Hello everyone! I’m proud and honored to introduce my very first academic white paper through SANS, which discusses the nuances and needs for planning for #ransomware in OT / industrial networks. https://www.sans.org/mlp/ics-ot-malware-and-ransomware/?utm_medium=Email&utm_source=HL-Global&utm_content=1468901_Simple_Framework_Whp_image&utm_campaign=ICS_OT_Malware_Ransomware_2025&utm_rdetail=Global&utm_goal=Leads&utm_type=Global_Campaign&is=be394332d8ab70db9bb29b280bd08c2899042252f80b48f1e01cd5b75d22b1c1
Finally put together a proper story on this funding debacle for MITRE's CVE program.
"A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintain the Common Vulnerabilities and Exposures (CVE) program -- which is traditionally funded each year by the Department of Homeland Security -- expires on April 16."
https://krebsonsecurity.com/2025/04/funding-expires-for-key-cyber-vulnerability-database/
PHMSA Sends LNG Safety ANPRM to OMB – https://tinyurl.com/242ujxbk #Regulation #PHMSA #LNG
CFSN Detailed Analysis - Substack Daily Update – 4-15-25 – Free Content – https://tinyurl.com/365cr2cy
Short Takes – 4-15-25 – Tomato tariffs – Pharma tariffs – Shower head definition – CyberAv3ngers – CVE contract lapse – Snake bite medicine – EO 14259 through EO 4270 – https://tinyurl.com/3brpdmw8
Review – 9 Advisories Published – 4-15-25 – NCCIC-ICS control system security advisories for products from Mitsubishi, ABB, Delta, National Instruments, Lantronix, Growatt, and Siemens (3) – Short version –https://tinyurl.com/2mdum727 #icsSecurity
9 Advisories Published – 4-15-25 – NCCIC-ICS control system security advisories for products from Mitsubishi, ABB, Delta, National Instruments, Lantronix, Growatt, and Siemens (3) – https://tinyurl.com/4sch5325 Subscription required #icsSecurity
Review – HR 1907 Introduced – Private cUAS – Would allow a property owner to use a shotgun to shoot down a drone flying no more than 200 feet over their property – Short version – https://tinyurl.com/3n7je449 #Legislation #cUAS
HR 1907 Introduced – Private cUAS – Would allow a property owner to use a shotgun to shoot down a drone flying no more than 200 feet over their property – Not applicable to industrial property protection - https://tinyurl.com/9s9xkhcs Subscription required #Legislation #cUAS
HR 1495 Introduced – Digital Economy Board – Would authorize current Digital Economy Board of Advisors – Cybersecurity coverage added – No new funding authorized – https://tinyurl.com/bdh9de8n Subscription required #Legislation #NTIA
CFSN Detailed Analysis - Substack Daily Update – 4-14-25 – Free Content – https://tinyurl.com/4znw9f72
Short Takes – 4-14-25 – Compressed air storage – Deferred resignation questions – Nuc an asteroid – Whooping cough increase – Short lived La Niña – https://tinyurl.com/5hfdc4zc
Review – Public ICS Disclosures – Week of 4-5-25 – Part 3 – 23 vendor updates – 5 researcher reports – 2 exploits – Short version – https://tinyurl.com/3v8pznau #icsSecurity
Public ICS Disclosures – Week of 4-5-25 – Part 3 – 23 vendor updates – 5 researcher reports – 2 exploits – https://tinyurl.com/4bvbpvkp Subscription required #icsSecurity
Review – OMB Approves OSHA Injuries and Illnesses ICR Revision – Revision increases burden estimate because of combining two ICR’s – Short version – https://tinyurl.com/rd4hwh5k #ICR #OSHA
OMB Approves OSHA Injuries and Illnesses ICR Revision – Revision increases burden estimate because of combining two ICR’s – https://tinyurl.com/4dwk7uxm Subscription required #ICR #OSHA
Review – Public ICS Disclosures – Week of 4-5-25 – Part 2 – For Part 2 we have 23 additional vendor disclosures – Part 3 still coming – Short version – https://tinyurl.com/4y5zv3mw #icsSecurity
Public ICS Disclosures – Week of 4-5-25 – Part 2 – For Part 2 we have 23 additional vendor disclosures – Part 3 still coming – https://tinyurl.com/3yxezjct Subscription required #icsSecurity
CFSN Detailed Analysis - Substack Daily Update – 4-12-25 – Free Content – https://tinyurl.com/yc8e4nuf
Short Takes – 4-12-25 – New risky OT/IoT devices – Girl Scout cookies safe – Measles outbreak – H2 fuel cell to ISS – Immigration enforcement and bird flu – NOAA layoffs and space weather forecasts – https://tinyurl.com/4v4d45yx