Show newer

If you have a 23andMe profile, it is possible that you have been affected by their latest data breach. Just to be safe, you should take a minute now to change your DNA.

Conference Report for HR 2670 Published – 2024 NDAA – Lots of cybersecurity provisions include – Some from earlier versions excluded – Vote in House next week - tinyurl.com/ye2fvdhh Subscription required

Review - CSB Publishes Didion Milling Investigation Report – Yet another combustible dust incident – 5 dead and 14 injured - $15 million in damages – Short version – tinyurl.com/mrysbt78

CSB Publishes Didion Milling Investigation Report – Yet another combustible dust incident – 5 dead and 14 injured - $15 million in damages - tinyurl.com/yk8m5mrf

CFSN Detailed Analysis - Substack Daily Update – 12-6-23 – Free Content – tinyurl.com/3k69efew

Review – HR 6496 Introduced – Valve Standards Expansion – Would require PHMSA to reinstate RMV requirements for new Type A gas gathering lines – Short version – tinyurl.com/y7wvm47j

Yo, I don’t know who needs to hear this but @dangoodin had some outstanding coverage on what’s been going on with attacks on water utilities in the US, and a lot of the other big outlet coverage has been pretty wonky and drawing false conclusions. I’ve been too heads down with everything to comment much.

But like, this is stuff we in ICS cybersecurity have been warning about for a long time. Not because of uber 1337 APTs, but because municipalities are super duper underfunded and under appreciated, and because commonalities in tooling and devices and lowering the bar to entry in ICS attacks all the time. It’s like when metasploit, or cracked cobalt strike, or the big Windows RCE 0days hit. Those change things, because they make attacks easier for less techy people, and they make a lot of juicy targets more visible.

Like I say, water has been keeping us awake for a long time. This is awful but no surprise. We have all been trying to fix it.

HR 6496 Introduced – Valve Standards Expansion – Would require PHMSA to reinstate RMV requirements for new Type A gas gathering lines - tinyurl.com/ekcyzy7b Subscription required

HR 4510 Reported in House – NTIA Reauthorization – Committee approved substitute language with only minor changes – 48 to 0 committee vote - tinyurl.com/nmpvau37

CFSN Detailed Analysis - Substack Daily Update – 12-5-23 – Free Content – tinyurl.com/54nuruby

Short Takes – 12-5-23 – Virtual juries – Spending deal – Cyber rotation program – CISA Gateway ICR – IoT Board meeting - tinyurl.com/2p82du2d

1 Advisory and 1 Update Published – 1-25-23 – NCCIC-ICS control system security advisory for products from Zebra – Update for products from Mitsubishi – DTRH look at printer cybersecurity - tinyurl.com/37va9rwd Subscription required

Reader Comment – CSB Backlog Update – Reader caught mistake in number of incident reports still outstanding – A brief look forward to post-back-log clearance at CSB - tinyurl.com/yckdabcr

CISA Removes a Vulnerability from the KEV Catalog – Apparently it was not a vulnerability after all –tinyurl.com/y64mcrpb

CFSN Detailed Analysis - Substack Daily Update – 12-4-23 – Free Content – tinyurl.com/y6a47x7u

Short Takes – 12-4-23 – Water hack investigation – Philosophical cybersecurity shift – SLT cybersecurity assessment ICR – tinyurl.com/5y3jxxkz

PIPES Act 2023 Markup – 12-6-23 – Late addition to hearing list – Periodic pipeline safety update (HR 6494) – Includes substitute language offering - tinyurl.com/yc3x7ztj

Review - CSB Publishes Yenkin-Majestic Incident Report – Report for explosion and fire that resulted in 1 death and $90 million in damages – 3 safety issues identified – 7 safety recommendations published – Short version - tinyurl.com/58vrnxen

CSB Publishes Yenkin-Majestic Incident Report – Report for explosion and fire that resulted in 1 death and $90 million in damages – 3 safety issues identified – 7 safety recommendations published - tinyurl.com/4ezb3hpe

Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.