Saturday, November 2, 2024

CRS Reports – Week of 10-26-24 – Supreme Court Jurisdiction

This week the Congressional Research Service (CRS) published a report on: “The Exceptions Clause and Congressional Control over Supreme Court Jurisdiction”. The report looks at the constitutional differences between the different types of cases that the Supreme Court may here. It describes the cases over which the Court has ‘original jurisdiction’, cases that are brought directly to the Court dealing with Ambassadors, other public Ministers and Consuls, and those in which a State shall be Party. All other cases reach the Court on appeal of judgements of the lessor courts. It takes special pains to discuss the fact that the Constitution limits those appeals under the ‘Exceptions Clause’ (Article III, Section 2, Clause 2) by making those appeals subject to ““such Exceptions, and … Regulations as the Congress shall make”.

The ‘Considerations for Congress’ section of the report is much more detailed than typically seen in these CRS reports. Instead of laying out specific actions that Congress could/should consider in respect to this topic, the Report continues the legal discussion about practical limits on the topics Congress could expect try to address in regulating the topics of potential litigation before the Court.

To anyone that has taken any courses on constitutional law (and I have taken a handful of undergraduate courses when I was a political science major), this discussion is hardly unusual, but for most folks (including the majority of congresscritters) it demonstrates how complicated these matters can get. Still, this relatively short report (20 pages) is well worth reading. 

Chemical Incident Reporting – Week of 10-26-24

NOTE: See here for series background.

Davenport, IA – 10-10-24

Local News Report: Here, here, and here.

There was an anhydrous ammonia leak at a food processing facility. The leak was isolated and the employees evacuated. No injuries were reported.

Not CSB reportable.

Litchfield, CT – 10-23-24

Local News Reports: Here, here, and here.

There was an explosion in a sewage treatment sludge tank, reportedly due to flammable gas produced by sludge decomposition reaching unidentified ignition source. No injuries were reported and there was some damage to storage tank lid.

Not CSB reportable.

Alcoa, TN – 10-25-24

Local News Report: Here, here, and here

There was an anhydrous ammonia leak at a food processing facility. The leak was due to a malfunctioning valve. No injuries were reported. There is no mention of damages in the articles.

Not CSB reportable.

Fredericktown, Mo – 10-30-24

Local News Report: Here, here, here, and here.

There was a fire with explosions at a Lithium-ion battery recycling facility. Evacuations and sheter-in-place orders have been issued. No injuries have been reported. No damage estimates have yet been published. The local fire department has published a down-wind advisory map.

Probable CSB reportable.

Hayfield, MN – 10-30-24

Local News Report: Here, here, here, and here.

A rural anhydrous ammonia storage tank began leaking, causing a local road to be closed while the leak was fixed. One deputy was taken to a local hospital for exposure related concerns, but was released without being admitted.

Not CSB reportable.

Review – Public ICS Disclosures – Week of 10-25-24 – Part 1

This week, for Part 1, we have 20 vendor disclosures from Broadcom (8), Beckhoff, Bosch, GE Vernova (2), Hikvision, Hitachi Energy (2), HP (3), HPE, and Omron.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses a function call with incorrect argument type vulnerability in their SANnav product.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an integer overflow or wrap around vulnerability in their SANnav product.

Broadcom Advisory #3 - Broadcom published an advisory that discusses nine vulnerabilities (three with publicly available exploits) in their Fabric OS, SANnav, and ASCG products.

Broadcom Advisory #4 - Broadcom published an advisory that discusses an incorrect resource transfer between spheres vulnerability in their SANnav product.

Broadcom Advisory #5 - Broadcom published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their SANnav product.

Broadcom Advisory #6 - Broadcom published an advisory that discusses an incomplete cleanup vulnerability in their SANnav product.

Broadcom Advisory #7 - Broadcom published an advisory that discusses three inadequately described vulnerabilities in their SANnav product.

Broadcom Advisory #8 - Broadcom published an advisory that discusses six vulnerabilities in their SANnav products.

Beckhoff Advisory - CERT-VDE published an advisory that describes an OS command injection vulnerability in the Beckhoff TwinCAT Package Manager.

Bosch Advisory - Bosch published an advisory that describes an uncontrolled resource consumption vulnerability in the PROFINET stack implementation of the IndraDrive.

GE Vernova Advisory #1 - GE published an advisory that discusses two vulnerabilities in Control Server installations that use VMware vCenter Server.

GE Vernova Advisory #2 - GE published an advisory that describes a side-channel key recovery vulnerability in YubiKey’s in customers using Xona devices and those using YubiKey authentication for certain HMI deployments.

Hikvision Advisory - JP- CERT published an advisory that announces firmware updates for multiple network cameras as a security enhancement, changing the behavior to communicate with Dynamic DNS services, to prevent cleartext transmission.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes two vulnerabilities in their TRO600 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses two vulnerabilities (both with publicly available exploits) in their MSM product web services.

HP Advisory #1 - HP published an advisory that discusses the PixieFail vulnerabilities.

HP Advisory #2 - HP published an advisory that discusses 353 vulnerabilities in their ThinPro product.

HP Advisory #3 - HP published an advisory that describes an out-of-bounds write vulnerability in their Smart Universal Printing Driver.

HPE Advisory - HPE published an advisory that discusses the regreSSHion vulnerability.

Omron Advisory - Omron published an advisory that describes an improper authorization vulnerability in their Sysmac Studio product.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-25a - subscription required.

Friday, November 1, 2024

Short Takes – 11-1-24

WHO sounds pandemic alarm as world's deadliest infection at highest level since records began. GNNews.com article. Pull quote: “Global funding for TB prevention and care decreased further in 2023, falling far short of targets. Low-and middle-income countries, which bear 98 per cent of the TB burden, faced significant funding shortages.”

What is happening with Boeing’s Starliner spacecraft? ArsTechnica.com article. Pull quote: “Does NASA actually need Starliner? Officials with the space agency have been consistently supportive of Boeing, and expressed a preference to work with the company on continuing certification work. Because the spacecraft will now fly a human mission no earlier than 2026, it would only be available for five or fewer years of the space station's remaining lifetime.”

Public Safety and Homeland Security Bureau Announces 15-Business Day Filing Window for Cybersecurity Labeling Administrator and Lead Administrator Applications; Correction. Federal Register FCC final rule correction notice. Corrected effective date: “Effective date: November 20, 2024, except for amendment 3 (47 CFR 8.220(f)(14)) which is delayed indefinitely until the Office of Management and Budget has completed review under the Paperwork Reduction Act. The Commission will publish a document in the Federal Register announcing that effective date.”

Review - S 5276 Introduced – SRM Industrial Base

Last month, Sen Cornyn (R,TX) introduced S 5276, the Solid Propulsion Enhancement and Advancement for Readiness (SPEAR) Act of 2024. The bill would require DOD to submit to Congress a “roadmap for the future desired state for the solid rocket motor (SRM) industrial base.” No new funding would be authorized by this legislation.

Moving Forward

While Cornyn is not a member of the Senate Armed Services Committee to which this bill was assigned for consideration, one of his two cosponsors {Wicker (R,MS)} is the Ranking Member of the Committee. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in the proposed legislation that would engender any organized opposition. I suspect that the bill would receive significant bipartisan support, but this late in the session, that will probably not be sufficient to see the bill considered before the end of the year.

 

For more information about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5276-introduced - subscription required.

NOTE: This bill is being covered here as part of the ‘Space Geek’ expansion of the scope of this blog. I am still working on determining how extensive that expansion will be.


Transportation Chemical Incidents – Week of 9-28-24

Reporting Background

See this post for explanation, with the most recent update here (removed from paywall).

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency.

Incidents Summary

• Number of incidents – 588 (561 highway, 21 air, 6 rail, 0 water)

• Serious incidents – 6 (4 Bulk release, 2 evacuation, 2 injury, 0 death, 0 major artery closed, 3 fire/explosion, 24 no release)

• Largest container involved – 30,520-gal DOT 117J100W Railcar {Alcohols, N.O.S.} Six manway bolts loose.

• Largest amount spilled – 412.6-gal Plastic drums {Sodium Bisulfite, Solution} Drum punctured by exposed nail in pallet. (Note: with just one drum affected, the reported amount “3301” lbs should have been something on the order of 300)

NOTE: Links above are to Form 5800.1 for the described incidents.

Most Interesting Chemical: N-Aminoethylpiperazine – A colorless liquid with a faint fishlike odor. Flash point 199°F. Corrosive to tissue. Toxic oxides of nitrogen are produced by combustion. (Source: CameoChemicals.NOAA.gov). It is used as an epoxy curing agent, and is used in the manufacture of pharmaceuticals and synthetic fibers.



Review - CSB Updates Recommendation Response Status – 10-23-24

Yesterday, the Chemical Safety Board updated their Recent Recommendation Status Updates page to reflect changes to ten open recommendations that were made as a result of four separate closed investigations. Eight of those recommendations were closed. The changes were approved at the recent public meeting of the Board. The updated recommendations included:

• Loy-Lange Box Company Pressure Vessel Explosion – 2017-04-I-MO-R8 - Open – Acceptable Response,

• Evergreen Packaging Paper Mill – Fire During Hot Work – 2020-07-I-NC-R3 - Closed – No Longer Applicable

• Evergreen Packaging Paper Mill – Fire During Hot Work – 2020-07-I-NC-R4 - Closed – No Longer Applicable

• Evergreen Packaging Paper Mill – Fire During Hot Work – 2020-07-I-NC-R7 - Closed – Acceptable Action

• Evergreen Packaging Paper Mill – Fire During Hot Work – 2020-07-I-NC-R8 - Closed – Acceptable Action

• Caribbean Petroleum Refining Tank Explosion and Fire – 2010-02-I-PR-R3 - Closed – Acceptable Action

• Husky Energy Superior Refinery Explosion and Fire – 2018-02-I-WI-R8 - Closed – Acceptable Action

• Husky Energy Superior Refinery Explosion and Fire – 2018-02-I-WI-R9 - Closed – Acceptable Action

• Husky Energy Superior Refinery Explosion and Fire – 2018-02-I-WI-R10 - Open – Acceptable Response

 

For more information about these incident response actions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/csb-updates-recommendation-response - subscription required.

 
/* Use this with templates/template-twocol.html */