CISA, U.S. and International Partners Announce Updated Secure by Design Principles Joint Guide

  • Post author:
  • Post category:

October 16, 2023,WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), along with 17 U.S. and international partners, published an update to “Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software” that includes further detail on key principles, guidance, and is co-sealed by eight additional international cybersecurity agencies. CISA Director

Continue ReadingCISA, U.S. and International Partners Announce Updated Secure by Design Principles Joint Guide

Cisco Releases Security Advisory for IOS XE Software Web UI

  • Post author:
  • Post category:

Cisco released a security advisory to address a vulnerability (CVE-2023-20198) affecting IOS XE Software Web UI. A cyber threat actor can exploit this vulnerability to take control of an affected device. CISA encourages users and administrators to review the Cisco security advisory, apply the necessary recommendations, hunt for any malicious activity and report any positive

Continue ReadingCisco Releases Security Advisory for IOS XE Software Web UI

Federal judge orders healthcare companion company to pay 34 workers $95K in wages, damages, following US Labor Department investigation

  • Post author:
  • Post category:

Employers:    Great Lakes Care Companions Inc., Juan G. Salazar, ownerActions:          Fair Labor Standards Act consent order and judgmentCourts:           U.S. District Court for the Eastern District of Michigan Investigation findings: On Oct. 13, 2023, Judge Mark A. Goldsmith entered an agreed consent order and judgment requiring Great Lakes Care Companions Inc., and its owner, Juan G. Salazar to

Continue ReadingFederal judge orders healthcare companion company to pay 34 workers $95K in wages, damages, following US Labor Department investigation

CISA, FBI, and MS-ISAC Release Joint Advisory on Atlassian Confluence Vulnerability CVE-2023-22515

  • Post author:
  • Post category:

Today, CISA, the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released a joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-22515. This critical vulnerability affects certain versions of Atlassian Confluence Data Center and Server, enabling malicious threat actors to obtain initial access to Confluence instances

Continue ReadingCISA, FBI, and MS-ISAC Release Joint Advisory on Atlassian Confluence Vulnerability CVE-2023-22515

Pfizer Inc. agrees to pay $2M to resolve alleged compensation discrimination at New York City location

  • Post author:
  • Post category:

NEW YORK – The U.S. Department of Labor’s Office of Federal Contract Compliance Programs has entered into a conciliation agreement with Pfizer Inc. to resolve alleged compensation discrimination affecting female employees at the federal contractor’s New York City headquarters.A compliance review conducted by OFCCP covered the period from Jan. 1, 2015, to Dec. 31, 2016, and

Continue ReadingPfizer Inc. agrees to pay $2M to resolve alleged compensation discrimination at New York City location