Thursday, August 21, 2025

Review – 2 Advisories and 1 Update Published – 8-21-25

Today CISA’s NCCIC-ICS published one control system security advisory and a medical device security advisory for products from Mitsubishi Electric and FUJIFILM. They also published an updated advisory for products from Mitsubishi.

Advisories

Mitsubishi Advisory - This advisory  describes an improper handling of length parameter inconsistency vulnerability in the Mitsubishi MELSEC iQ-F Series CPU module.

FUJIFILM Advisory - This advisory describes an external control of assumed-immutable web parameter vulnerability in the FUJIFILM Synapse Mobility product.

Updates

Mitsubishi Update - This update provides additional information on the Air Conditioning Systems advisory that was originally published on June 26th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-79a - subscription required.

OSHA Publishes 16 Respirator NPRM Comment Extensions

Yesterday the DOL’s Occupational Safety and Health Administration published 16 notices in the Federal Register for extensions of comment periods for notices of proposed rulemakings related  respirator requirements for various OSHA safety standards, aligning those rules with the OSHA respiratory protection standard (29 CFR 1910.134). The related NPRMs were published on July 1st, 2025. These are substances covered in the comment extension notices (first link is to the individual notice and the second to the standard being revised).

• 1,2-Dibromo-3-chloropropane (29 CFR 1910.1044) – OSHA-2025-0019,

• 1,3-Butadiene (29 CFR 1910.1051) – OSHA-2025-0020,

• 13 Carcinogens (29 CFR 1910 subpart Z) – OSHA-2025-0013,

• Acrylonitrile (29 CFR 1910 subpart Z) – OSHA-2025-0017,

• Asbestos (29 CFR 1910 subpart Z) – OSHA-2025-0024,

• Benzene (29 CFR 1910 subpart Z) – OSHA-2025-0023,

• Cadmium (29 CFR 1910 subpart Z) – OSHA-2025-0021,

• Coke Oven Emissions (29 CFR 1910 subpart Z) – OSHA-2025-0014,

• Cotton Dust (29 CFR 1910 subpart Z) – OSHA-2025-0011,

• Ethylene Oxide (29 CFR 1910 subpart Z) – OSHA-2025-0018,

• Formaldehyde (29 CFR 1910 subpart Z) – OSHA-2025-0026,

• Inorganic Arsenic (29 CFR 1910 subpart Z) – OSHA-2025-0016,

• Lead (29 CFR 1910 subpart Z) – OSHA-2025-0022,

• Methylene Chloride (29 CFR 1910 subpart Z) – OSHA-2025-0012,

• Methylenedianiline (29 CFR 1910 subpart Z) – OSHA-2025-0025, and

• Vinyl Chloride (29 CFR 1910 subpart Z) – OSHA-2025-0015

The revised close of comment date for each of the NPRM’s is now November 1st, 2025. Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; docket numbers listed above).

Wednesday, August 20, 2025

Review – HR 3478 Introduced – UAS Destruction

Back in June Rep McGuire (R,VA) introduced HR 3478, the Manned Aircraft Clarification Act. The bill would amend 18 USC 32, clarifying that this statute prohibiting the destruction of aircraft is limited to manned aircraft. It also amends 49 USC 46502, clarifying that the ‘aircraft piracy’ provisions specifically apply to manned aircraft. No new funding is authorized.

McGuire is not a member of the House Judiciary Committee to which this bill was assigned for primary consideration. This means that there is probably not sufficient influence to see the bill considered in Committee. I am not sure that there would be adequate support for these proposed changes for it to advance in Committee if it were considered. There would most likely not be sufficient support for the bill to be considered before the full House under the suspension of the rules process.

Commentary

This bill is an attempt to address the need to use the ‘not withstanding’ language found in most cUAS legislative actions because of the disparate statutes that would have to be ‘violated’ to conduct counter drone operations. Unfortunately, this bill only addresses two of the six US Code sections that need to be dealt with to allow for effective cUAS operations. The other sections of concern are:

18 USC 1030 (computer fraud),

18 USC 1367 (interference with satellites),

18 USC Chapter 119 (wire intercept), and

18 USC Chapter 206 (pen registers).



For more information on the provisions of this bill, including additional commentary on those provisions and alternative considerations, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3478-introduced-uas-destruction - subscription required.

CISA Published 30-day Notice for New Coordinated Disclosure ICR

Today, CISA published a 60-day information collection request (ICR) notice in the Federal Register (90 FR 40638-40639) for a new ICR on Vulnerability Reporting Submission Form. CISA intends to collect this  information as part of their on-going coordinated disclosure process. The 60-day ICR notice was published on October 30, 2024.

CISA continues to provide the following burden estimate:

 

CISA is soliciting public comments on this ICR notice. Normally a person wishing to comment could follow the instructions provided in the Federal Register listing for this notice, but with the current problems being experienced by OMB’s RegInfo web site alternative methods are required. According to OMB’s instructions, comments should be emailed to MBX.OMB.OIRA.ICRComments@omb.eop.gov. The subject line should read: “ICR Comment - 1670-NEW - Vulnerability Reporting Submission Form”. Comments should be submitted by September 19th, 2025.

Review - Bills Introduced – 8-19-25

Yesterday, with the House and Senate meeting in pro forma session, there were 22 bills were introduced. One of those bills may receive additional coverage in this blog:

HR 5000 To amend title 5, United States Code, to limit the use of educational requirements or qualifications in evaluating candidates for certain cybersecurity positions in the competitive service, and for other purposes. Mace, Nancy [Rep.-R-SC-1]

 

For more information on these bills, including legislative history for similar bills in the 118th, as well as a mention-in-passing about an airline cabin air protection bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-8-19-25 - subscription required.

CISA Publishes 30-day Notice for KEV ICR

Today, CISA published a 30-day information collection request notice in the Federal Register (90 FR 40637-40638) for “Actively Exploited Vulnerability Submission Form”. The dedicated form on the CISA website will allow for external reporting of vulnerabilities that the reporting entity believe to be Known Exploited Vulnerabilities (KEV) eligible. The 60-day ICR notice was published on February 29th, 2025. No comments were received for the 60-day ICR notice.

CISA continues to report the following burden estimate:

 

CISA is soliciting public comments on this ICR notice. Normally a person wishing to comment could follow the instructions provided in the Federal Register listing for this notice, but with the current problems being experienced by OMB’s RegInfo web site alternative methods are required. According to OMB’s instructions, comments should be emailed to MBX.OMB.OIRA.ICRComments@omb.eop.gov. The subject line should read: “ICR Comment - 1670-NEW - Actively Exploited Vulnerability Submission Form”. Comments should be submitted by September 19th, 2025.

Tuesday, August 19, 2025

Short Takes – 8-19-25

EPA, WaterISAC caution utilities on drone threats and cyber risks in evolving security landscape. IndustrialCyber.co article. Pull quote: “In the latest quarterly edition of the National Security Information Sharing Bulletin (ISB), the agencies warn that the heightened threat environment is increasing operational risks for water and wastewater utilities across the full spectrum of hazards, from cyberattacks to physical security threats and natural disasters. The issue underscores how emerging technologies are reshaping the risk landscape, while also outlining recent cybersecurity concerns for utilities and recommending measures to strengthen defenses.”

Data that taxpayers have paid for and rely on is disappearing – here’s how it’s happening and what you can do about it. TheConversation.com article. Pull quote: “While the pace of intentional government data removal appears to have slowed, it hasn’t stopped. New datasets under threat of disappearing are being rescued daily. Restructured federal agencies and related changes to – or neglect of – official websites can make data difficult or impossible to find.”

Climate Change is Coming for Your Bananas. Time.com article.  Pull quote: “For banana lovers, one silver lining remains. Though banana prices might be on the rise, experts predict that bananas will keep their title as the most affordable fruit. “I think that even over the next decade or so, the banana will still be the cheapest fruit on the shelf,” says Abu-Ghazaleh, whose company is a major fruit supplier. "The consumer will still have the opportunity to enjoy a very affordable fruit compared to any other.””

After recent tests, China appears likely to beat the United States back to the Moon. ArsTechnica.com interview. Pull quote: “By contrast, the Chinese are stable, systematic. They pursue a given goal (e.g., human spaceflight, a space station) over decades, with persistence and programmatic (both budgetarily and in terms of goals) stability. So I expect that the Chinese will put a Chinese person on the Moon by 2030 and follow that with additional crewed and unmanned facilities. This will be supported by a built-out infrastructure of lunar PNT/comms. The US will almost certainly put people on the Moon in a landing in the next several years, but then what? Is Lunar Gateway going to be real? How often will the US go to the Moon, as the Chinese go over and over?”

A review of cybersecurity incidents in the food and agriculture sector. ScienceDirectAssets.com article. Pull quote: “A smart farm is a cyber–physical system whose operations can be monitored and controlled by a computer and communication system using a set of networked agents [8,9]. These network agents can be sensors, linear actuators, control processing units, and communication devices [10]. As noted by Zanella et al. [11], smart farming utilizes emerging technologies, and due to their complexity, it incorporates all the security problems present in these technologies into smart farms, making them vulnerable to security threats.”

SpaceX completes investigation into recent Starship failures, clears the way for Flight 10. Space.com article. Pull quote: “The next iteration of Super Heavy and Starship will need to pick up the pace to qualify in time to fly as part of NASA's Artemis 3 moon mission. NASA selected Starship as the lunar lander for the mission, which will put astronauts on the moon for the first time since the final Apollo mission in 1972. NASA is currently targeting 2027 for the launch of Artemis 3, and Starship's recent test-flight issues are unlikely to quell ongoing concerns at the space agency that Starship's development may delay the mission further.”

EO 14336 - Ensuring American Pharmaceutical Supply Chain Resilience by Filling the Strategic Active Pharmaceutical Ingredients Reserve, Federal Register.

EO 14337 - Revocation of Executive Order on Competition [Executive Order 14036 of July 9, 2021], Federal Register.

 

This month, I am offering a reduced-price subscription to my CFSN Detailed Analysis newsletter, 40% off the annual subscription rate. Sale ends on August 31st, 2025.

 
/* Use this with templates/template-twocol.html */