j

Littler Lightbulb – June Employment Appellate Roundup

This Littler Lightbulb highlights some of the more significant employment law developments at the U.S. Supreme Court and federal courts of appeal in the last month.

At the Supreme Court




j

Supreme Court of Canada Confirms “Owners” of Construction Projects Are “Employers” Under OHSA

  • Supreme Court of Canada lets stand decision finding an “owner” of a construction project can be considered an “employer” within the meaning of the Occupational Health and Safety Act (OHSA).
  • This decision has significant implications for the construction sector, as a project owner can now be liable for OHSA violations of its contractor, subject to a due diligence defence.  




j

Effective January 1, 2024, Employers in British Columbia, Canada Have Duties to Cooperate and to Maintain Employment Regarding Certain Workplace Injuries

On November 24, 2022, Bill 41 – 2022: Workers Compensation Amendment Act (No. 2), 2022 (Bill 41), which introduced changes to British Columbia’s Workers Compensation Act, received Royal Assent. Effective January 1, 2024, Bill 41 imposes certain duties on employers and employees following a workplace injury.




j

Connecticut Employers Can Terminate Employees Impaired by Medical Marijuana While Working; Appellate Court Also Provides Guidance for Reasonable Suspicion Drug Tests

In a significant decision about workplace drug use, the Connecticut Appellate Court backed an employer’s right to terminate a worker who was impaired on the job by medical marijuana. The decision also clarified the factual basis an employer must possess to justify ordering a drug test based on suspicion of impairment.




j

Employer Zero-Tolerance Marijuana Policy Justified Termination, Federal District Court Agrees

  • A recent federal court decision agreed an Illinois employer had the right to enforce a zero-tolerance policy on marijuana use.
  • Off-the-job marijuana use can trigger employee discipline so long as it is not unreasonable or discriminatory.




j

Employer Zero-Tolerance Marijuana Policy Justified Termination, Federal District Court Agrees

Grant Goerke and Jennifer Chierek Znosko discuss a recent federal court decision that agreed an Illinois employer had the right to enforce a zero-tolerance policy on marijuana use.

Westlaw Today

View (Subscription required)




j

Are You Ready for the June 18th PWFA Rule?




j

Using the New Jersey Wage Hub for Certified Payroll Reporting




j

Using the New Jersey Wage Hub for Certified Payroll Reporting




j

Using the New Jersey Wage Hub for Certified Payroll Reporting




j

Using the New Jersey Wage Hub for Certified Payroll Reporting




j

The New Jersey Wage Hub Unpacked: A 60-day Review of the New Jersey Wage Hub and What Comes Next




j

Japan: Some Progress Trimming Work Hours Since Overtime Law Took Effect

Aki Tanaka talks about how the monthly average working hour per employee went down in Japan after the country started implementing a law limiting overtime in 2018.

SHRM Online

View (Subscription required.)




j

Felicia Watson Joins Littler as Senior Counsel in Washington, D.C.

WASHINGTON, D.C. (March 29, 2024) – Littler, the world’s largest employment and labor law practice representing management, has added Felicia Watson as senior counsel in its Washington, D.C., office. Watson joins from the National Association of Home Builders, where she served as assistant vice president of construction liability and research.




j

Littler Welcomes Shareholder John Nordlund in San Diego

SAN DIEGO (April 1, 2024) – Littler, the world’s largest employment and labor law practice representing management, has added John Nordlund as its newest shareholder in its San Diego office. Nordlund joins the firm from Jackson Lewis P.C.




j

Special Counsel Elizabeth Sitgreaves Joins Littler in Growing Nashville Office

NASHVILLE, Tenn. (April 8, 2024) – Littler, the world’s largest employment and labor law practice representing management, has added Elizabeth Sitgreaves as special counsel in its Nashville office. Sitgreaves joins from The Law Offices of John Day, P.C. and brings over 15 years of litigation experience.




j

Littler Adds Shareholder John Tripoli in Milwaukee

MILWAUKEE (April 8, 2024) – Littler, the world’s largest employment and labor law practice representing management, has added John D. (J.D.) Tripoli as a shareholder in its Milwaukee office. Tripoli joins from Eimer Stahl LLP and focuses his practice on employment-related litigation.




j

Briana Swift Joins as a Shareholder in Littler’s Seattle Office

SEATTLE (May 28, 2024) – Littler, the world’s largest employment and labor law practice representing management, has added Briana M. Swift as a shareholder in its Seattle office. She joins the firm from K&L Gates and focuses her practice on employee benefits and executive compensation. Swift is the sixth attorney to join Littler at the shareholder level since the beginning of April.




j

Three in a Row! Littler Adds Third Partner in Just Two Months to Growing Toronto Office

TORONTO (June 17, 2024) – Littler, the world’s largest employment and labour law practice representing management, continues its hiring streak in Toronto today with the addition of Matthew Badrov as a partner. Badrov, who joins from Sherrard Kuzz, marks Littler’s third partner addition in Toronto in recent months, following the arrivals of Shana French and Stephen Shore.




j

New amendments to California bill clarify scope of prohibition on junk fees for restaurant industry

Stacey James and Jamie L. Santos discuss a California amendment that seeks to allow restaurants to support higher wages and benefits while clearly disclosing service fees to consumers upfront.

Wolters Kluwer

View (Subscription required)




j

Time for Employers to Complete California Privacy Rights Act Compliance as Court of Appeal Lifts Injunction on Enforcement

  • The California Court of Appeal’s decision on February 9, 2024 immediately restores the California Privacy Protection Agency’s enforcement power.
  • The decision impacts finalized regulations – which are no longer subject to enforcement delay. 
  • Upcoming and pending regulations are unlikely to face enforcement delay once finalized.




j

July is Still the New January! Littler’s Workplace Policy Institute’s Mid-Year Legislative Report

Hot off the press – here is Littler’s mid-year report!  As federal regulators, states and cities continue to pass new workplace regulations through the calendar year, we summarize each state’s notable labor and employment law updates. Some states, like Maryland, have at least a dozen new laws and regulations taking effect this summer, tackling everything from vaping at work to pay discrimination.  Other states have just one, such as the state of West Virginia, which now restrains employers from acting against employees who store firearms in their vehicles on company property.




j

Mailbag: We rejected a job candidate. When can we delete their information?

David Goldstein discusses how long employers should keep rejected job candidates’ records and says their ATS system for storing those records should be configured to comply with applicable laws.

HR Dive

View




j

Just 11% of Legal Departments Predict Gen AI Will Be 'Transformative,' As Its Honeymoon Phase Fades

Marko Mrkonich says it’s important for companies to establish their AI compliance framework at the beginning, instead of after employees have already gotten used to deploying AI in certain ways.

Corporate Counsel

View (Subscription required)




j

3 Wage Cases To Watch As Justices Return To Bench

Alex MacDonald says a California assembly bill unlawfully targets certain companies or groups of companies.

Law360 Employment Authority

View (Subscription required)




j

Day 1 Unfair Dismissal Right Risks Diversity And Justice Aims

Ben Smith discusses a UK proposal to abolish the two-year qualifying period for employees to bring an unfair dismissal claim against their employer.

Law 360

View (Subscription required)




j

Texas ABM Ruling Threatens Future of Labor Agency Law Judges

Alex MacDonald says the US Labor Department’s ability to use in-house judges to resolve claims may have to be addressed by the US Supreme Court because circuit splits threaten to limit the judges’ power. 

Bloomberg Law

View (Subscription required)




j

3 GOP States Join Paid Sick Leave Movement, Passing Ballot Measures by Wide Margin

Shannon Meade says Democrats and Republicans both want to make progress on paid leave, but no one is sure whether a national paid leave program will be among their priorities.

Corporate Counsel

View (Subscription required)




j

ETSI Intelligent Transport Systems workshop outlines global projects

ETSI Intelligent Transport Systems workshop outlines global projects

Sophia Antipolis, 8 March 2019

The annual ETSI Intelligent Transport Systems (ITS) workshop ended after 2 days of intensive discussions and networking opportunities between industry, the European Commission and stakeholders involved in Cooperative ITS deployment (C-ITS) worldwide.

Read More...




j

ETSI re-elects Director-General Luis Jorge Romero

ETSI re-elects Director-General Luis Jorge Romero

Sophia Antipolis, 2 April 2019

During their 73rd General Assembly, 2-3 April 2019, ETSI members re-elected the current ETSI Director-General Mr. Luis Jorge Romero with an overwhelming majority on the first ballot.

Read More...




j

AIOTI, ISO/IEC JTC1, ETSI, oneM2M and W3C Collaborate on Two Joint White Papers on Semantic Interoperability Targeting Developers and Standardization Engineers

AIOTI, ISO/IEC JTC1, ETSI, oneM2M and W3C Collaborate on Two Joint White Papers on Semantic Interoperability Targeting Developers and Standardization Engineers

Cross-organization expert group works together on accelerating adoption of semantic technologies in IoT.

AIOTI today announced its collaborative role in the publication of two joint white papers on semantic interoperability entitled Semantic IoT Solutions - A Developer Perspective and Towards semantic interoperability standards based on ontologies in conjunction with organizations closely tied to the advancement of the IoT ecosystem.

Read More...




j

ETSI issues two major standards for emergency calls: Next Generation 112 and Advanced Mobile Location

ETSI issues two major standards for emergency calls: Next Generation 112 and Advanced Mobile Location

Sophia Antipolis, 20 January 2020

ETSI’s Emergency Communication Special Committee has recently released two major specifications, ETSI TS 103 479, for NG112, the next generation of European emergency services and ETSI TS 103 625, for the specific Advanced Mobile Location function. AML is already implemented in 22 countries worldwide following the publication of the first ETSI technical report TR 103 393.

Read More...




j

Fighting pandemic: special edition of Enjoy! now available

Fighting pandemic: special edition of Enjoy! now available

Sophia Antipolis, 7 July 2020

ETSI is pleased to unveil a special edition of its magazine Enjoy! As a global pandemic hit the world at all levels, people and companies had to cope with this crisis each in their own way. Through a variety of interviews and articles, this new issue reflects the challenges and perspectives of our international members.

Read More...




j

Testing to the edge: join us at our virtual UCAAT 2021

Testing to the edge: join us at our virtual UCAAT 2021

Sophia Antipolis, 16 August 2021

The automation of test processes is proven to increase productivity and product quality. The global pandemic has increased the demands on various IT systems and services in terms of interoperability, scalability and adaptability, making test automation even more critical for the delivery of agile solutions in uncertain times.

To tackle these challenges, ETSI is organizing the 8th User Conference on Advanced Automated Testing (UCAAT) as a virtual conference on 19-21 October.

Read More...




j

ENISA and ETSI joint workshop tackles challenges for European identity proofing

ENISA and ETSI joint workshop tackles challenges for European identity proofing

Sophia Antipolis, 3 May 2022

Today ENISA (the European Union Agency for Cybersecurity) and ETSI organized a workshop as part of their joint effort and collaboration to support EU requirements for identity proofing. The event was mainly addressed at EU companies and other public or academic organizations that run or prepare to launch their remote ID solution.

Read More...




j

ETSI Research Conference: Research and Standards on a successful journey

Sophia Antipolis, 10 February 2023

With more than 170 face-to-face attendees, coming from 30 countries, the three day ETSI conference on Maximizing the Impact of European 6G Research through Standardization came to a close on 8 February. The event provided a unique opportunity for the research community to come together with industry representatives and standardization experts to discuss future technology research and building stronger links to standardization.

Read More...




j

Your Smart Digital Identity with ETSI: Join our webinar on 20 April

Sophia Antipolis, 14 April 2023

Today we expect to be able to communicate anywhere, with everyone, at anytime, on every device and at the same time use various services that will help us save time in our daily life.

Read More...





j

ETSI and TCCA Statement to TETRA Security Algorithms Research Findings Publication on 24 July 2023

Sophia Antipolis, 24 July 2023

The European Telecommunications Standards Institute (ETSI) and The Critical Communications Association (TCCA) are the proud authorities and custodians of the ETSI TETRA (Terrestrial Trunked Radio) technology standard, one of the world’s most secure and reliable radio communications standards.

Read More...




j

ETSI elects Director-General Jan Ellsberger

ETSI elects Director-General Jan Ellsberger

Sophia Antipolis, 17 April 2024

During their 83rd General Assembly, 16-17 April 2024, ETSI members elected the ETSI Director-General Mr. Jan Ellsberger with a majority on the third ballot.

Read More...




j

Frederick Douglass and Harriet Jacobs: American Slave Narrators

New essay by Lucinda MacKethan just added to Freedom's Story: Teaching African American Literature and History, TeacherServe from the National Humanities Center.




j

Jazz and the African American Literary Tradition

New essay, "Jazz and the African American Literary Tradition," by Gerald Early, Merle Kling Professor of Modern Letters at Washington University in St. Louis, added to Freedom's Story: Teaching African American Literature and History, TeacherServe from the National Humanities Center.




j

2024 Martin J. Forman Lecture | Supporting and shaping the global nutrition agenda with evidence




j

2024 Martin J. Forman Lecture | Supporting and shaping the global nutrition agenda with evidence




j

Supporting and shaping the global nutrition agenda with evidence: A three-decade journey of resea…




j

CVE-2024-47575: Frequently Asked Questions About FortiJump Zero-Day in FortiManager and FortiManager Cloud

Frequently asked questions about a zero-day vulnerability in Fortinet’s FortiManager that has reportedly been exploited in the wild.

Background

The Tenable Security Response Team (SRT) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding a zero-day vulnerability in Fortinet’s FortiManager.

Update October 23: The blog has been updated with new information about in-the-wild exploitation and threat actor activity associated with this vulnerability.

View Change Log

FAQ

What is FortiJump?

FortiJump is a name given to a zero-day vulnerability in the FortiGate-FortiManager (FGFM) protocol in Fortinet’s FortiManager and FortiManager Cloud. It was named by security researcher Kevin Beaumont in a blog post on October 22. Beaumont also created a logo for FortiJump.

What are the vulnerabilities associated with FortiJump?

On October 23, Fortinet published an advisory (FG-IR-24-423) for FortiJump, assigning a CVE identifier for the flaw.

CVEDescriptionCVSSv3
CVE-2024-47575FortiManager Missing authentication in fgfmsd Vulnerability9.8

What is CVE-2024-47575?

CVE-2024-47575 is a missing authentication vulnerability in the FortiGate to FortiManager (FGFM) daemon (fgfmsd) in FortiManager and FortiManager Cloud.

How severe is CVE-2024-47575?

Exploitation of FortiJump could allow an unauthenticated, remote attacker using a valid FortiGate certificate to register unauthorized devices in FortiManager. Successful exploitation would grant the attacker the ability to view and modify files, such as configuration files, to obtain sensitive information, as well as the ability to manage other devices.

Obtaining a certificate from a FortiGate device is relatively easy:

Comment
by from discussion
infortinet

 

According to results from Shodan, there are nearly 60,000 FortiManager devices that are internet-facing, including over 13,000 in the United States, over 5,800 in China, nearly 3,000 in Brazil and 2,300 in India:

When was FortiJump first disclosed?

There were reports on Reddit that Fortinet proactively notified customers using FortiManager about the flaw ahead of the release of patches, though some customers say they never received any notifications. Beaumont posted a warning to Mastodon on October 13:

 

Was this exploited as a zero-day?

Yes, according to both Beaumont and Fortinet, FortiJump has been exploited in the wild as a zero-day. Additionally, Google Mandiant published a blog post on October 23 highlighting its collaborative investigation with Fortinet into the “mass exploitation” of this zero-day vulnerability. According to Google Mandiant, they’ve discovered over 50 plus “potentially compromised FortiManager devices in various industries.”

Which threat actors are exploiting FortiJump?

Google Mandiant attributed exploitation activity to a new threat cluster called UNC5820, adding that the cluster has been observed exploiting the flaw since “as early as June 27, 2024.”

Is there a proof-of-concept (PoC) available for this vulnerability/these vulnerabilities?

As of October 23, there are no public proof-of-concept exploits available for FortiJump.

Are patches or mitigations available for FortiJump?

The following table contains a list of affected products, versions and fixed versions.

Affected ProductAffected VersionsFixed Version
FortiManager 6.26.2.0 through 6.2.12Upgrade to 6.2.13 or above
FortiManager 6.46.4.0 through 6.4.14Upgrade to 6.4.15 or above
FortiManager 7.07.0.0 through 7.0.12Upgrade to 7.0.13 or above
FortiManager 7.27.2.0 through 7.2.7Upgrade to 7.2.8 or above
FortiManager 7.47.4.0 through 7.4.4Upgrade to 7.4.5 or above
FortiManager 7.67.6.0Upgrade to 7.6.1 or above
FortiManager Cloud 6.46.4 all versionsMigrate to a fixed release
FortiManager Cloud 7.07.0.1 through 7.0.12Upgrade to 7.0.13 or above
FortiManager Cloud 7.27.2.1 through 7.2.7Upgrade to 7.2.8 or above
FortiManager Cloud 7.47.4.1 through 7.4.4Upgrade to 7.4.5 or above
FortiManager Cloud 7.6Not affectedNot Applicable

Fortinet’s advisory provides workarounds for specific impacted versions if patching is not feasible. These include blocking unknown devices from attempting to register to FortiManager, creating IP allow lists of approved FortiGate devices that can connect to FortiManager and the creation of custom certificates. Generally speaking, it is advised to ensure FGFM is not internet-facing.

Has Tenable released any product coverage for these vulnerabilities?

A list of Tenable plugins for this vulnerability can be found on the individual CVE page for CVE-2024-47575 as they’re released. This link will display all available plugins for this vulnerability, including upcoming plugins in our Plugins Pipeline.

Get more information

Change Log

Update October 23: The blog has been updated with new information about in-the-wild exploitation and threat actor activity associated with this vulnerability.

Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.




j

Social Media for Science Outreach – A Case Study: The Beagle Project, Galapagos Live & ISS Wave

Selected responses categorized into 'helped', 'helped and harmed' and 'harmed'.




j

Social Media for Science Outreach – A Case Study: National Science Foundation-funded IGERT project team

To tie in with this month’s SoNYC birthday celebrations, we are hosting a collection of case




j

SpotOn London 2012: My not-so-secret-anymore double life: Juggling research and science communication

Dr Anne Osterrieder is a Research and Science Communication Fellow in Plant Cell Biology at the Department of




j

Attack on Titan. 4, Humanity pushes back! / Hajime Isayama ; [translator, Sheldon Drzka ; lettering, Steve Wands].

"Humanity pushes back! The Survey Corps develops a risky gambit— have Eren in Titan form attempt to repair Wall Rose, reclaiming human territory from the monsters for the first time in a century. But Titan-Eren's self-control is far from perfect, and when he goes on a rampage, not even Armin can stop him! With the survival of humanity on his massive shoulders, will Eren be able to return to his senses, or will he lose himself forever?"-- Page [4] of cover.