Thursday, December 19, 2024

Review – 8 Advisories Published – 12-19-24

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (2), Tibbo, Siemens, Delta Electronics, and Hitachi Energy (2). The also published a medical device security advisory for products from Ossur.

Advisory

Schneider Advisory #1 - This advisory describes a cross-site scripting vulnerability in multiple Schneider Modicon Controllers.

Schneider Advisory #2 - This advisory describes a classic buffer overflow vulnerability in the Schneider Accutech Manager product.

Tibbo Advisory - This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Tibbo AggreGate Network Manager.

Siemens Advisory - This advisory describes a heap-based buffer overflow vulnerability in the Siemens User Management Component.

Delta Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Delta DTM Soft product.

Hitachi Energy Advisory #1 - This advisory describes two vulnerabilities in the Hitachi Energy SDM600 product.

Hitachi Energy Advisory #2 - This advisory describes a classic buffer overflow vulnerability in the Hitachi Energy RTU500 series CMU.

Ossur Advisory - This advisory describes three vulnerabilities in the Ossur Logic Mobile Application.

 

For more information about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-12-19-24 - subscription required.

Bills Introduced – 12-18-24

Yesterday, with both the House and Senate in session, there were 82 bills introduced. Two of those bills would be expected to receive additional coverage in this blog if there were time left in the session for actions to be taken on the bills:

 

HR 10483 To amend the Safe Drinking Water Act to provide grants under the Drinking Water Infrastructure Risk and Resilience Program for training programs relating to protecting public water systems from and responding to cyberattacks, and for other purposes. Gallego, Ruben [Rep.-D-AZ-3]

S 5600 A bill to authorize programs for the National Aeronautics and Space Administration for fiscal year 2025, and for other purposes. Cantwell, Maria [Sen.-D-WA]

OMB Approves HIPPA Security NPRM

Yesterday OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking from HHS’s Office for Civil Rights (OCR) on “Proposed Modifications to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information”. This NPRM was sent to OIRA on October 18th, 2024.

According to the Fall 2024 Unified Agenda entry for this rulemaking:

“This rule will propose modifications to the Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications will improve cybersecurity in the health care sector by strengthening requirements for HIPAA regulated entities to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.”

The Fall 2024 Unified Agenda has included expanded supporting information on rulemakings, including entries for ‘Statement of Need’, “Summary of the Legal Basis”, and ‘Alternatives’. The ‘Statement of Need’ comment for this rulemaking is of potential interest:

“In February 2003, the HIPAA Security Rule established standards for the security of electronic protected health information (ePHI) to be implemented by HIPAA covered entities and, by amendment of the HITECH Act, their business associates (collectively, "regulated entities"). Prior to the HIPAA Security Rule, standard security measures did not exist in the health care industry to address the security of ePHI while stored and exchanged between entities. Since 2003, the Department has received recommendations from the National Committee on Vital and Health Statistics (NCVHS), an advisory committee to the Secretary of HHS, and the public to update and strengthen security standards to protect ePHI, especially in light of newer threats not previously contemplated in 2003 such as ransomware. Additionally, the Department has reviewed media reports advocating the strengthening of protections provided by the HIPAA Security Rule as well as a report from a U.S. Senator advocating for modernizing HIPAA to increase protections of ePHI in the face of current cyber threats.”

It will be interesting to see if this NPRM specifically addresses security requirements for medical devices that store or transmit ePHI.

CISA Sends EO 14117 Restricted Transactions Notice to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice from CISA on “Security Requirements for Restricted Transactions Under Executive Order 14117”.

This action was not listed in the Fall 2024 Unified Agenda. Looking at EO 14117, however, this notice is almost certainly that required by §2(d):

“(d) The Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency, shall, in coordination with the Attorney General and in consultation with the heads of relevant agencies, propose, seek public comment on, and publish security requirements that address the unacceptable risk posed by restricted transactions, as identified by the Attorney General pursuant to this section. These requirements shall be based on the Cybersecurity and Privacy Frameworks developed by the National Institute of Standards and Technology.”

Wednesday, December 18, 2024

Short Takes – 12-18-24

FBI Warns of HiatusRAT Attacks on Cameras, DVR Systems. SecurityWeek.com article. Pull quote: “They used the Ingram scanning tool to mainly target Xiongmai and Hikvision devices with telnet access in the Five Eyes intelligence alliance countries, looking for those impacted by vulnerabilities such as CVE-2017-7921, CVE-2018-9995, CVE-2020-25078, CVE-2021-33044, and CVE-2021-36260.”

NASA astronauts stuck in space after Boeing spaceship hit new delay. TheHill.com article.  Pull quote: ““NASA’s SpaceX Crew-10 now is targeting no earlier than late March 2025 to launch four crew members to the International Space Station,” NASA said in a release.”

Congress strikes deal to avert government shutdown. TheHill.com article. Pull quote: “Johnson said the goal was for “a very simple, very clean” stopgap funding plan “to get us into next year when we have a unified government.” But he added that “acts of God,” such as hurricanes, required disaster aid and other additions to the package.” Morning story.

Trump, Vance call for streamlined CR and debt ceiling debate. Politico.com article. Pull quote: “Trump said in a post later a post on Truth Social that he would primary any Republican who supported the original temporary funding bill that included the Democrat requests. He said it would “bring the mess of the Debt Limit" to his administration.” Evening story.

Johnson considers plan B amid Trump World opposition to spending deal. TheHill.com article. Pull quote: “The back-up option Johnson is examining is a “clean” continuing resolution, two sources familiar with the matter told The Hill. That would entail dropping the additional provisions that were included in the initial 1,500-page spending package negotiated by congressional leaders, including disaster aid and economic assistance for farmers.”

Axiom Space Accelerates Axiom Station Assembly. AxiomSpace.com press release. Pull quote: ““The result – free-flight capability after the launch and berthing of PPTM,” Greeley explained, “allowing us to add modules while on orbit once we have separated from station. Our goal is to ensure a smooth transition from a government to a commercial platform, maintaining a continuous human presence on orbit to serve a community of global customers and partners, to include NASA.””

S 3959 Passed in House – TWIC-HME Applications

This afternoon the House took up  S 3959 [removed from paywall], the Transportation Security Screening Modernization Act, under the suspension of the rules process. After nine minutes of debate, the House passed the bill by a voice vote. The legislation now goes to the President; Biden is expected to sign the bill, almost certainly before Christmas.

The bill would require the TSA to take actions (potentially including issuing an interim final rule) to streamline the procedures for individuals applying for or renewing enrollment in more than one TSA security threat assessment program, in particular, the TWIC and HAZMAT Endorsement programs. No new funding is authorized by the legislation.

Bills Introduced – 12-17-24

Yesterday, with both the House and Senate in session (and looking forward to the fast approaching end of the 118th Congress), there were 64 bills introduced. Five of those bills will (or would if sufficient time remained to take any action) will receive additional coverage in this blog:

HR 10445 Further Continuing Appropriations and Disaster Relief Supplemental Appropriations Act, 2025 Cole, Tom [Rep.-R-OK-4]

HR 10446 Disaster Offset and Government Efficiency Act Roy, Chip [Rep.-R-TX-21] 

HR 10455 To direct the Secretary of Health and Human Services to establish the Health Sector Cybersecurity Coordination Center, and for other purposes. Kelly, Robin L. [Rep.-D-IL-2] 

HR 10464 To amend chapter 511 of title 51, United States Code, to modify the authority for space transportation infrastructure modernization grants, and for other purposes. Strong, Dale W. [Rep.-R-AL-5]

S 5556 A bill to require a solid rocket motor industrial base strategy. Cornyn, John [Sen.-R-TX]

HR 10464 and S 5556 are being added as part of my Space Geek coverage.

 
/* Use this with templates/template-twocol.html */