Thursday, November 20, 2025

Review – 6 Advisories Published – 11-20-25

Today CISA’s NCCIC-ICS published six control system security advisories for products from Emerson, Festo (2), Opto 22, ICAM365 and Automated Logic.

Advisories

Emerson Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Emerson Appleton UPSMON-PRO.

Festo Advisory #1 - This advisory discusses an improper input validation vulnerability in the Festo Didactic products.

Festo Advisory #2 - This advisory describes a hidden functionality vulnerability in the Festo MSE6-C2M-5000 product line.

NOTE: I briefly discussed this vulnerability on September 9th, 2023. CERT-VDE updated the Festo advisory (administrative and format changes) on October 1st, 2025.

Opto 22 Advisory - This advisory describes an OS command injection vulnerability in the Opto 22 GRV Programmable Logic Controllers.

ICAM365 Advisory - This advisory describes two missing authentication for critical function vulnerabilities in the ICAM365 ROBOT PT Camera P201 and Night Vision Camera QC021.

Automated Logic Advisory - This advisory describes two vulnerabilities in multiple Automated Logic (and Carrier) products.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-11-20-25 - subscription required.

Review - Bills Introduced – 11-19-25

Yesterday, with both the House and Senate in Washington, there were 87 bills introduced. One of those bills may receive additional coverage in this blog:

S 3202 A bill to direct the Director of the National Security Agency to develop guidance to secure artificial intelligence related technologies, and for other purposes. Young, Todd [Sen.-R-IN]

Space Geek Legislation

I would like to mention one bill under my limited Space Geek coverage in this blog:

S 3198 A bill to establish the National Institute for Space Research, and for other purposes. Cornyn, John [Sen.-R-TX] 

 

For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a mention in passing concerning two bills addressing conflicts of interest in the rulemaking process, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-11-19-25 - subscription required.

Wednesday, November 19, 2025

Short Takes – 11-19-25 – Federal Register Edition

United States v. Hewlett Packard Enterprise Co. and Juniper Networks, Inc.; Response of the United States to Public Comments on the Proposed Final Judgments. Federal Register DOJ notice. Summary: “Notice is hereby given pursuant to the Antitrust Procedures and Penalties Act, 15 U.S.C. 16(b)-(h), that the Response of the United States to Public Comments on the Proposed Final Judgment in United States of America v. Hewlett Packard Enterprise Co. and Juniper Networks, Inc., Civil Case No. 5:25-CV-00951-PCP, has been filed in the United States District Court for the Northern District of California, together with copies of the public comments.”

1,2-Dichloroethane; Draft Risk Evaluation Under the Toxic Substances Control Act (TSCA); Notice of Availability and Request for Comment. Federal Register EPA notice. Summary: “The Environmental Protection Agency (EPA or Agency) is announcing the availability of and seeking public comment on a draft risk evaluation under the Toxic Substances Control Act (TSCA) for 1,2-dichloroethane (CASRN 107-06-2). The purpose of risk evaluations under TSCA is to determine whether a chemical substance presents an unreasonable risk of injury to health or the environment under the conditions of use (COUs), including unreasonable risk to potentially exposed or susceptible subpopulations identified as relevant to the risk evaluation by EPA, and without consideration of costs or non-risk factors. EPA used the best available science to prepare this draft risk evaluation and to preliminarily determine, based on the weight of scientific evidence, that 1,2-dichloroethane poses unreasonable risk to human health and the environment driven primarily by certain COUs analyzed in the draft risk evaluation.”

Notice of Guidance: Transporting Hazardous Materials by Unmanned Aircraft Systems (UAS). Federal Register FAA notice. Summary: “This notice announces the availability of a joint FAA-PHMSA guidance document on transporting hazardous materials by Unmanned Aircraft Systems (UAS). This document is available at: https://www.faa.gov/​hazmat/​air_​carriers/​operations/​drones.”

EO 14359 - Fostering the Future for American Children and Families, Federal Register.

Review - Bills Introduced – 11-18-25

Yesterday, with both the House and Senate in session, there were 81 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 6089 Biomanufacturing Excellence Act of 2025 Houlahan, Chrissy [Rep.-D-PA-6]

S 3188 A bill to establish a Biopharmaceutical Center of Excellence, and for other purposes. Coons, Christopher A. [Sen.-D-DE]

 

For more information on these bills, including legislative history for similar bills in the 118th Congress, including a mention in passing about two bill addressing civil restitution for constitutional rights violations by law enforcement, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-11-18-25 - subscription required.

CSB Adds AES Explosion to the List of Open Investigations – 11-18-25

Yesterday the Chemical Safety Board (CSB) added the investigation of the October 10th, 2025 Accurate Energetic Systems (AES) Fatal Explosion in McEwen, TN, to their list of open investigations. The Board had announced on October 27th, 2025, that they had sent a team of investigators to the site. This brings the total number of open investigations back up to nine, with the oldest open investigation dating back to July 2023.

I would not be surprised to see an investigation update for this incident in the next week or so.

OPM Sends RIF NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the Office of Personnel Management on “Reduction in Force”.

According to the listing for this rulemaking in the Spring 2025 Unified Agenda:

“The Office of Personnel Management is proposing to modify the regulations for reduction in force (RIF) to amend the retention factors to prioritize performance over length of service when determining which employees will be retained in a RIF and streamline the RIF process.”

The current civil service program was specifically designed to prevent federal jobs from being part of a political patronage system. While recognizing that above a certain level, management of the federal bureaucracy is political in nature (and thus requiring presidential appointment), most federal jobs require some level of practical expertise and experience to fairly and efficiently operate and oversee federal programs. Those jobs should not be subject to political litmus tests that change with every change in administration.

While I am sure that the folks at the Heritage Foundation have done an admirable job of cloaking their intent to rid the swamp of any liberal employees in language that would appear to be purely focused on efficiency and efficacy, the brief history of this administration makes it clear that ‘performance’ in the 47th Administration means fealty to, and adoration of, the royal executive. That makes this rulemaking suspect at best.

This rulemaking is outside of the typical scope of coverage of this blog, so I will probably not devote any significant coverage to it, but I will certainly mention its publication in the appropriate Short Takes post.

Tuesday, November 18, 2025

CISA Adds FortiGuard Vulnerability to KEV Catalog – 11-18-25

Today CISA announced that they had added an OS command injection vulnerability in the FortiGuard FortiWeb products to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard reported the vulnerability today, noting that it had been exploited in the wild. The vulnerability was reported by Jason McFadyen from Trend Research of Trend Micro. 

CISA has directed federal agencies that are using the affected FortiWeb products to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” CISA has set November 25th, 2025 as the deadline for agencies to comply.

 
/* Use this with templates/template-twocol.html */