Thursday, September 24, 2026

Review – CSB Updates Accidental Release Reporting Data – 9-23-26

Yesterday, the CSB updated their published list of reported chemical release incidents. They added 63 new incidents that occurred since the previous version was published in June 2026. These are not incidents that the CSB is investigating; these are incidents that were reported to the CSB under their Accidental Release Reporting rules (40 CFR 1604) through September 1st, 2026. 

The table below shows the top five states based upon the number of reported incidents since the December update was published.  


For more information on the updated incident reporting data, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/csb-updates-accidental-release-reporting-90c - subscription required. 

 

Review – Bills Introduced – 9-23-26

Yesterday, with just the Senate in session, there were 60 bills introduced. Two of those bills may receive additional coverage in this blog: 

S 5461 A bill to require a study to evaluate the feasibility of establishing a Strategic Fertilizer Reserve for the storage and management of fertilizer products and fertilizer product inputs, and for other purposes. Schumer, Charles E. [Sen.-D-NY]    

S 5487 A bill to require the Administrator of the Transportation Security Administration to develop certain guidelines to improve access to the Transportation Worker Identification Credential program. Kennedy, John [Sen.-R-LA]   


For more information on these bills, including legislative history for similar bills in the 118th Congress, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-23-26 - subscription required. 

Wednesday, September 23, 2026

Review – Bills Introduced – 9-22-26

Yesterday, with just the Senate in session, there were 18 bills introduced. One of those bills may receive additional coverage in this blog: 

S 5450 A bill to adjust the rail safety inspections General Schedule classification, and for other purposes. Peters, Gary C. [Sen.-D-MI] 


For more information on this bill, including legislative history for similar bills in the 118th Congress, as well as a mention in passing of a spending reduction resolution, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-22-26 - subscription required. 

Tuesday, September 22, 2026

Review – Advisories Published – 9-22-26

Today CISA’s NCCIC-ICS published nine control system security advisories for products from OpenPLC, Siemens (6), and Lightweight IP (2).  

Advisories  

OpenPLC Advisory - This advisory describes a cross-site scripting vulnerability in the Autonomy Logic OpenPLC. The vulnerability was reported to CISA by Rajivarnan R. and Shirshak of Secnora. 

Siemens Advisory #1 - This advisory describes an improper validation of specified type of input vulnerability in the Siemens WTV676 and WTV776 products. The vulnerability was self-reported. 

Siemens Advisory #2 - This advisory describes a relative path traversal vulnerability in the Siemens SIMOVE Fleetmanager and SIPLANT products. The vulnerability was self-reported. 

Siemens Advisory #3 - This advisory discusses a weak password recovery mechanism for forgotten password vulnerability in the Siemens Industrial Edge Management product line. This is a third-party (Red Hat) vulnerability. 

Siemens Advisory #4 - This advisory describes a code injection vulnerability in the Siemens Desigo CC family. The vulnerability was reported by Michelin CERT. 

Siemens Advisory #5 - This advisory discusses the Copy Fail vulnerability in the Siemens SIPLUS and SIMATIC products. This is a third-party (Linux) vulnerability.  

Siemens Advisory #6 - This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Siemens Siveillance Control product. The vulnerability was self-reported. 

Lightweight IP (lwIP) Advisory #1 - This advisory describes a double free vulnerability in the Lightweight IP. The vulnerability was reported to CISA by Eric Evenchick of Tetrel Security. 

Lightweight IP (lwIP) Advisory #2 - This advisory describes an out-of-bounds write vulnerability in the lwIP TCP/IP Stack MQTT Client Application. The vulnerability was reported to CISA by Shahriyar Jalayeri of ByteRay Ltd. 


For more information on these advisories, as well as a DTRH look at the Copy Fail vulnerability in products from Siemens, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/advisories-published-9-22-26 - subscription required. 

Short Takes – 9-22-26 - Federal Register Edition

HSAR – PPE  

Homeland Security Acquisition Regulation, Make Personal Protective Equipment in America Act Restrictions on Foreign Acquisition (HSAR Case 2024-003). DHS final rule. Summary: “DHS is issuing a final rule to amend the Homeland Security Acquisition Regulation (HSAR) codifying how DHS complies with the requirements of the Make Personal Protective Equipment (PPE) in America Act. These changes are intended to ensure the sustainment and expansion of domestic manufacturing for certain types of PPE critical to the United States' national response to a public health crisis.” 

Pipeline Safety  

Pipeline Safety: Meeting of the Liquid Pipeline Advisory Committee. PHMSA advisory committee meeting notice. Summary: “This notice announces a public meeting of the Technical Hazardous Liquid Pipeline Safety Standards Committee, also known as the Liquid Pipeline Advisory Committee (LPAC). The meeting will be held virtually to discuss the following notices of proposed rulemaking (NPRMs): “Breakout Tank Inspection,” “Remote Monitoring of Hazardous Liquid Pipeline Rectifiers,” and “Hazardous Liquid Valve Maintenance Schedule.”” 

Executive Orders  

EO 14428 - Providing Meaningful Water Quality Improvements Through Collaboration and Oversight of Federal Support. 

EO 14429 - Reinvigorating America's Hunting Heritage. 

EO 14430 - Restoring American Saltwater Angling and Recreation. 

 
/* Use this with templates/template-twocol.html */