Saturday, April 19, 2025

Review - S 1007 Introduced – 9-8-8 Lifeline Cybersecurity

Last month Sen Mullin (R,OK) introduced S 1007, the 9–8–8 Lifeline Cybersecurity Responsibility Act. This bill would establish broadly written cybersecurity requirements for the National Suicide Prevention Lifeline Program. No new funding is provided in the legislation. Mullin’s office has a press release about this legislation.

This bill is very similar to S 1493, the 9–8–8 Lifeline Cybersecurity Responsibility Act, that was introduced by Sen Sinema (I,AZ) in May 2023, Mullin was a cosponsor of that bill. No action was taken on S 1493 in the 118th Congress. It is also similar to HR 912 that was introduced this session in the House by Rep Obernolte (R,CA) in February.

Moving Forward

Mullins is a Subcommittee Chair in the Senate Health, Education, Labor, and Pensions Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in the legislation that would engender any organized opposition to the bill. I suspect that the bill would receive significant bipartisan support {with an obvious no vote from Sen Paul (R,KY), who rarely supports any legislation}. The big problem moving this bill forward is that it is not politically important enough to bring to the floor of the Senate under regular order. This leaves the unanimous consent process or including the language in a spending or authorization bill.


For more information on the provisions of this bill, including a brief look at some press coverage of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-1007-introduced - subscription required.


Review – Public ICS Disclosures – Week of 4-12-25

This week we have 14 vendor disclosures from ads-tech, Broadcom, Delta Electronics, GE Vernova (2), HP, HPE (2), Philips, Rockwell Automation, SEL (3), and WAGO. There are two vendor updates from Broadcom and Siemens. We also have three researcher reports for vulnerabilities in products from Eclipse. Finally, we have two exploits for products from Ruckus and FortiGuard.

Advisories

Ads-tech Advisory - CERT-VDE published an advisory that discusses three vulnerabilities (two with publicly available exploits) in the ads-tech IRF products.

Broadcom Advisory - Broadcom published an advisory that describes an input validation vulnerability in multiple Brocade products.

Delta Advisory - Delta published an advisory that describes three vulnerabilities in their ISPsoft product.

GE Advisory #1 - GE Vernova published an advisory that discusses four vulnerabilities in their NetworkST4 devices and Remote Operations Offering products.

GE Advisory #2 - GE Vernova published an advisory that discusses three vulnerabilities (all three listed in CISA’s KEV catalog) in unspecified GE products.

HP Advisory - HP published an advisory that describes a link following vulnerability in their Touchpoint Analytics Service.

HPE Advisory #1 - HPE published an advisory that describes an unauthorized access vulnerability in their Performance Cluster Manager.

HPE Advisory #2 - HPE published an advisory that describes an unauthorized access vulnerability in their Cray Data Virtualization Service.

Philips Advisory - Philips published an advisory that discusses a use after free vulnerability (with publicly available exploit) in multiple Philips products.

Rockwell Advisory - Rockwell published an advisory that describes two vulnerabilities in their ThinManager product.

SEL Advisory #1 - SEL published a software update notice that includes cybersecurity enhancements for their SEL-5032 acSELerator Architect Software.

SEL Advisory #2 - SEL published a software update notice that includes cybersecurity enhancements for their SEL-5702 Synchrowave Operations product.

SEL Advisory #3 - SEL published a software update notice that includes cybersecurity enhancements for their SEL-5231 SEL Configuration API.

WAGO Advisory - CERT-VDE published an advisory that discusses the Year 2038 problem.

Updates

Broadcom Update - Broadcom published an update for their Fabric OS advisory that was originally published on September 26th, 2034, and most recently updated on February 27th, 2025.

Siemens Update - Siemens published an update for their Industrial Edge Device Kit advisory that was originally published on April 8th, 2025.

Researcher Reports

Eclipse Reports - Cisco Talos published three reports about individual vulnerabilities in the Eclipse ThreadX NetX Duo HTTP server.

Exploits

Ruckus Exploit - Korelogic published an exploit for an undocumented backdoor vulnerability in the Ruckus IoT Controller.

FortiGuard Exploit - Zach Hanley published a Metasploit module for an improper authentication vulnerability (listed in CISA’s KEV catalog) in multiple FortiGuard products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-971 - subscription required.

Friday, April 18, 2025

Short Takes – 4-18-25

NASA safety panel warns of increasing risks to ISS operations. SpaceNews.com article. Pull quote: “The station is dealing with several other issues, such as keeping sufficient spare parts for life support systems and delays with cargo resupply vehicles. That latter concern involves both the delays in the first flight of Sierra Space’s Dream Chaser vehicle, now expected no earlier than late summer. and Northrop Grumman scrapping its NG-22 Cygnus mission to the ISS, which was scheduled to launch in June, because of damage to the spacecraft incurred during shipping.”

The world’s biggest space-based radar will measure Earth’s forests from orbit. TechnologyReview.com article. Pull quote: “This is why for the Biomass mission ESA went with P-band radar. P-band radio waves, which are about 10 times longer in wavelength, can see bigger branches and the trunks of trees, where most of their mass is stored. But fitting a P-band radar system on a satellite isn’t easy. The first problem is the size.”

Trump’s War on Measurement Means Losing Data on Drug Use, Maternal Mortality, Climate Change and More. ProPublica.org article. Pull quote: “Reaction to those (DOGE) cuts has focused understandably on the hundreds of thousands of civil servants who have lost their jobs or are on the verge of doing so and the harm that millions of people could suffer as a result of the shuttering of aid programs. Overlooked amid the turmoil is the fact that many of DOGE’s cuts have been targeted at a very specific aspect of the federal government: its collection and sharing of data. In agency after agency, the government is losing its capacity to measure how American society is functioning, making it much harder for elected officials or others to gauge the nature and scale of the problems we are facing and the effectiveness of solutions being deployed against them.”

Travel Guidance. WHMurray.blogspot.com blog post. Pull quote: “I am leaving the country in May and returning in June. All of my data is already in the cloud, mostly for device independence.  Just before returning,  I plan to erase the clients from my phone and tablet.  It will be simple enough to reinstall them from the app store after I clear customs.”

Video shows doctor with measles treating kids. RFK Jr later praised him as an ‘extraordinary’ healer. APNews.com article. Pull quote: “Measles is most contagious for about four days before and four days after the rash appears and is one of the world's most contagious diseases, according to the U.S. Centers for Disease Control and Prevention. Doctors and public health experts said Edwards' decision to go into the clinic put children, their parents and their community at risk because he could have spread it to others. They said there was no scenario in which Edwards' conduct would be reasonable.”

Moon-orbiting Gateway space station's habitat module arrives in the US (photos). Space.com article. Pull quote: “NASA calls the [Italian supplied] HALO module a "core component" of Gateway. Aside from providing astronaut living quarters, the module will offer a range of utilities like command and control, power distribution, communications and tracking. It will also enable research, supporting internal and external science payloads.”

A mysterious, 100-year solar cycle may have just restarted — and it could mean decades of dangerous space weather. LiveScience.com article. Pull quote: “The inner belt's proton flux decreases when solar activity increases because of interactions with Earth's upper atmosphere, which swells as it soaks up more solar radiation. On the flip side, the proton flux increases as solar activity decreases.”

Transportation Chemical Incidents – Week of 3-15-25

Reporting Background

See this post for explanation, with the most recent update here (removed from paywall).

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.

Incidents Summary

• Number of incidents – 413 (394 highway, 17 air, 2 rail, 0 water)

• Serious incidents – 2 (1 Bulk release, 1 evacuation, 1 injury, 0 death, 0 major artery closed, 2 fire/explosion, 28 no release)

• Largest container involved – 5,631-gal Tank Truck {Combustible Liquid, N.O.S.} Single vehicle accident.

• Largest amount spilled – 1,400-gal DOT 406 Tank Truck {Diesel Fuel} Train-truck collision at uncontrolled rail crossing.

NOTE: Links above are to Form 5800.1 for the described incidents. Links to accident reports are not working.

Most Interesting Chemical: Pentane-2,4-Dione: A colorless or yellow colored liquid. Less dense than water. Vapors are heavier than air. Used as a solvent in paints and varnishes. Inhalation causes dizziness, headache, nausea, vomiting and loss of consciousness. Contact with liquid irritates eyes. (Source: CameoChemicals.NOAA.gov).

 


CSB Updates Recommendation Response Spreadsheet – 4-15-25

Yesterday the Chemical Safety Board (CSB) updated their Recommendations Statistics page to include a link to the latest version of their spreadsheet, all_rec_status_update_4-15-2025.xlsx. This spreadsheet tracks all 1008 recommendations made by the CSB in their closed accident investigations and is current through the publication of the Marathon Martinez investigation. The previous version (that old link still works) of this spreadsheet on the CSB website was dated December 19th, 2024.


OMB Approves OPM Civil Service Accountability NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the Office of Personnel Management (OPM) on “Improving Performance, Accountability and Responsiveness in the Civil Service”.  This draft rule was submitted to OIRA on February 10th, 2025.

This rulemaking was not published in the Fall 2024 Unified Agenda. It looks like, however, that it fulfilling the requirements of § 4, Conforming Regulatory Changes, of EO 14171, “Restoring Accountability to Policy-Influencing Positions Within the Federal Workforce”. That EO amends and reinstates Trump’s EO 13957, Creating Schedule F in the Excepted Service, and revokes President Biden’s EO 14003, Protecting the Federal Workforce.

Section 4 of EO 14171 required OPM to “promptly amend the Civil Service Regulations to rescind all changes made by the final rule of April 9, 2024, “Upholding Civil Service Protections and Merit System Principles,” 89 Fed. Reg. 24982 [link added], that impede the purposes of or would otherwise affect the implementation of Executive Order 13957.”

I will not be covering this rulemaking in any depth in this blog, but I will announce it’s publication in the appropriate ‘Short Takes’ post.

Thursday, April 17, 2025

Short Takes – 4-17-25

Republicans consider increasing taxes on the rich in break from party orthodoxy. TheHill.com article. Pull quote: “The discussions are in the early stages, and lawmakers say it is possible that no tax hike makes it in the final legislation. But the once-inconceivable consideration of tax increases underscores the tricky task that Republicans have in meeting competing demands from fiscal hawks, moderates, and tax slashers for the ambitious party-line bill — as well as the rise of populist instincts in the party.”

CDC ‘scraping’ to find resources to help states respond to growing measles outbreaks. TheHill.com article. Pull quote: “When asked about the deaths compared to the number of infections, Sugerman said the agency suspects there are many cases not being reported. Measles normally has a fatality rate of about one to three deaths out of every 1,000 children infected.”

Three U.S tick species may cause a mysterious red meat allergy. ScienceNews.org article. Pull quote: “After being outdoors, many people rely on tick checks, scanning their bodies to ensure they’re not inadvertently carrying any bloodsucking critters. For tick-borne illnesses like Lyme disease, Rocky Mountain spotted fever and anaplasmosis, quick identification and tick removal can prevent disease. That’s because the tick must be attached to a person’s body for hours or days to transmit disease-causing bacteria. “That does not seem to be the case with alpha-gal syndrome,” Oltean says. There’s no bacteria being transmitted in alpha-gal syndrome — it’s an allergic response that’s triggered following a tick bite. So it’s possible that a single bite from a tick, even one yanked away immediately, could spark the condition.”

Trump moves raise presidential power questions. TheHill.com article. Pull quote: ““The White House is asserting the power, essentially, to regulate or to deregulate by executive order. That is novel,” said Nina Mendelson, a law professor at the University of Michigan.”

 
/* Use this with templates/template-twocol.html */