Tuesday, May 21, 2024

Review – 1 Advisory Published – 5-21-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from LCDS. They also published an alert about a new cybersecurity initiative from Rockwell Automatio 

Advisories

LCDS Advisory - This advisory describes a path traversal vulnerability in the LCDS LAquis SCADA product.

Rockwell Initiative - This alert notes that: “Rockwell Automation has released guidance encouraging users to remove connectivity on all Industrial Control Systems (ICS) devices connected to the public-facing internet to reduce exposure to unauthorized or malicious cyber activity.”

 

For more information about the advisory and alert, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-5-21-24 - subscription required.

Committee Hearings – Week 5-20-24

This week, with both the House and Seante in session, there is a moderately heavy hearing schedule. The House is starting hearings on FY 2025 spending bills. The FY 2025 NDAA also gets a full committee hearing this week.

FY 2025 Spending Bills

 

House

Mil Construction

Subcommittee

Legislative Branch

Subcommittee

Mil Construction

Full Committee

This is relatively early in the year to start marking up spending bills, but if there is any chance in getting any of these bills done before September 30th, action is going to have to start now. Theoretically, these two are the least controversial bills. Probably the only matter of real contention between the House and Senate on these two bills will be the spending levels, with the House Republicans again poised to call for steep spending cuts (probably less steep on these two bills).

Commentary: It will be interesting to see if the House Republicans have the votes to pass a bill that will even come close to satisfying the fringe elements of the party. It is going to be a long summer.

FY 2025 NDAA

On Wednesday, the House Armed Forces Committee will hold their markup hearing for HR 8070, the Servicemember Quality of Life Improvement Act. This will also be the FY 2025 National Defense Authorization Act (NDAA). The hearing page provides links to the various subcommittee markups. Of interest here is the Subcommittee on Cyber, Information Technologies, and Innovation print. There are only two sections in that print that appears to be of specific interest here:

Section 221—Plan for Establishment of Secure Computing and Data Storage Environment for Testing of Artificial Intelligence Trained on Biological Data, and

Section 1511—Protective Measures for Mobile Devices within the Department of Defense

EPA Sends TSCA New Chemicals Update Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had received a final rule from the EPA on Updates to New Chemicals Regulations Under the Toxic Substances Control Act (TSCA). The notice of proposed rulemaking (NPRM) was published on May 26th, 2023.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“EPA is reviewing public comments on the proposed amendments to the new chemicals procedural regulations under the Toxic Substances Control Act (TSCA). These amendments are intended to align the regulatory text with the amendments to TSCA's new chemicals review provisions contained in the Frank R. Lautenberg Chemical Safety for the 21st Century Act, enacted on June 22, 2016, improve the efficiency of EPA's review processes, and update the regulations based on existing policies and experience implementing the New Chemicals Program. The proposal includes amendments that would reduce the need to redo all or part of the risk assessment by improving information initially submitted in new chemicals notices, which should also help reduce the length of time that new chemicals notices are under review. EPA proposed several amendments to the regulations for low volume exemptions (LVEs) and low release and exposure exemptions (LoREXs), which include requiring EPA approval of an exemption notice prior to commencement of manufacture, making per- and polyfluoroalkyl substances (PFAS) categorically ineligible for these exemptions, and providing that certain persistent, bioaccumulative, toxic (PBT) chemical substances are ineligible for these exemptions, consistent with EPA's 1999 PBT policy.”

Bills Introduced – 5-20-24

Yesterday, with just the Senate in session, there were three bills introduced. One of those bills will receive additional coverage in this blog:

S 4369 A bill to require the Director of the National Counterintelligence and Security Center to develop a strategy and conduct outreach to United States industry, including shipping companies, port operators, and logistics firms, on the risks of smartport technology of the People's Republic of China and other related risks, and for other purposes. Casey, Robert P., Jr. [Sen.-D-PA]

Review – EPA Publishes Water System Cybersecurity Enforcement Alert – 5-20-24

Yesterday, the EPA updated their website to include a page on “Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities”. The page notes that:

“As part of EPA’s multi-year drinking water National Enforcement and Compliance Initiative, Increasing Compliance with Drinking Water Standards, inspectors are assessing CWS compliance with SDWA Section 1433. Given the vulnerabilities and attacks on systems, EPA also will increase the number of CWS inspections that focus on cybersecurity. Where vulnerabilities are identified and may present an imminent and substantial endangerment to public health, enforcement actions may be appropriate [emphasis added] under SDWA Section 1431 to mitigate those risks.”

Commentary

The EPA typically relies on state water authorities to enforce SDWA related regulations. It simply does not have the number of inspectors necessary to periodically visit each of the 52,000+ community water systems. The number of EPA inspectors with sufficient cybersecurity training to conduct a meaningful review of the cybersecurity assessments and response plans makes it extremely unlikely that any given community water system will be visited in this enforcement effort. This is an awfully small ‘big stick’ being wielded by the EPA.

Monday, May 20, 2024

Short Takes – 5-20-24

WHO updates bacterial priority pathogens list. CIDRAP.UMN.edu article. Pull quote: “Also new in the high-priority pathogen group is fluoroquinolone-resistant Shigella, which is the second most common cause of diarrheal mortality in all age-groups globally. Previously listed in the medium-priority group, Shigella primarily affects children in the developing countries where it is prevalent, but the WHO notes that multidrug-resistant Shigella strains are being increasingly reported in men who have sex with men in urban areas in high-income countries, suggesting a shift in AMR trends.”

Elevated carbon dioxide lets Sars-CoV-2 live far longer in droplets. ChemistryWorld.com article. Pull quote: “‘To understand viral decay in respiratory aerosol, one needs to understand the complex pH dynamics occurring in the respiratory droplet,’ says Haddrell. ‘There is a significant amount of bicarbonate in respiratory fluid. When the bicarbonate leaves the aerosol in the form of CO2, it takes with it a large amount of acid. This results in a dramatic shift in pH of the droplet from neutral to more than 10. The high pH that respiratory aerosol reaches following exhalation is a major driver of viral decay. Thus, anything that reduces the pH of the aerosol will significantly prolong the time the virus will remain infectious in the air, consequently increasing overall transmission risk.’ Higher environmental carbon dioxide levels mean that the chemical equilibrium of the droplets is shifted and less bicarbonate decomposes, making the aerosols’ pH more acidic and hospitable to viruses.”

Wastewater testing finds H5N1 avian flu in 9 Texas cities. CIDRAP.UMN.edu article. Pull quote: “In a May 10 response update, the CDC said more than 260 people have so far been monitored for H5N1 symptoms following exposure to infected or potentially infected animals. Of at least 33 who had flulike symptoms, no additional human cases have been reported beyond an initial case in a Texas dairy worker who had conjunctivitis.”

This Year’s La Niña Could Worsen Atlantic Hurricane Season. ScientificAmerican.com article. Short explainer. Pull quote: “Normally, air rises over the Amazon and Indonesia because moisture from the tropical forests makes the air more buoyant there, and it comes down in East Africa and the eastern Pacific. During La Niña, those loops intensify, generating stormier conditions where they rise and drier conditions where they descend. During El Niño, ocean heat in the eastern Pacific instead shifts those loops, so the eastern Pacific gets stormier.”

Researchers studying ‘doomsday glacier’ make worrying discovery. TheHill.com article. Pull quote: ““It will take many decades, not centuries” for the Thwaites Glacier to fully melt,” Rignot told USA Today. “Part of the answer also depends on whether our climate keeps getting warmer or not, which depends completely on us and how we manage the planet.””

Di-isodecyl Phthalate (DIDP) and Di-isononyl Phthalate (DINP); Science Advisory Committee on Chemicals (SACC) Peer Review of Draft Documents; Notice of SACC Meeting; Availability; and Request for Comment. Federal Register EPA notice. Summary: “The Environmental Protection Agency (EPA or “Agency”) is announcing the availability of and soliciting public comment on the draft manufacturer-requested risk evaluation for Di-isodecyl Phthalate (DIDP) and the draft physical chemical, fate, and hazard assessments for Di-isononyl Phthalate (DINP) prepared under the Toxic Substances Control Act (TSCA). The draft documents will also be submitted to the Science Advisory Committee on Chemicals (SACC) for peer review. EPA is also announcing that there will be two virtual public meetings of the SACC: On July 23, 2024, for the SACC to consider the scope and clarity of the draft charge questions for the peer review; and on July 30-August 2, 2024, for the SACC to consider the draft documents and public comments for peer review.”

Fall 2024 Cybersecurity and Infrastructure Security Agency SBOM-a-Rama; Meeting. Federal Register CISA event notice. Summary: “CISA will facilitate a public event to build on existing community-led work around Software Bill of Materials (SBOM) on specific SBOM topics. The first goal of this two-day event is to help the broader software and security community understand the current state of SBOM. Secondly, this event will foster discussion between organizations interested in exploring SBOM automation solutions and those focusing on open source and proprietary tools.” Event Dates: September 11th and 12th, 2024.

CISA Adds Medical Device Vulnerability to KEV Catalog -

Today, CISA announced that it had added two vulnerabilities to their Known Exploited Vulnerabilities (KEV) Catalog, including CVE-2023-43208 for NextGen Healthcare’s Mirth Connect healthcare integration engine. The vulnerability was reported by Horizon3.ai. The team of r00t, Spencer McIntyre, Naveen Sunkavally have published a Metasploit module for the vulnerability.

The Horizon3.ai report notes that:

CVE-2023-37679 was reported to be fixed in Mirth Connect 4.4.0. In the release notes for 4.4.0, it was reported as only affecting Mirth Connect installs running on Java 8 or below. This caught our attention (why only Java 8?), and we started digging. We found that in fact, all installs of Mirth Connect, regardless of the Java version, were vulnerable. We also found that the patch for CVE-2023-37679 could be bypassed. We subsequently reported a new vulnerability to NextGen, tracked as CVE-2023-43208. The fix for CVE-2023-43208 is in 4.4.1.”

The KEV entry for the vulnerability notes that:



 
/* Use this with templates/template-twocol.html */