Saturday, December 16, 2023

CRS Reports – Week of 12-16-23 – Cyber in War

This week the Congressional Research Service (CRS) published three reports dealing with cyber operations and warfare:

Defense Primer: Cyberspace Operations,

Defense Primer: Operations in the Information Environment, and

Use of Force in Cyberspace

Each of these reports deal with overlapping, yet separate looks at various aspects of cyber operations. All three were written by Catherine A. Theohary, a CRS Specialist in National Security Policy, Cyber and Information Operations. This allows for a certain level of coherency in the discussion that might not really reflect a coherent policy across the government.

Remembering that the purpose of the CRS is to provide information to Congress to inform the legislative process, it is interesting to note that that none of these three reports contains a discussion about how Congress can influence these cyber operations.

 

Another important topic that is essentially missing from these reports is a discussion about cyber-physical operations. While tangentially discussed in the ‘Use of Force in Cyberspace’ report, Theohary does not move past the discussion about cyber-physical equivalence, ignoring a discussion about the possible scope of cyber-physical actions and how they could influence or supplement conventional military operations.

Chemical Incident Reporting – Week of 12-9-23

NOTE: See here for series background.

Homewood, AL – 12-9-23

Local News Reports: Here, here, here, and here.

Anhydrous ammonia leak at ice cream manufacturing facility. No reports of injuries or damage. Very little information.

Probably not a CSB reportable.

Review – Public ICS Disclosures – Week of 12-9-23 – Part 1 –

This week we have 22 vendor disclosures from ABB, Beckhoff, BD (2), Bosch (2), Cisco, FortiGuard (3), Frauscher, HPE (3), JTEKT, and Palo Alto Networks (7).

Advisories

ABB Advisory - ABB published an advisory that discusses the Apache ActiveMQ deserialization of untrusted data vulnerability that is listed on the CISA Known Exploited Vulnerabilities Catalog.

Beckhoff Advisory – CERT-VDE published an advisory that describes an open redirect vulnerability in the Beckhoff TwinCAT/BSD product.

BD Advisory #1 - BD published an advisory that discusses the Windows 7 Operating System End of Life Notice.

BD Advisory #2 - BD published an advisory that discusses an out-of-bounds write vulnerability that is listed in the CISA KEV catalog.

Bosch Advisory #1 - Bosch published an advisory that describes two improper handling of a malformed API request vulnerabilities in their BT software products

Bosch Advisory #2 - Bosch published an advisory that describes a command injection vulnerability in their Bosch IP Cameras.

Cisco Advisory - Cisco published an advisory that discusses the recent Apache Struts vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a use of externally controlled format string vulnerability in their FortiOS, FortiProxy and FortiPAM products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a double free vulnerability in their FortiOS and FortiPAM HTTPSd daemon.

Frauscher Advisory - CERT-VDE published an advisory that describes a code injection vulnerability in the Frauscher FDS102 for FAdC/FAdCi.

HPE Advisory #1 - HPE published an advisory that discusses seven vulnerabilities in their Cray Programming Environment.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities in their Intelligent Management Center (iMC) product.

HPE Advisory #3 - HPE published an advisory that discusses 14 vulnerabilities in their Virtualized Telecommunication Management Information Platform (vTeMIP) application.

JTEKT Advisory - JTEKT published an advisory that describes four uncontrolled resource consumption vulnerabilities in their HMI GC-A2 series products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a weakness introduced during design vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an argument injection vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability in their PAS-OS product.

Palo Alto Networks Advisory #6 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their PAN-OS product.

Palo Alto Networks Adviosry #7 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS product.

 

For more details about these disclosures, including links to 3rd party advisories, vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-9fa https://tinyurl.com/yty8yuyt- subscription required. 

Friday, December 15, 2023

Short Takes – 12-15-23

Human Brain Cells on a Chip Can Recognize Speech And Do Simple Math. ScienceAlert.com article. Pull quote: “There are still significant limitations, including the issue of keeping the organoids alive and healthy, and the peripheral equipment power consumption levels. But, bearing ethical considerations in mind, Brainoware has implications not just for computing, but understanding the mysteries of the human brain.”

Synthetic Bioweapons Are Coming. USNI.org article. Pull quote: “Of those dangers, next-generation bioweapons are the most serious. Unlike traditional bioweapons, which most states have abandoned as unreliable, synthetic bioweapons (SBWs) are weaponized biological threats modified through synthetic biology for novel effects, mechanisms, or processes.8 Unshackled from natural biology, SBWs possess characteristics engineered to target populations or individuals, through socially transmitted rather than kinetic means. Although each of the military services and the entire U.S. population could be at risk from SBWs, the nature of the Sea Services’ operations—far from home but necessarily dependent on local goods and services in forward-deployed locations—places them at particular risk.”

Jeffries: Government will shut down unless House GOP yields on demands. TheHill.com article. Pull quote: ““The problem is that while House Democrats agree with Senate Democrats on that number, and House and Senate Democrats agree with Senate Republicans on that number, and all of us agree with the Biden administration on that number, the extreme MAGA Republicans remain on an island, trying to break the agreement that they themselves negotiated,” he [Rep Jefferies (D,NY)] continued.”

Senate to return next week in hopes of pre-Christmas border deal. TheHill.com article. Pull quote: “The chamber is expected to need more time to finish work, including reauthorization of Federal Aviation Administration funding and a number of nominations, including potential votes on four-star military promotions that are being held up by Sen. Tommy Tuberville (R-Ala.).”

Tris(2-chloroethyl) Phosphate (TCEP); Draft Risk Evaluation Under the Toxic Substances Control Act (TSCA); Letter Peer Review; Notice of Availability, Public Meeting and Request for Comment. Federal Register EPA TSCA notice. Summary: “The Environmental Protection Agency (EPA) is announcing the availability of and soliciting public comment on the document titled: “2023 Draft Risk Evaluation for Tris(2-chloroethyl) Phosphate (TCEP)” and related draft charge questions. EPA will be submitting the Draft Risk Evaluation and public comments to peer reviewers who will consider the approach and methodologies utilized. The letter peer review will include review of the analysis of physical-chemical properties, the fate of TCEP in the environment, releases of TCEP to the environment, environmental hazard and risk characterization for terrestrial and aquatic species, and human health hazard and risk characterization for workers, consumers, and the general population. The letter peer review is expected to begin on March 13, 2024, and end on April 12, 2024. A preparatory virtual public meeting will be held on March 5, 2024, for reviewers and the public to comment on and ask questions regarding the scope and clarity of the draft charge questions.”

Export Controls on Semiconductor Manufacturing Items; Implementation of Additional Export Controls: Certain Advanced Computing Items; Supercomputer and Semiconductor End Use; Updates and Corrections; Extension of Comment Period. Federal Register BIS comment extension notice. Summary: “On October 25, 2023, the Bureau of Industry and Security (BIS) published in the Federal Register the interim final rules (IFR), “Export Controls on Semiconductor Manufacturing Items” (SME IFR) and “Implementation of Additional Export Controls: Certain Advanced Computing Items; Supercomputer and Semiconductor End Use; Updates and Corrections” (AC/S IFR). This notification extends the deadline for submission of written comments on both rules to January 17, 2024. BIS is making this extension to allow commenters to have additional time to review the interim final rules and to benefit from the significant amount of public outreach that BIS is conducting on the rules prior to preparing and submitting their comments on the IFRs.”

Review - HR 6524 Introduced – CISA Cybersecurity Apprenticeship Programs

Last month, Rep Houlahan (D,PA) introduced HR 6524 , the Federal Cybersecurity Workforce Expansion Act. The bill would require CISA to establish an apprenticeship program that would lead to cybersecurity related employment with CISA or other Federal entity. The bill would also require the Veterans Administration to establish a pilot program providing cyber-specific training for eligible individuals. There is no funding authorized in the legislation.

This bill is very similar to S 2256 [removed from paywall], introduced in the Senate on July 12th, 2023, and recently reported in the Senate. While there are many editorial differences between the two bills, the major difference is that the Senate bill is a standalone act, whereas this legislation would add a new section to the Homeland Security Act of 2002 (§2220F). Where the Senate bill would have to be codified as a note to an existing USC section, this bill would become a new section in 6 USC. This makes finding the resulting codified language much easier.

Moving Forward

Neither Houlahan, nor any of her four cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for primary consideration. This means that there would probably not be sufficient influence to see this bill considered in Committee. I see nothing in the bill that would engender any organized opposition. I suspect that there may be sufficient bipartisan support that the legislation could move to the floor under the suspension of the rules process.

Commentary

The lack of funding authorization in HR 6524 removes a possible source of opposition to the bill from the fiscal conservatives in the House. Unfortunately, it would also mean that any spending on these apprenticeship programs would have to come out of existing CISA budget authorizations. This effectively limits the size and number of apprenticeship programs that CISA could operate. It would also make it easy for CISA to decide to opt out of any new apprenticeship program.

 

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6524-introduced - subscription required. 

FMCSA Sends Automated Driving System NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOT’s Federal Motor Carrier Safety Administration (FMCSA) on “Motor Carrier Operation of Automated Driving System (ADS)-Equipped Commercial Motor Vehicles”. The FMCSA published an advanced notice of rulemaking (ANPRM) on this topic on May 18th, 2019.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“FMCSA proposes to amend certain Federal Motor Carrier Safety Regulations (FMCSRs) to ensure the safe introduction of automated driving systems (ADS)-equipped commercial motor vehicles (CMVs) onto the Nation's roadways. The proposed changes to the CMV operations, inspection, repair, and maintenance regulations prioritize safety and security, promote innovation, foster a consistent regulatory approach to ADS-equipped CMVs, and recognize the difference between human operators and ADS. FMCSA has taken several actions to solicit information on issues relating to the testing and integration of ADS-equipped CMVs, including holding listening sessions beginning in 2017 and a 2018 Request for Comments Concerning Federal Motor Carrier Safety Regulations (FMCSRs) Which May Be a Barrier to the Safe Testing and Deployment of Automated Driving Systems-Equipped Commercial Motor Vehicles on Public Roads” (83 FR 12933).  FMCSA continues to attend industry conferences, road show events and meet with various developers and other stakeholders.” 

Bills Introduced – 12-14-23

Yesterday, with both the House and Senate in session, there were 113 bills introduced. One of those bills may receive additional attention in this blog:

HR 6822 To amend title 44, United States Code, and for other purposes. Khanna, Ro [Rep.-D-CA-17]

The coverage of 44 USC is broad, and most of it is of little interest here, but there are two chapters that deal with IT issues that may be of tangential interest:

Chapter 35 - Coordination of Federal Information Policy, and

Chapter 36 - Management And Promotion of Electronic Government Services

I will be watching this bill for language and definitions that include federal cybersecurity coverage withing the scope of the changes being proposed. I suspect, however, that this may deal with Presidential records administration.


 
/* Use this with templates/template-twocol.html */