Sunday, June 22, 2025

Review – HR 4016 Introduced – FY 2026 DOD Spending

Last week Rep Calvert (R,CA) introduced HR 4016, the Department of Defense Appropriations Act, 2026. The House Appropriations Committee published their Report on the bill. In addition to setting spending for DOD, the bill includes two minor cyber related mentions as well as a brief chemical weapons destruction entry. There are three cybersecurity discussions in the Report. The bill passed in Committee on a party-line vote.

Moving Forward

In recent years spending bills have been a pro forma statement of policy by the ruling party as continuing resolutions and year-end deals have become the funding mechanisms de jure. The problem has been exacerbated since the Republicans came back into control of the House in that they have had problems even passing bills in the House because of intraparty conflicts.

This year may be different, at least for this bill. With the attacks on Iran last night, we might see a stronger push to support the Pentagon in its ongoing war role. This bill passed in Committee on a party-line vote, and I would expect it to receive similar support on the floor of the House. The Senate has not yet started crafting spending bills, so it is too early to tell how far apart the two houses of congress are. In any case the 60-vote Senate is unlikely to pass this bill as it stands, but there is still plenty of time between now and September 30th to work out reasonable differences. The unreasonable differences could still remain a problem.

 

For more details about the cybersecurity and chemical safety issues see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4016-introduced-fy-2026-dod-spending - subscription required.

War With Iran – The Response

 With the U.S. attack last night on the nuclear facilities in Iran, we (both as a country and as individuals) need to start thinking about what sort of response to expect from Iran. Anyone that thinks that Iran is going to do nothing in response to a physical attack upon their soil by the “Great Satan” is guilty of wishful thinking at its worst.

Pundits today are certainly going to discuss the threat to US personnel (military and otherwise) stationed in, or operating within, the Gulf States, Diego Garcia, or Isreal, and that cannot be ignored. While my prayers and support go out to those personnel, that is beyond the scope of this blog. My concerns are more focused on the potential for Iranian attacks on facilities here in the United States. We probably do not have to worry about direct military attacks by the Republican Guards forces (though I must admit that drone attacks like those seen being conducted by Ukraine against Russia remain a distinct possibility given Iranian drone technology), but terror attacks and cyber attacks are a significant concern.

Terror attacks by their very nature are hard to predict. Would Iran go after direct attacks on the people of the United States in a true terror campaign? The weapons available to them are many (including those drones that I mentioned above) and it would be difficult to defend against such attacks by a nation state. Or would they specifically target military and critical infrastructure targets? If it is the later type targets, then we will have to be concerned about cyberattacks as part of that terror campaign.

Unfortunately, attacks against chemical facilities would fit into both of these scenarios. Facilities that hold significant quantities of what the now defunct CFATS program called ‘release threat’ chemicals (toxic, flammable, and explosive chemicals) could be attacked to cause great physical harm to surrounding population centers, as well as having a potential outsized impact on the national economy. More sophisticated attacks on chemical facilities could be designed with less direct impact on civilians and a more targeted attack on military capabilities or the economy. And, of course, a pure terror campaign could first target chemical facilities that house explosive or chemical weapon precursors for theft of those chemicals to empower WMD attacks on the population.

While the CFATS program was never designed to protect against nation state level attacks on chemical facilities, it did make those facilities harder to attack. More importantly it provided a cadre of federal assistance to those facilities and a way to funnel more resources to the most dangerous targets. Unfortunately, those resources are no longer available, and those defenses are almost certainly weakened by the loss of that program. While it would not be easy to stand that program back up, Congress certainly needs to look at emergency measures to do so, before Iran decides to use our chemical facilities as a weapon against us.

Saturday, June 21, 2025

Short Takes – 6-21-25 – War with Iran

U.S. Enters the War with Iran - Here are the latest developments. NYTimes.com article.  Pull quote: “Iran, which has refrained so far from direct attacks on U.S. troops and interests in the Middle East, has warned that American entry into war would bring retaliation, raising fears around the region about the danger of a widening war. But what form that response would take is unclear. Analysts have also speculated that Iran could react by attacking U.S. troops in the region, or by accelerating its nuclear program — assuming the program survives U.S. bombing.”

What we know about the three Iranian nuclear sites struck by the US. CNN.com article. Pull quote: “The main halls [at Fordow] are an estimated 80 to 90 meters (around 262 to 295 feet) beneath the ground, making it very difficult to destroy the facility from air. The US is the only country with the kind of bomb required to strike that deep, Israeli officials and independent reports have previously said. However analysts have warned even those bombs might not be enough.”

Trump says Iran’s key nuclear sites were ‘completely and fully obliterated’ by U.S. strikes. APNews.com article. Pull quote: “The White House and Pentagon did not immediately elaborate on the operation. But Fox News host Sean Hannity said shortly after 9 p.m. Eastern that he had spoken with Trump and that six bunker buster bombs were used on the Fordo facility. Hannity said 30 Tomahawk missiles fired by U.S. submarines 400 miles away struck the Iranian nuclear sites of Natanz and Isfahan.”

Congressional leaders react to Trump ordering strike attack on Iran. ABCNews.com article. Pull quote: “Pennsylvania Democratic Sen. John Fetterman said on X, "As I’ve long maintained, this was the correct move by @POTUS. Iran is the world’s leading sponsor of terrorism and cannot have nuclear capabilities. I’m grateful for and salute the finest military in the world. 🇺🇸"”

Trump declares 'very successful attack' on Iran's nuclear program as US forces strike 3 key sites. FoxNews.com article. Pull quote: “A senior White House official told Fox News the U.S. gave Israel a heads-up before the strikes, and President Trump spoke with Israeli Prime Minister Benjamin Netanyahu following the attacks.”

U.S. warplanes carry out ‘successful’ strikes on three nuclear sites in Iran, Trump says. WashingtonPost.com article. Pull quote: ““Tonight’s [strike] was the most difficult of them all by far, and perhaps the most lethal,” Trump said. “But if peace does not come quickly, we will go after those other targets with precision, speed and skill. Most of them can be taken out in a matter of minutes.””

Chemical Incident Reporting – Week of 6-14-25

NOTE: See here for series background.

Texas City, TX – 6-14-25

Local News Report: Here, here, here, and here.

There was a fire at a refinery in Texas. There was a shelter-in-place order for local residents. No injuries have been reported and there is no discussion about the amount of damages at the facility.

Not CSB reportable.

GA/SC Border – 6-14-25

Local News Report: Here, here, and here.

There was fuel truck crash under I-20 near the Georgia South Carolina border. The resulting fire severely damaged the overpass which will have to be replaced. No injuries reported.

Not CSB reportable, this is a transportation related incident.

Review – CSB Updated Status of 5 Investigation Recommendations – 6-18-25

Yesterday the Chemical Safety Board (CSB) updated their Recent Recommendation Status Updates page, closing five recommendations with acceptable alternative actions. These actions left 133 of 1019 recommendations open. The CSB took these actions on June 18th, 2025.

The five recommendations recently addressed are:

Macondo Blowout and Explosion - 2010-10-I-OS-3 - American Petroleum Institute (API),

Macondo Blowout and Explosion - 2010-10-I-OS-1 - Bureau of Safety and Environmental Enforcement (BSEE),

Macondo Blowout and Explosion - 2010-10-I-OS-2 - BSEE,

Macondo Blowout and Explosion - 2010-10-I-OS-11- Department of the Interior (DOI), and

Macondo Blowout and Explosion - 2010-10-I-OS-12 - DOI

Commentary

In several instances, while noting that the actions taken “would not have prevented the Macondo incident”, the Board concluded that, “DOI-BSEE has done a tremendous amount of work toward addressing the intent of R11. DOI-BSEE implemented several initiatives following the Macondo incident, several of  which address a majority of the objectives envisioned by the Board and provide an equivalent level of safety.”

This is an example of why it is so important to have these investigations being done by a non-regulatory body. They have more flexibility to judge the adequacy (or inadequacy) of actions without regard to the letter of the recommendations made or existing regulatory or statutory requirements. Instead, they can look at the reality of the situation to determine if an adequate (and honest) effort has been taken to improve the safety of chemical operations.

 

For more details about the actions taken and the CSB’s actions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/csb-updated-status-of-5-investigation - subscription required.

Review – Public ICS Disclosures – Week of 6-14-25

This week we have five vendor disclosures from Delta Electronics, HP, Sick, VMware, and WAGO (2). We also have three vendor updates from Moxa and Siemens (2). There are seven researcher reports for vulnerabilities in products from Fuji Electric. Finally, we have six exploits for vulnerabilities in products from Advantech, FortiGuard, Palo Alto Networks, Parrot, SIMCom, and WAGO.

Advisories

Delta Advisory - Delta published an advisory that discusses a code injection vulnerability (listed in the CISA Known Exploited Vulnerabilities catalog) in their Delta Academy site (https://preprod-secai-academy￾flow.deltaww.com).

HP Advisory - HP published an advisory that discusses an out-of-bounds read vulnerability in their Notebook and Desktop PCs.

Sick Advisory - Sick published an advisory that describes 20 vulnerabilities in their Field Analytics and Media Server products.

VMware Advisory - Broadcom published a software release notice for their VMware Tanzu Greenplum 7.5.0 product that addresses 21 vulnerabilities

WAGO Advisory #1 - CERT-VDE published an advisory that describes two vulnerabilities in the device manager component of multiple WAGO products.

WAGO Advisory #2 - CERT-VDE published an advisory that discusses 15 vulnerabilities in the WAGO Edge Controller product.

Updates

Moxa Update - Moxa published an update for their Multiple PT Switches advisory that was originally published on January 19th, 2025, and most recently updated on February 26th, 2025.

Siemens Update # 1 - Siemens published an update for their Questa and ModelSim advisory that was originally published on October 8th, 2024.

Siemens Update #2 - Siemens published an update for their Elspec G5 Digital Fault Recorder advisory that was originally published on June 10th, 2025.

Researcher Reports

Fuji Reports - Zero Day Initiative published seven reports of vulnerabilities in the Fuji Smart Editor.

Exploits

Advantech - Jay Turla published an exploit for a command injection vulnerability in the Advantech WISE 4060LAN.

FortiGuard Exploit - Shahid Parvez Hakim published an exploit for an insufficient session expiration vulnerability in the FortiGuard FortiOS SSL-VPN.

Palo Alto Networks Exploit - Cody Sixteen published a Metasploit module for a denial of service vulnerability in the Palo Alto Networks PAN-OS product.

Parrot Exploit - Mohammed Idrees Banyamer published an exploit for a kernel panic vulnerability in the Parrot QRD, Parrot Alpha-M, DJI QRD, and DJI Alpha-M drone operating systems.

SIMCom Exploit - SEC Consult published an exploit for a hidden functionality vulnerability in the SIMCom SIM7600G Modem.

WAGO Exploit - Ibrahimsql published an exploit for an OS command injection vulnerability in unnamed WAGO products.

 

For more information on these disclosures, including links to 3rd party advisories, and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-e18 - subscription required.

Friday, June 20, 2025

Short Takes – 6-20-25

Senate Parliamentarian Advises Several Provisions in Republicans’ “One Big, Beautiful Bill” Are Not Permissible, Subject to Byrd Rule. Budget.Senate.gov Ranking Member press release. Pull quote: ““Tonight, the Senate Parliamentarian advised that certain provisions in the Republicans’ One Big, Beautiful Betrayal will be subject to the Byrd Rule – ultimately meaning they will need to be stripped from the bill to ensure it complies with the rules of reconciliation. As much as Senate Republicans would prefer to throw out the rule book and advance their families lose and billionaires win agenda, there are rules that must be followed and Democrats are making sure those rules are enforced,” said Ranking Member Jeff Merkley. “We will continue examining every provision in this Great Betrayal of a bill and will scrutinize it to the furthest extent.””

How Rand Paul got sidelined by fellow Republicans. Politico.com article. Pull quote: “Paul has made clear repeatedly he isn’t planning to vote for the party-line tax and spending bill anyway, giving leadership few reasons to try and play nice. Yet the decision by senior Senate Republicans to undermine a committee chair in such a way marks a dramatic departure from standard Senate procedure. It also reflects the extent to which Paul has become an ideological island, despite him holding a committee gavel thanks to the chamber’s rules around seniority.”

NIH launching long-term health studies of East Palestine train crash. TheHill.com article. Trump Administration funded program. Pull quote: “The project aims to evaluate the impacts of exposure to chemicals of concern in East Palestine and its surrounding communities in the short and long term. The studies will also focus on public health tracking and surveillance of the community’s health conditions, the agency said.”

We may finally know how Tylenol works — and it's not how we thought. LiveScience.com article. Pull quote: “Previous research found that AM404 can act in the central nervous system — the brain and spinal cord. But the new study, published June 4 in the journal PNAS, reveals that AM404 also affects the peripheral nervous system, where pain signals originate.”

Unprecedented pentacoordinate oxygen cluster isn’t so new after all. ChemistryWorld.com article. Chem Geeky article. Pull quote: “Dreuw, who’s now at Heidelberg University in Germany, says he was surprised by the peculiarity of the Shanxi team’s structure: ‘But when you think about it, then it’s immediately clear that this should be stable.’ Advances in computational tools mean scientists can now efficiently search for minima across the full potential energy surface, something that was unrealistic back in 2006 [when a similar construct was apparently incorrectly characterized]. ‘Now you have programs where you can sample whole ensembles … and find structures that you had not expected, such as this one,’ Dreuw adds.”
 
/* Use this with templates/template-twocol.html */