Monday, August 21, 2023

Review - S 2393 Introduced – Ag Cyber Clearinghouse

Last month, Sen Rounds (R,SC) introduced S 2393, the Food and Agriculture Industry Cybersecurity Support Act. The bill would require National Telecommunications and Information Administration (NTIA) to establish a food and agriculture cybersecurity clearinghouse which would include direct support by NTIA to the food and agriculture industry. No funding is authorized by this bill.

 This bill is very similar to HR 1219 [removed from paywall], which was introduced in March. No action has been taken on that bill.

Moving Forward

Neither Rounds, or his sole cosponsor {Sen Cortez-Maso (D,NV)} are members of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. This means that there will probably not be sufficient influence to see this bill considered in Committee. I see nothing in this bill that would engender any significant opposition to the legislation. I suspect that there would be some level of bipartisan support for the bill if it were taken up by the Committee.

 

For more information on the differences between this bill and HR 1219, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2393-introduced - subscription required.

Saturday, August 19, 2023

Short Takes – 8-19-23

Invasive firestarter: How non-native grasses turned Hawaii into a tinderbox. Phys.org article. Pull quote: “The problem isn't confined to Hawaii. Over in the mainland United States, "the deserts of the West and the conifer forests, and then the shrub lands in the coastal zone, invasive grasses are here to stay, they're now part of the ecosystem," said D'Antonio.”

Before Joining Federal Safety Program, Freight Railroads Push to Change It. NYTimes.com article. Pull quote: ““The position that the freight railroads have taken is both unfortunate and unwise,” Mr. Mathews said. “If they truly want a safer system, then punishment and discipline cannot be the only tool in your toolbox.”” Railroads want to kill non-retaliation provisions.

Putin Profits Off US, European Reliance on Russian Nuclear Fuel. VOANews.com article. Pull quote: “The dependence on Russian nuclear products — used mostly to fuel civilian reactors — leaves the U.S. and its allies open to energy shortages if Russian President Vladimir Putin were to cut off supplies. The challenge is likely to grow more intense as those nations seek to boost production of emissions-free electricity to combat climate change.”

China’s dangerous secrets. ASOIStrategist.org.au commentary. Pull quote: “There’s no reason to expect China to abandon its rule-breaking, its debt-based coercion or its other malign activities anytime soon. Chinese President Xi Jinping—who has strengthened the CCP’s control over information, cutting off outside analysts’ access even to economic data—is now on track to hold power for life, and remains eager to reshape the international order to China’s benefit.”

Donald Trump Is Likely to Try to Move Georgia Case to Federal Court. It Could Work. WSJ.com article. Pull quote: “In Georgia, Trump would gain a jury pool with a slightly more pro-Trump voting record by moving the trial to federal court. The Fulton County jury pool largely draws from the heavily Democratic city of Atlanta, while the federal jury pool would likely draw from 10 counties that make up the metro Atlanta area.”

Should the West Fear Putin’s Fall? WSJ.com article. Pull quote: “As a historical matter, revolutions in Russia have usually been triggered by military setbacks: losing a war against Japan in 1905, huge casualties during World War I, and the failure to secure Afghanistan in the 1980s, which was one of the factors that precipitated the Soviet Union’s dissolution.”

Tennessee [zinc] Refinery Could Break Chinese Chokehold on Two Critical Minerals. VOANews.com article. Pull quote: “Colorado-based mineral economist David Hammond told VOA he thinks the company’s timeline for the construction’s completion of two to two and a half years is realistic and, like Ecclestone, he believes the United States should be willing to shoulder the added cost of establishing domestic sources for critical minerals such as gallium and germanium.”

Virtual city prepares students for future of cybersecurity. Arizona.edu article. Pull quote: ““We built a synthetic world that looks and feels exactly like the internet, without being on the internet,” Denno said. “We have over 100 different companies, as well as five fully operational social media sites and two online news agencies like CNN and Fox News. Living in this virtual city are virtual personas that do everything normal humans do: They email each other, browse the web, conduct transactions in stores, maintain bank accounts, leave social media posts and comment on news stories.””

 

Reminder – CFNS Subscription Sale through August 31st - https://chemical-facility-security-news.blogspot.com/2023/08/cfsn-detailed-analysis-subscription.html  See article for links to reduced rate subscriptions –

Chemical Sector Security Summit Update – 8-19-23

With just over a week and a half until the 2023 Chemical Sector Security Summit (August 29th, thru 31st), CISA has provided a more detailed agenda for the meeting. There are no major changes to the breakout sessions, but there is more information available about presenters.

With the demise (hopefully temporary) of the CFATS program since the last update, the morning sessions on Day 1 of the Summit take on increased importance, and fortunately, they will all be live-streamed. These include:

8:35  DHS and CISA Keynote Addresses, Jen Easterly and an as of yet unnamed DHS official,

9:20  Federal and Industry Discussion on the Future of Chemical Security, Eric Byer (NACD) and Caitlin Durkovich (NSC),

10:05 State of Chemical Security, Kelly Murray (CISA), and

11:00 Chemical Threats to the Homeland, Lisa Parnpichate (FBI).

These four presentations alone will be well worth the price of admission (FREE registration).

Chemical Incident Reporting – Week of 8-12-23

NOTE: See here for series background.

Plum, PA – 8-12-23

Local News Reports: Here, here and here.

House explosion, unknown cause. 6 dead.

Technically a CSB reportable, because a house does meet the definition of a ‘stationary source’ under 40 CFR 1604.2. I would be surprised if CSB took umbrage that a home owner did not make a report under §1604, but CSB could initiate an investigation, particularly if a series of house explosions occurred that demonstrated a pattern of a deficiency in design or operation.

Nunnelly, TN – 8-18-23

Local News Reports: Here, here, and here.

Explosion and fire at gas pipeline compressor station. No injuries

Possible CSB reportable depending on level of damage. This one poses an interesting jurisdictional issue. Generally, the NTSB is responsible for investigating pipeline explosions, as they fall under ‘transportation’. Compressor stations, however, fall under the definition of ‘stationary source’, particularly if there are storage tanks on site. Whether this incident would fall under CSB, or NTSB, or both is one of those legal issues, the decision of which, where lawyers get rich.


Review – Public ICS Disclosures – Week of 8-12-23

This week we have 17 vendor disclosures from Aruba Networks, Broadcom, CODESYS, FortiGuard, GE Gas Power, Helmholz, HPE (2), Inductive Automation, Moxa (2), Palo Alto Networks, Red Lion, Rockwell, Ruckus Wireless, Wibu, and Zyxel.

Advisories

Aruba Advisory - Aruba published an advisory that describes two vulnerabilities in their Virtual Intranet Access (VIA) Windows Client.

Broadcom Advisory - Broadcom published an advisory that discusses a type confusion vulnerability in their Brocade Fabric OS product.

CODESYS Advisory - CODESYS published an advisory that discusses a heap-based buffer overflow vulnerability in multiple products.

FortiGuard Advisory - FortiGuard published an advisory that describes a stack-based buffer overflow vulnerability in their FortiOS product.

GE Gas Power - GE published an advisory that discusses a heap-based buffer overflow vulnerability in their CIMPLICITY product.

Helmholz Advisory - CERT-VDE published an advisory that discusses a cross-site scripting vulnerability in their REX 200 and REX 250 products.

HPE Advisory #1 - HPE published an advisory that discusses 13 vulnerabilities in their HP-UX Web Server Suite Software.

HPE Advisory #2 - HPE published an advisory that discusses two vulnerabilities in their SimpliVity Servers.

Inductive Automation Advisory - Inductive Automation published an advisory that describes six vulnerabilities in their Ignition product.

Moxa Advisory #1 - Moxa published an advisory that describes a use of hard-coded credentials vulnerability in their NPort IAW5000A-I/O Series.

Moxa Advisory #2 - Moxa published an advisory that describes eight vulnerabilities in their TN-5900 and TN-4900 Series Web Server.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the TunnelCrack vulnerabilities.

Red Lion Europe Advisory - CERT-VDE published an advisory that descries a cross-site scripting vulnerability in the Red Lion mbNET and mbNET/.rokey.

Rockwell Advisory - Rockwell published an advisory that describes three improper input validation vulnerabilities in their ThinManager ThinServer product.

Ruckus Advisory - Ruckus published an advisory that describes three cross-site scripting vulnerabilities in their ICX product line.

Wibu Advisory - Wibu published an advisory that describes a heap-based buffer overflow vulnerability in their CodeMeter Runtime product.

Zyxel Advisory #1 - Zyxel published an advisory that describes an improper handling of exceptions vulnerability in their XGS2220, XMG1930, and XS1930 series switches.

Zyxel Advisory #2 - Zyxel published an advisory that describes an OS command injection vulnerability in their NBG6604 home router.

 

For more information about the disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-810 - subscription required.

Friday, August 18, 2023

Review - HR 4915 Introduced – Project Spectrum

Last month, Rep Joyce (R,OH) introduced HR 4915, the Project Spectrum Authorization Act. The bill would specifically authorize DOD’s existing Project Spectrum which is designed to “to provide to covered entities, through an online platform, digital resources and services that increase awareness about cybersecurity risks and help such covered entities to comply with the cybersecurity requirements of the defense acquisition system.” No funding is authorized by this bill.

Moving Forward

Joyce is not a member of the House Armed Services Committee to which this bill was assigned for consideration, but one of his three co-sponsors {Rep Escobar (D,TX)} is a member of that Committee. This means that there may be sufficient influence to see this bill considered in Committee. I do not see anything in this bill that would engender any organized opposition to the bill. So there should be some level of bipartisan support for this bill. While it should be sufficient to see the bill adopted in Committee, it is too early to determine if there would be sufficient support for the bill to be considered under the House suspension of the rules process. If not, it is not likely that the bill would advance past the committee approval.

 

For more details about the provisions of the legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4915-introduced - subscription required.

Review - PHMSA Publishes Next Set of Hazmat FAQs – 8-18-23 – Incident Reporting

Today, DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) published a notice in the Federal Register (88 FR 56702-56705) on “Hazardous Materials: Frequently Asked Questions – Incident Reporting”. This is part of a continuing effort at PHMSA to convert existing Letters of Interpretation into more broadly applicable frequently asked questions (FAQs) that was started [removed from paywall] in March of 2022.

Public Comments

PHMSA is soliciting public comments on this proposed set of FAQ and responses. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #PHMSA-2021-0109). Comments should be submitted by September 18th, 2023.

Commentary

I think that this project of converting existing historical letters of interpretation into broadly applicable FAQ’s is a commendable information sharing effort on the part of PHMSA. The only problem is I am unable to find the FAQ’s from the initial tranche published in the Federal Register by PHMSA in March of 2022 on the PHMSA website. There is a “Hazardous Materials Safety FAQs” page, but it was last updated on August 23, 2019 and contains none of the questions proposed in the earlier notice.

If PHMSA is going to continue with this program, each subsequent notice in the Federal Register should contain a link to the web site where PHMSA is going to make these FAQ’s and responses readily available to the public. And to be fair, this notice should be updated with that link.

I will be posting this commentary as a comment on this notice.

 

For more details about this notice, including a list of the proposed FAQ’s, see my article at CFSN Detailed Analysis - https://open.substack.com/pub/patrickcoyle/p/phmsa-publishes-next-set-of-hazmat - subscription required.

 
/* Use this with templates/template-twocol.html */