The following was posted, among other places, on the SCADASEC listserv. Eyal Udassin, a well-known and well respected security researcher with significant experience with control system functional security has discovered a vulnerability in some of Rockwell's products, and he and Rockwell have moved quickly to fix the vulnerability.
The December issue of IEEE Spectrum had a small lead about the following Open Source attempt to hack the GSM phone system. The full article can be found at http://spectrum.ieee.org/telecom/wireless/open-source-effort-to-hack-gsm/0.
John Eidar Simensen of Institute for Energy Technology offered a methodology using Baysian Belief Networks for estimating the complexity of critical instrumentation and control systems. This is an ongoing project which may provide the first real metrics for complexity after years of trying.
Don't know the exact implications of this. Thinking too hard about the games that go on in Washington hurts my head -- a lot. But having the "cybersecurity czar" resign even before she barely got started and having all the power brokers messing with her job doesn't sound good.
Our indefatigable blogger and functional security expert, Joe Weiss, was asked to provide written testimony for the record for the House Homeland Security Committee on Emerging Threats, Cybersecurity, Science and Technology hearings on the cyber security of the electric grid for today's hearing.