about

Further information about the Museum of Science and Industry in Manchester now available

Further information about the Museum of Science and Industry in Manchester, where the reception on day 2 of the workshop will take place, is now available. [2005-05-24]




about

Information About Technologies Now Available

Information about the technologies which will be available at the workshop is now available. This page describes the instant messaging environment and Wiki service which will be available during the event for use by workshop delegates who have brought a networked computer.




about

Details about sponsorship for the Institutional Web Management Workshop 2007 are now available

A sponsors page containing details of the sponsorship packages available has now been set up. Interested parties should contact the organisers. [2006-08-24]




about

Companies Are Warned About Compliance 'Minefields' for Pay Equity

Denise Visconti and Allan King urge employers to be vigilant regarding pay equity issues.

The National Law Journal

View Article 




about

What Should Employers Do About the California Consumer Privacy Act?

Philip Gordon suggests steps that employers should take in response to the privacy act.

SHRM Online

View Article 




about

RIFs and Rioja: Let’s W(h)ine About It




about

Profit sharing 2022: everything you need to know about the scenarios for outsourcing reform

Jorge Sales Boyoli talks about the outsourcing law came into force last year, who will receive profits and the new challenges that have come with it. 

El Heraldo de México

View




about

What Employers Need to Know About the PBGC’s Interim Final Rule About the Special Financial Assistance Program




about

Celebrating AAPI Heritage Month: Bringing About Change Through Servant Leadership

As May comes to a close, we end our celebration of Asian American Pacific Islander Heritage Month with the second of two podcasts that feature the personal stories of some of our ‘Ohana group attorneys. Littler attorney Brandon Mita has an inspiring conversation with fellow Littler attorneys Nicole LeFave, James Lee, and Urvi Morolia about leading through community service, non-profits and pro bono organizations that make a difference in their communities.
  




about

Sharing Space: A Conversation About Intersectionality

In celebration of Pride Month, Whitney Williams (L.A. – Century City) and Michael Hui (San Francisco) discuss their personal experiences growing up gay in the Black and Asian American communities, what their similar upbringings have taught them about being an attorney, and how the Littler Pride affinity group is an important part of their lives at the firm.
  




about

Allied Behavior: Perceptions about Race (Juneteenth Edition)

Kimberly Doud of Littler’s Orlando office, Chelsea Lewis of Littler's Miami office and Kameron Miller of Littler's Charleston office present episode two of the Allied Behavior podcast series. Allied Behavior is focused on cultivating conscious conversations about inclusion, equity, diversity, and allyship in a corporate environment. In this episode, Kimberly, Chelsea and Kameron discuss Juneteenth, the factors shaping our perceptions about race, and how to foster meaningful interactions in the workplace.
  




about

What To Know About EEOC Conciliation Regs' Coming Demise

Jim Paretti discusses the rescinding of a controversial EEOC rule that would have required the agency to share more information with employers credibly accused of discrimination during the conciliation process.

Law360 Employment Authority

View (Subscription required.)




about

Timely Talk About Wage and Hour Law: Sales-Based Incentives (aka Commissions)




about

Bills 47, 66 and 57: Everything You Need to Know About the Never Ending Changes to Ontario, Canada’s Employment Standards Act, 2000 and Labour Relations Act, 1995 and the Indefinite Delay of its Pay Transparency Act




about

Why Employers Shouldn't Forget About Executive Compensation




about

The Accidental Success of the NLRA: How a Law about Unions Achieved Its Goals by Giving Us Fewer Unions

Alexander Thomas MacDonald explains how, through a century of trial and error, labor law has been wildly successful in giving us the most peaceful labor market in history. 

The Federalist Society

View




about

OFCCP Revises Compensation Analysis Directive But Leaves Questions About Documentation Created Under Attorney-Client Privilege

On August 18, 2022, the Office of Federal Contract Compliance Programs (OFCCP) issued a revised version of its Directive 2022-01 - Advancing Pay Equity Through Compensation Analysis, which was originally issued on March 15, 2022.




about

We’re thinking about rolling out some IE&D initiatives – is that the same thing as an Affirmative Action Plan?

We’re thinking about rolling out some IE&D initiatives – is that the same thing as an Affirmative Action Plan?

The short answer is no, and there is often confusion between an Affirmative Action Plan, or AAP, and more general and voluntary IE&D initiatives.




about

Sponsoring a Group Health Plan for Employees? What Employers Need to Know About the Consolidated Appropriations Act

  • Employers sponsoring group health plans must understand and comply with new requirements imposed by the Consolidated Appropriations Act.
  • On the plus side, the new compliance requirements can provide sponsors with valuable insights into the operation of their group health plans.
  • To avoid potential liabilities, however, sponsors should act proactively to avoid allegations of imprudent fiduciary processes.   




about

Why Employers Should Care About Women’s Health And Its Impact On Workplace Policies

Mikayla Almeida, Kimberly Doud and Anne Sanchez LaWer explain to employers about how implementing benefits related to women’s health and fertility could reduce turnover and retain talent.

ACC Central Florida

View




about

4 Things Employers Should Know About the Vaccination Gap

Devjani Mishra discusses employers coming up with COVID-19 safety rules that are appropriate for their own workplace.

Law360 Employment Authority

View (Subscription required.)




about

What to do about "Global COVID Nomads" and Other Wandering Workers Who Telecommute from Abroad for Personal Reasons

Technology facilitates remote work in ways that, years ago, just were not possible. Take telecommuting. These days, all kinds of jobs that had to be performed at an employer site are now performed remotely. Some call center workers, for example, now work from home using home telephones no brick-and-mortar call center needed. Some secretaries now telecommute using laptops and the internet. Some teachers now teach remotely using laptops and video links.




about

New Opinion Allowing Plaintiff to Present His Class Action Willful FCRA Claims to a Jury Reinforces Need to Remain Vigilant About FCRA Compliance

The Fair Credit Reporting Act (FCRA) is a federal law that governs employment-related background checks.  Most lawsuits asserting federal claims proceed in federal court.1  The FCRA is atypical in that FCRA claims can proceed in either federal or state court.  A new opinion from a California court of appeal in Hebert v.




about

Reports About the Wholesale Demise of Claims Against Employers Under the Fair Credit Reporting Act (FCRA) are Premature

  • Lawsuits against employers under the FCRA show no signs of abating in 2023, including nationwide class actions.
  • Employers can fortify efforts to comply with the FCRA by, among other things, reviewing their policies and procedures and providing FCRA compliance training.




about

Second Chance Employment: Addressing Concerns About Negligent Hiring Liability

Rod Fliegel co-authors a report that explains negligent hiring, employers’ risks and how they can protect their company. 

Legal Action Center

View




about

The CFPB Cautions Employers About Using Technology to Track, Assess, and Evaluate Workers

  • Employers should be mindful of whether workforce tracking technology, including AI, may provide information, such as employee performance scores, that triggers FCRA compliance.
  • The FCRA protects both job applicants and employees.
  • Education about basics of the FCRA is key for all employers, including in-house counsel, due to the proliferation of such tracking and scoring technology.




about

Dear Littler: What is so Taxing about our Wandering Workers?

Dear Littler: You alerted us to some wage & hour and leaves & benefits issues stemming from our “wandering workers” who have scattered across the country during the pandemic, yet continue to work for our Texas-based company.




about

This is what you should know about the proof of tax situation of the SAT

In Mexico, the fiscal authority has dramatically strengthened all the strategies that allow for better control and collection of employment taxes, and Jorge Sales Boyoli explains what that means for employers.

Forbes Mexico

View




about

N.J. Legislature Tells Employers to Be Transparent About Pay, Promotions

Lauren J. Marcus, Amber M. Spataro and Francis A. Kenny discuss New Jersey’s new bill that would require employers to disclose wage or salary ranges and general benefits information in each job posting/advertisement.

SHRM

View (Subscription required)




about

This Legal Change Could "Severely Disrupt" Franchising. Learn About the PRO Act's Joint-Employer Standard

Michael Lotito offers insight on the Protecting the Right to Organize Act (or PRO Act), which includes a change to a standard known as “joint employer.”

Entrepreneur

View 




about

What Unionized and Non-Unionized Employers Need to Know About OSHA's Worker Walkaround Rule




about

House Subcommittee Hearing Raises Concerns About Proposed Heat Illness Rule

Felicia Watson discusses three concerns about a proposed OSHA rule that would protect indoor and outdoor workers from heat illness.

SHRM

View (Subscription required)




about

What Employers Need to Know About the UK Worker Protection Act




about

What HR should know about Colorado’s new AI law

Philip L. Gordon says a new AI law in Colorado means that any employer doing business in the state with more than 50 employees will have specific obligations when AI is a factor in the decision-making processes that affect personnel.

HR Brew

View




about

5 Questions About NY's Workplace Violence Prevention Law

Rebecca Goldstein and Terri Solomon comment on New York's Retail Worker Safety Act, which requires retail employers to adopt a violence prevention policy.

Law360 Employment Authority

View (Subscription required)




about

Why You Haven’t Heard More About The Minimum Wage This Election Season

Shannon Meade says wage legislation on the hill has consistently failed and stalled in Congress, so states have been stepping up to fill the void.

Forbes

View (Subscription required)




about

CVE-2024-47575: Frequently Asked Questions About FortiJump Zero-Day in FortiManager and FortiManager Cloud

Frequently asked questions about a zero-day vulnerability in Fortinet’s FortiManager that has reportedly been exploited in the wild.

Background

The Tenable Security Response Team (SRT) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding a zero-day vulnerability in Fortinet’s FortiManager.

Update October 23: The blog has been updated with new information about in-the-wild exploitation and threat actor activity associated with this vulnerability.

View Change Log

FAQ

What is FortiJump?

FortiJump is a name given to a zero-day vulnerability in the FortiGate-FortiManager (FGFM) protocol in Fortinet’s FortiManager and FortiManager Cloud. It was named by security researcher Kevin Beaumont in a blog post on October 22. Beaumont also created a logo for FortiJump.

What are the vulnerabilities associated with FortiJump?

On October 23, Fortinet published an advisory (FG-IR-24-423) for FortiJump, assigning a CVE identifier for the flaw.

CVEDescriptionCVSSv3
CVE-2024-47575FortiManager Missing authentication in fgfmsd Vulnerability9.8

What is CVE-2024-47575?

CVE-2024-47575 is a missing authentication vulnerability in the FortiGate to FortiManager (FGFM) daemon (fgfmsd) in FortiManager and FortiManager Cloud.

How severe is CVE-2024-47575?

Exploitation of FortiJump could allow an unauthenticated, remote attacker using a valid FortiGate certificate to register unauthorized devices in FortiManager. Successful exploitation would grant the attacker the ability to view and modify files, such as configuration files, to obtain sensitive information, as well as the ability to manage other devices.

Obtaining a certificate from a FortiGate device is relatively easy:

Comment
by from discussion
infortinet

 

According to results from Shodan, there are nearly 60,000 FortiManager devices that are internet-facing, including over 13,000 in the United States, over 5,800 in China, nearly 3,000 in Brazil and 2,300 in India:

When was FortiJump first disclosed?

There were reports on Reddit that Fortinet proactively notified customers using FortiManager about the flaw ahead of the release of patches, though some customers say they never received any notifications. Beaumont posted a warning to Mastodon on October 13:

 

Was this exploited as a zero-day?

Yes, according to both Beaumont and Fortinet, FortiJump has been exploited in the wild as a zero-day. Additionally, Google Mandiant published a blog post on October 23 highlighting its collaborative investigation with Fortinet into the “mass exploitation” of this zero-day vulnerability. According to Google Mandiant, they’ve discovered over 50 plus “potentially compromised FortiManager devices in various industries.”

Which threat actors are exploiting FortiJump?

Google Mandiant attributed exploitation activity to a new threat cluster called UNC5820, adding that the cluster has been observed exploiting the flaw since “as early as June 27, 2024.”

Is there a proof-of-concept (PoC) available for this vulnerability/these vulnerabilities?

As of October 23, there are no public proof-of-concept exploits available for FortiJump.

Are patches or mitigations available for FortiJump?

The following table contains a list of affected products, versions and fixed versions.

Affected ProductAffected VersionsFixed Version
FortiManager 6.26.2.0 through 6.2.12Upgrade to 6.2.13 or above
FortiManager 6.46.4.0 through 6.4.14Upgrade to 6.4.15 or above
FortiManager 7.07.0.0 through 7.0.12Upgrade to 7.0.13 or above
FortiManager 7.27.2.0 through 7.2.7Upgrade to 7.2.8 or above
FortiManager 7.47.4.0 through 7.4.4Upgrade to 7.4.5 or above
FortiManager 7.67.6.0Upgrade to 7.6.1 or above
FortiManager Cloud 6.46.4 all versionsMigrate to a fixed release
FortiManager Cloud 7.07.0.1 through 7.0.12Upgrade to 7.0.13 or above
FortiManager Cloud 7.27.2.1 through 7.2.7Upgrade to 7.2.8 or above
FortiManager Cloud 7.47.4.1 through 7.4.4Upgrade to 7.4.5 or above
FortiManager Cloud 7.6Not affectedNot Applicable

Fortinet’s advisory provides workarounds for specific impacted versions if patching is not feasible. These include blocking unknown devices from attempting to register to FortiManager, creating IP allow lists of approved FortiGate devices that can connect to FortiManager and the creation of custom certificates. Generally speaking, it is advised to ensure FGFM is not internet-facing.

Has Tenable released any product coverage for these vulnerabilities?

A list of Tenable plugins for this vulnerability can be found on the individual CVE page for CVE-2024-47575 as they’re released. This link will display all available plugins for this vulnerability, including upcoming plugins in our Plugins Pipeline.

Get more information

Change Log

Update October 23: The blog has been updated with new information about in-the-wild exploitation and threat actor activity associated with this vulnerability.

Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.




about

Canadian securities regulators issue warning about fraudulent investment solicitations involving crypto assets

Montréal –The Canadian Securities Administrators (CSA) warns the public about investment schemes involving fraudulent websites that solicit investments in foreign exchange (often referred to as “forex”), binary options and/or crypto assets.




about

CSA Investor Alert: Canadian securities regulators warn the public about impersonation scams

Montreal - The Canadian Securities Administrators (CSA) is warning the public to be vigilant for unsolicited communications that come from scammers posing as CSA staff or staff of CSA members.




about

Canadian securities regulators warn public about unregistered trading platform Nova Tech Ltd

Toronto – The Canadian Securities Administrators (CSA) is warning the public that Nova Tech Ltd (NovaTech), which operates the website www.novatechfx.com, is not registered with a securities regulator in any province or territory in Canada.




about

Dear Libby : will you answer my questions about friendship?.

How do we find lasting, trusting, and fulfilling friendships? Is it by being popular? Dazzling others with your genius? Looking for that ultimate BFF? Hiding all your imperfections and trying hard to fit in? Deep and enduring friendships are essential to our psychological and physical well-being. Unfortunately, between bullying, social anxiety, peer pressure, and other issues, many teens feel isolated. In Dear Libby, trusted columnist Libby Kiszner offers a breakthrough approach to friendship and connection. You can create friendships from the inside out-rather than from the outside in. You can experience friendships with vibrant self-expression in every stage of life, making Dear Libby a book that can be read and reread at any age. Containing seven core principles, this life-changing resource not only explains the dynamics of connections and friendships but also gives practical tools to develop them. Integrating contemporary issues, timeless insight, real-life skills, and unique perspectives, Dear Libby provides a hands-on guide for dealing with everyday friendship struggles faced by teens today. Teens and readers of all ages will gain insight and understanding on how to make profound, joyful relationships possible. Find answers to real questions like: What should I do when people who are supposed to be my friends call me names or embarrass me? What should I do I do if I'm being ignored at school? What is the best way to handle loneliness? Someone just stole my friend. What can I do? What can I do when my friends get together and "forget" to invite me?




about

Dear Lilly : from father to daughter : the truth about life, love, and the world we live in.

A father offers his advice, opinions, and the many useful stories gleaned from his past experiences in order to help his beloved daughter not only survive, but thrive in the dangerous and unpredictable world of young adulthood. From the pen of a former abused child, drug addict, womanizing frat boy, and suicidal depressive, comes forth the emotionally stirring account of a young man's battle with crippling inner demons and his eventual road to enlightenment. Peter Greyson calls upon his wisdom as both father and school teacher to gently lead teenage girls through a maze of truth, deception, and adolescent uncertainty. Greyson's literary style sparkles with a youthful enthusiasm that will capture your heart and provide boundless inspiration. Dear Lilly is a survival guide that offers the brutally honest male perspective to young women struggling for answers to life's deepest questions. Topics include: Boys lie What every guy wants from his girlfriend Tales from the drug world Everybody hurts High school exposed




about

We Write To You About Africa (November 13, 2024 11:00am)

Event Begins: Wednesday, November 13, 2024 11:00am
Location: Museum of Art
Organized By: University of Michigan Museum of Art (UMMA)


Following years of research into the Museum’s and University of Michigan’s relationships with Africa and African art collections, We Write To You About Africa is a complete reinstallation and doubling of the Museum’s space dedicated to African art. 

Featuring a wide range of artworks—from historic Yoruba and Kongo figures to contemporary works by African and African American artists, such as Sam Nhlengenthwa, Masimba Hwati, Jon Onye Lockard and Shani Peters—the exhibition directly addresses the complex and difficult histories inherent to African art collections in the Global North, including their entanglements with colonization and global efforts to repatriate African artworks to the continent.

Art collections, by their very nature, can not be anything other than subjective. With I Write To You About Africa, we examine the subjective ways UMMA and the University of Michigan as a whole have collected and presented art from and connected to the African diaspora.

Drawn from art collections across the U-M campus, a special section of the exhibition highlights how the founding of the Department of Afroamerican and African Studies (DAAS) and the African Studies Center (ASC) impacted U–M’s collecting practices. This section includes an exciting and ongoing project—contemporary African artists, scholars, and curators will be asked to write about their work on postcards, in their first language, and mail them to UMMA where they will be displayed alongside their works. 

We Write To You About Africa will be a reinstallation of the Museum’s Robert and Lillian Montalto Bohlen Gallery of African art and the connected Alfred A Taubman Gallery II. It is slated to open in 2021 and will be on view indefinitely.

Lead support for this exhibition is provided by the University of Michigan Office of the Provost, the Michigan Arts and Culture Council, and the African Studies Center.
 





about

Maria Bamford gets personal (about) finance

Note: There is swearing in this episode.

In 2017, The University of Minnesota asked comedian Maria Bamford to give their commencement speech. But the University may not have known what it was in for. In her speech, Bamford told the crowd of graduates how much the university offered to pay her (nothing), her counteroffer ($20,000), and the amount they settled on ($10,000), which (after taxes and fees, etc.) she gave away to students in the audience to pay down their student loans.

Maria Bamford is a big believer in full disclosure of her finances, a philosophy she's adopted after decades in a Debtors Anonymous support group. In meetings, she learned important financial tips and tricks to go from thousands of dollars in debt to her current net worth of $3.5 million (a number which, true to her philosophy, she will share with anyone).

She spoke with us about her financial issues, how she recovered, and why she believes in total financial transparency, even when it makes her look kinda bad.

Disclaimer: Planet Money is not qualified or certified to give financial advice. And Maria is not a spokesperson for Debtors Anonymous in any way.

This show was hosted by Kenny Malone and Mary Childs. It was produced by Emma Peaslee, edited by Jess Jiang, fact-checked by Sierra Juarez, and engineered by Neisha Heinis. Alex Goldmark is Planet Money's executive producer.

Help support Planet Money and get bonus episodes by subscribing to Planet Money+ in
Apple Podcasts or at plus.npr.org/planetmoney.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




about

Why are we so bummed about the economy?

Would you say that you and your family are better off or worse off, financially, than you were a year ago? Do you think in 12 months we'll have good times, financially, or bad? Generally speaking, do you think now is a good time or a bad time to buy a house?

These are the kinds of questions baked into the Consumer Sentiment Index. And while the economy has been humming along surprisingly well lately, sentiment has stayed surprisingly low.

Today on the show: We are really bummed about the economy, despite the fact that unemployment and inflation are down. So, what gives? We talk to a former Fed economist trying to get to the heart of this paradox, and travel to Michigan to check in on the place where they check the vibes of the economy.

Help support Planet Money and get bonus episodes by subscribing to Planet Money+ in Apple Podcasts or at plus.npr.org/planetmoney.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




about

Why is everyone talking about Musk's money?

We've lived amongst Elon Musk headlines for so long now that it's easy to forget just how much he sounds like a sci-fi character. He runs a space company and wants to colonize mars. He also runs a company that just implanted a computer chip into a human brain. And he believes there's a pretty high probability everything is a simulation and we are living inside of it.

But the latest Elon Musk headline-grabbing drama is less something out of sci-fi, and more something pulled from HBO's "Succession."

Elon Musk helped take Tesla from the brink of bankruptcy to one of the biggest companies in the world. And his compensation for that was an unprecedentedly large pay package that turned him into the richest person on Earth. But a judge made a decision about that pay package that set off a chain of events resulting in quite possibly the most expensive, highest stakes vote in publicly traded company history.

The ensuing battle over Musk's compensation is not just another wild Elon tale. It's a lesson in how to motivate the people running the biggest companies that – like it or not – are shaping our world. It's a classic economics problem with a very 2024 twist.

Help support Planet Money and hear our bonus episodes by subscribing to Planet Money+ in Apple Podcasts or at plus.npr.org/planetmoney.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




about

Learn about creating a startup from the accelerator that launched Airbnb, Reddit and Dropbox

Toronto, ON – Since 2005, Y Combinator (YC) has launched 1,200 startups which have a combined valuation of over $65 billion. Without the help of this seed accelerator, companies such as DoorDash, Code Academy and Thalmic Labs would have been lost. On Friday, January 20, 2017, YC will be inaugurating Accelerator Weekend with a panel led […]




about

The Moth Radio Hour: Facing the Music - Stories About Coming to Terms

In this hour, storytellers have to face the music. This episode is hosted by Suzanne Rust. The Moth Radio Hour is produced by The Moth and Jay Allison of Atlantic Public Media.

Hosted by: Suzanne Rust

Storytellers:

EJR David

Mary Furlong Coomer

Karen Kibaara

Colin Channer




about

The Moth Radio Hour: Signed, Sealed, Delivered - Stories about Letters

Special delivery!—a Moth Radio Hour all about letters. At work, for romance, and to the Tooth Fairy. This episode is hosted by Moth Executive Producer, Sarah Austin Jenness. The Moth Radio Hour is produced by The Moth and Jay Allison of Atlantic Public Media.

Storytellers:

Meg Ferrill's letter is read aloud in her human sexuality class.

Danielle Dardashti is surprised by the severance letter she receives.

Matty Struski pens a letter in an attempt to win back his ex.

Lu Levin strikes up a correspondence with the Tooth Fairy.

Otis Gray gets a job writing rejection letters.

Stacey Perlman visits a medium, who knows of a letter to the great beyond.