectiveness of establishing a national strategic propane reserve. Stabenow, Debbie [Sen.-D-MI]

Given the political machinations surrounding the operation of the Strategic Petroleum Reserve, any such study by DOE, should at least take a pro forma look at the political restrictions that should be placed upon the possible propane strategic reserve.

Thursday, February 16, 2023

Short Takes – 2-16-23

US NIST unveils winning encryption algorithm for IoT data protection. BleepingComputer.com article. Pull quote: “"The world is moving toward using small devices for lots of tasks ranging from sensing to identification to machine control, and because these small devices have limited resources, they need security that has a compact implementation," stated Kerry McKay, a computer scientist at NIST.”

Active defense a key approach to protecting against major threats. TalosIntelligence.com blog post. Searching for attackers not hacking back. Pull quote: “Ransomware compromises, which usually involve data exfiltration, are not fast nor swift. Attackers need time to find their way in the network, including identifying the databases with the relevant information they are seeking, to exfiltrate the information and finally to deploy the ransomware. This is the time window when an active defense strategy can make the most impact, by looking from the inside out: The perimeter was already compromised, no relevant alerts were raised, and the attackers have already begun to carry out their malicious activities within the victim’s network.”

Investigation updated released into hazardous train derailment as rail company pulls out of meeting with locals. HazardExOnTheNet.net article. Pull quote: “A town meeting was called on February 15 as hundreds of locals looked to ask questions about the health risks the derailment had caused. East Palestine’s Mayor Trent Conaway told the meeting that he wanted those responsible for the incident to be held to account and that he was working closely with Norfolk Southern, adding “they screwed up our town, they are going to fix it.” However, Norfolk Southern pulled out of the town meeting saying they feared violence.”

Frustration builds over response to Ohio train derailment as officials urge patience. TheHill.com article. Pull quote: ““The fact that it happened on the state line where it’s a lower income area … especially the area where the derailment itself [occurred], it’s not heavily populated, no injuries happened. … It’s not going to be an immediate ‘oh, what’s happened,’” he [Greg Brown, nearby resident] said. “When there are reports of people who are finding these fish dead, [the state] giving us kind of a runaround, it just really didn’t sit well with a lot of people, especially in the community.””

‘This Is Absurd’: Train Cars that Derailed in Ohio Were Labeled Non-Hazardous. GovExec.com article. The actual complaint was that the train was not labeled as a ‘Highly Hazardous Flammable Train’ (HHFT). Pull quote: “Speaking at a press conference on Tuesday, Republican Governor Mike DeWine said he learned that the train cars were marked as non-hazardous, and thus officials weren’t notified that the train would be crossing through the state.”

How the U.S. Can Use Taxes to Improve Cybersecurity. WSJ.com article. Pull quote: “A new study, which I co-wrote with Professors Janine Hiller and Kathryn Kisska-Schulze, suggests ways to do just that. Specifically, we propose offering a three-tier Federal Cybersecurity Investment Tax (FCIT) credit to encourage businesses to adopt and implement cybersecurity practices that an agency such as the Cybersecurity and Infrastructure Security Agency (CISA) has identified as necessary to defend our nation and critical infrastructure.”

Review – OCS Publishes 2 New FAQs and 3 Updated FAQ Responses – 2-16-23

Today, CISA’s Office of Chemical Security (OCS) published two new frequently asked questions (FAQs) and updated the responses to three other FAQs on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The two new FAQs were #1799 and #1800; one was related to restoring CSAT access issues and the other to Top Screen issues. The three revised FAQ responses were for FAQs, #641, #1275, and #1756; the first deals with Top Screen issues, the second is about facility ID changes, the third about owner name changes.

 

For more details about these new FAQs and revised FAQ responses, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ocs-publishes-2-new-faqs-and-3-updated - subscription required.

Review – 14 Advisories and 1 Update Published – 2-16-23

Today, CISA’s NCCIC-ICS published twelve control system security advisories for products from Sub-IoT and Siemens (12). They also published a medical device security advisory for products from BD. Finally, they updated an advisory for products from Delta Electronics.

NOTE 1: Siemens published one additional advisory on Tuesday that was not covered today by NCCIC-ICS. I will cover it this weekend.

NOTE 2: NCCIC-ICS continues to report on Siemens advisories that it will not report updated information on those advisories, so the seven updates published by Siemens this week will not be addressed by NCCIC-ICS.

Control System Advisories

Sub-IoT Advisory - This advisory describes an out-of-bounds write vulnerability in the Sub-IoT DASH 7 Alliance protocol implementation.

JY Open Advisory - This advisory describes three vulnerabilities in the Siemens JT Open Toolkit, JT Utilities, and Parasolid products.

Mendix Advisory - This advisory describes an improper access control vulnerability in the Siemens Mendix Applications.

COMOS Advisory - This advisory describes a classic buffer overflow vulnerability in the Siemens COMOS products.

SIMATIC Advisory - This advisory describes a TOCTOU race condition vulnerability in the Siemens SIMATIC industrial products.

RUGGEDCOM Advisory - This advisory describes seven TOCTOU race condition vulnerabilities in the Siemens RUGGEDCOM APE1808 product family.

TIA Project-Server Advisory - This advisory describes an untrusted search path vulnerability in the Siemens TIA Project-Server.

Simcenter Advisory - This advisory describes two vulnerabilities in the Siemens Simcenter Femap.

SiPass Advisory - This advisory describes an improper input validation vulnerability in the Siemens SiPass integrated AC5100, AC5102, AC5200, ACC-AP, Granta-MK3.

Brownfield Connectivity Advisory #1 - This advisory discusses eight vulnerabilities in the Siemens Brownfield Connectivity—Gateway products.

Brownfield Connectivity Advisory #2 - This advisory discusses four vulnerabilities in the Siemens Brownfield Connectivity Client.

SCALANCE Advisory - This advisory discusses an improper input validation vulnerability in the Siemens SCALANCE X200 IRT Products.

Medical Device Advisory

Solid Edge Advisory - This advisory describes 37 vulnerabilities in the Siemens Solid Edge products.

BD Advisory - This advisory this advisory describes a credentials management errors vulnerability in the BD Alaris Infusion Central.

Update

Delta Update - This update provides additional information on an advisory that was originally published on October 25th, 2022 and most recently updated on November 10th, 2022.

 

For more details about advisories, including links to researcher reports and 3rd-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-and-1-update-published - subscription required.

Bills Introduced – 2-15-23

Yesterday, with just the Senate in session, there were 41 bills introduced. None of these bills are of specific interest here, but I would like to mention one Resolution in passing:

S Res 66 A resolution condemning the use by the People's Republic of China of a high-altitude surveillance balloon over the territory of the United States as a brazen violation of United States sovereignty. Tester, Jon [Sen.-D-MT]

This resolution, along with a similar resolution, S Res 49 (A resolution expressing the sense of the Senate that the Chinese Communist Party's espionage mission to send a surveillance balloon across the United States, in violation of international law, is unacceptable and should be condemned) that was introduced by Sen Hawley (R,MO) on February 9th, 2023, were taken up by the Senate yesterday. The Senate passed both under their unanimous consent process. No action is necessary on the measures by either the House or the President.

Swift, bipartisan, action by the Senate, but it does not really accomplish anything.

NOTE: Corrected date in title at 11:31 EST, 2-16-23

OIRA Approves TSA PCSR ICR Revision – 2-15-23

Yesterday OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a revision of the information collection request (ICR) for TSA’s “Pipeline Corporate Security Reviews and Security Directives”. The revision request was submitted to OIRA back in January. OIRA approved the revisions without additional changes.

The minor burden reduction for this ICR was accomplished by removing redundant cybersecurity questions from the PCSR. See my January post for more details.

 
/* Use this with templates/template-twocol.html */