Friday, June 21, 2024

Short Takes – 6-21-24 – Space Geek Edition

Bacterial genome sequences of uncharacterized Chitinophaga species isolated from the International Space Station. Journals.ASM.org article. Mutated in space or brought from Earth? Pull quote: “We report four Chitinophaga sp. strains isolated from wastewater collected onboard the International Space Station. Here, we present three finished and one draft genome. Taxonomic ranks established by genome-based analysis indicate that these Chitinophaga sp. strains represent candidates for a new species.”

Two astronauts wait to come home as Boeing races to understand spacecraft issues. Here’s what’s at stake. CNN.com article. Interesting note on possible backup reture. Pull quote: ““The embarrassing backup is that a Crew Dragon would have to go and retrieve the astronauts,” Lembeck said. The spacecraft “could be sent up with two crew members and sent back with four — and that would probably be the way home.””

Elon Musk shares target date for fifth Starship test. DigitalTrends.com article. Pull quote: ““Following liftoff, and after the two stages separate in-flight, Super Heavy will return to the launch site, reignite its engines to slow the vehicle down, and the tower’s arms will catch the rocket booster before restacking it on the orbital launch mount for its next flight.” Target launch: late July.

'ESA Space Bricks' landing at Lego Stores could build real moon base. CollectSpace.com article. Pull quote: “As a stand-in for regolith, the ESA team used the dust from a 4.5 million-year-old meteorite, which was added to polylactide (a biodegradable polymer) and lunar regolith simulant to form the feedstock for their 3D printers. The meteorite was originally found in North-West Africa 24 years ago. Classed as an L3-6, the rock was a brecciated stone, comprised of large metal grains, inclusions, chondrules and elements.”

Asteroid headed toward Earth? NASA simulation explores how the nation might respond. NPR.org article. Pull quote: “This is the hypothetical scenario that asteroid experts, NASA workers, federal emergency management officials, and their international partners recently discussed as part of a table-top simulation designed to improve the nation’s ability to respond to future asteroid threats, according to a report just released by the space agency.”

Transportation Chemical Incidents – Week of 5-18-24

Reporting Background

See this post for explanation, with the most recent update here (removed from paywall).

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.

Incidents Summary

• Number of incidents – 579 (449 highway, 56 air, 7 rail, water 1)

• Serious incidents – 3 (3 Bulk release, 0 evacuation, 1 injury, 0 death,0 major artery closed, 1 fire/explosion).

• Largest container involved – 30,130-gal DOT 111A100W1 railcar {Flammable Liquids, N.O.S.} Improperly placed manway seal and vapor release from vacuum relief valve. (Note: The database listed a 269,713-gal railcar of Denatured Alcohol, but that is an obvious typo).

• Largest amount spilled – 1,000-gal Plastic drums (Bisulfites, Aqueous Solutions, N.O.S.) Load not properly blocked or braced, drums were crushed.

NOTE: Links above are to the Form 5800.1 for the described incidents.

Most Interesting Chemical: Isophorone Diisocyanate - A clear to light-yellow liquid. Slightly denser than water and insoluble in water. Toxic by inhalation and skin absorption. Very irritating to skin. Used to make polyurethane coatings. Reacts violently with water.



Review - Rabbit Hole Update – RAD Advisory Background

On Tuesday in my CISA advisory post on Substack, I included a down-the-rabbit-hole (DTRH) look at the delay between the apparent 2019 discovery (per the CVE number - CVE-2019-6268) of the path traversal vulnerability reported by CISA on Tuesday and the publication of an exploit earlier this year. I contacted Branko Milicevic, the researcher who originally identified the vulnerability and published the exploit, to find out the classic ‘rest of the story’.

 

For more details about that ‘rest of the story’, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/rabbit-hole-update - subscription required.

Thursday, June 20, 2024

Short Takes – 6-20-24

Hydroxide-loaded sponge soaks up atmospheric carbon dioxide. ChemistryWorld.com article. May be more useful for other, point-source atmospheric scrubbing applications. Pull quote: “García points out that the adsorption capacity of the charged sponges is ‘approximately one fourth of the uptake reported for current benchmarks’, including amines. Moreover, the capture capacity is almost halved if humidity increases from 10 to 40%, which would be problematic if capturing carbon dioxide in climates with high humidity, for example in the UK where the average humidity is over 70%. ‘Such problematic performance could also hugely hinder applications in point-source carbon capture, [where] gas streams are normally saturated in water,’ explains García López. However, she sees the tuneability, quick kinetics, and simple preparation of the system as major benefits. ‘The method has a huge potential to achieve very good results in the future,’ she adds.”

Electronic Weapons: SpaceX Stifles Russian Use of Starlink. StrategyPage.com article. Pull quote: “Early in the war American defense officials admitted that if the Starlink satellite internet service were government run, it would not have remained operational over Ukraine because government regulations do not allow for the quick responses Starlink management used to defeat Russian electronic attacks and keep Starlink operational in Ukraine.”

Titan Disaster Forces Global Rethinking of Deep Sea Exploration. NYTimes.com article. Pull quote: ““It has to be mandatory,” Alfred S. McLaren, a retired Navy submariner, submersible pilot and president emeritus of the Explorers Club, said of the proposed upgrade. “Until you get these testing and certification rules in place, it’s a wide open sea, and stupid things are going to happen.””

Mathematicians Are Suddenly Rethinking the Equal Sign. PopularMechanics.com article. Slightly geeky, but may have implications outside of academia. Pull quote: “If that sounds like overthinking, you’re right—using the highly intuitive and context-adapting human mind, we can do it pretty much without thinking at all. But math is an abstract field of study, and computer programming is arguably even more so. The machines we rely on to solve complicated problems need a lot more direction than our flexible human minds, and Buzzard’s career project is converting human-written math proofs into all of the algorithmic steps that are required to code them with a computer.”

Safety Fitness Determinations; Virtual Public Listening Sessions. Federal Register FMCSA virtual meeting notice. Summary: “FMCSA announces that it will host two virtual public listening sessions pertaining to development of an updated methodology to determine when a motor carrier is not fit to operate commercial motor vehicles in or affecting interstate commerce. Specifically, the Agency would like to hear from members of the public on issues of concern relating to the current Safety Fitness Determination (SFD), including, for example, the three-tiered rating system (Satisfactory, Unsatisfactory, Conditional) versus changing to a proposed single rating only when a carrier is found to be Unfit; utilizing inspection data and FMCSA's Safety Measurement System (SMS); incorporating driver behavior into SFD ratings; and revising the list of safety violations used to calculate the rating, and adjusting the weights allocated to particular violations including increasing the weight for unsafe driving violations.” First meeting date: June 25th, 2024.

Massive underwater drone skates off California coast. Axios.com article. Extremely sparse language. Pull quote: “The drone is modular, meaning it is easily taken apart and reassembled in the field. The Manta Ray prototype was shipped cross-country in pieces for at-sea assessments earlier this year.”

Review – 3 Advisories Published – 6-20-24

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Westermo, CAREL, and Yokogawa.

Advisories

Westermo Advisory - This advisory describes three vulnerabilities in the Westermo L210-F2G industrial ethernet switches.

CAREL Advisory - This advisory describes a path traversal vulnerability (with known exploit) in the CAREL Boss-Mini, a local supervisor solution.

Yokogawa Advisory - This advisory describes an improper access control vulnerability in the Yokogawa CENTUM distributed control system.

 

For more information about these advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-6-20-24 - subscription required.

CISA CSAT Breach Update – 6-20-24

Earlier this afternoon, CISA provided an email to registered recipients providing the following updates to their CSAT Breach notification. This latest notification notes that:

“This announcement applies to all facilities registered with the CFATS program. Direct email notification is being made to individual facilities’ CSAT Authorizers and Cyber Security Officers, if designated, in batches; we anticipate that all registered Authorizers and Cyber Security Officers will receive this notification by Monday, June 24. If you have additional questions, please contact us at CFATS.Notifications@cisa.dhsg.gov or CFATS@hq.dhs.gov.”

The terminology “all facilities registered with the CFATS program” almost certainly means any facility that has registered a facility Authorizer in preparation for submitting a Top Screen, whether or not a Top Screen was ever submitted. It is certainly not limited to facilities that have been notified that they were a covered facility under the Chemical Facility Anti-Terrorism Standards (CFATS) program.

CISA Announces CSAT Breach

As if the CFATS program did not have enough problems, today CISA announced that there was a cybersecurity breach of their Chemical Security Assessment Tool (CSAT) in January of this year. The notice states that:

“While CISA’s investigation found no evidence of exfiltration of data, this intrusion may have resulted in the potential unauthorized access of Top-Screen surveys, Security Vulnerability Assessments, Site Security Plans, Personnel Surety Program (PSP) submissions, and CSAT user accounts.”

CISA has directly contacted individuals with CSAT accounts to notify them of the breach.

CISA has scheduled two webinars to discuss the breach, its potential consequences, and actions facilities should take as a consequence of the breach. Webinars will be held on June 24th, 2024 and July 9th, 2024 (links are to registration pages).

There is an interesting notification problem associated with this potential breach, there is a possibility that that individuals who had been vetted via the CFATS personnel surety tool may have had their data exposed during the breach. CISA does not have access to the contact information for these individuals so cannot make the necessary breach notifications. CISA thus notes that:

“CISA is thereby requesting, on a voluntary basis, that facilities that received the CSAT Ivanti Notification Letter notify individuals submitted by that facility for vetting under the CFATS Personnel Surety Program of this incident. Download a template letter that facilities can use to notify personnel. Alternatively, should facilities decline to notify these individuals, CISA requests that facilities provide CISA with the contact information for individuals submitted under the CFATS Personnel Surety Program on a voluntary basis so that CISA can notify impacted individuals. Facilities can send contact information for personnel that had Personally Identifiable Information (PII) submitted for vetting under CFATS Personnel Surety Program to CFATS.Notifications@cisa.dhs.gov.”

The announcement has a brief frequently asked question section that addresses the following questions:

• How was this compromise identified?

• What actions did CISA take to address the compromise?

• If CISA does not have any evidence of data exfiltration, why are notifications being sent?

• Where can I get more information on this cybersecurity incident?

• As a facility official, who do I contact if I have more questions about this incident?

• As a potentially impacted individual, who do I contact if I have more questions?

• Who is eligible for identity protection based on this compromise?

• How do I apply for identity protection?

• Why is identity protection not available to me?

• What data was collected in the CFATS Top-Screen survey?

• What data was collected in the Security Vulnerability Assessment (SVA)?

• What data was collected in the Site Security Plan/Alternative Security Program (SSP/ASP)?

• What data was collected in the Personnel Surety Program?


 
/* Use this with templates/template-twocol.html */