questions

To Improve Measurement of Changing Nature of Employment, Bureau of Labor Statistics Should Add Questions, Make Other Changes to Workforce Survey

To better measure the changing nature of employment, independent contracting and freelance work, and jobs with unstable hours, a new report from the National Academies of Sciences, Engineering, and Medicine recommends that the U.S. Department of Labor’s Bureau of Labor Statistics (BLS) add questions to the Contingent Worker Supplement (CWS) about work done by people who may not be steadily employed, details about secondary jobs, and work scheduling practices.




questions

New Research Models Offer Promise for Understanding the Human Brain and Finding Pathways to Therapies, But Also Raise Profound Ethical Questions

New models for studying the human brain — human neural organoids, transplants, and chimeras — show promise for advancing understanding of the brain and laying the groundwork for new therapeutic approaches to brain diseases that have so far proved hard to treat, says a new report from the National Academies of Sciences, Engineering, and Medicine.




questions

NIH Should Standardize Questions Used to Collect Sex, Gender, and Sexual Orientation Data in Studies and Surveys, Says New Report

The National Institutes of Health should adopt new practices and standardized language to collect data about sex, gender identity, and sexual orientation from survey respondents or research participants. Better measurements will improve data quality, as well as NIH’s ability to identify and understand LGBTQI+ populations.




questions

Questions plumbing business owners should be asking themselves

Here are 46 business proverbs or truths that apply to the plumbing profession, presented in no particular order. Accompanying each is a question every plumbing company owner should ask about his company.




questions

Asking questions leads to improved worker performance

We had just witnessed a large toolbox talk at a mining construction site in Africa. It wasn’t a bad session; the safety officers were loud and lively in their statements, there was some humor and even the safety manager from the general contractor stepped in to say a couple words.




questions

Frequently asked questions about vehicle maintenance

Because vehicle maintenance is essentially the mechanical equivalent of keeping up with your regular physicals and other necessary doctor’s appointments, it’s time for a bit of a checkup.




questions

Solveit.Earth's History-Making Founder, Unveils His Most Unusual and Secretive Project: An Experiment to Face Our Humanity, and Uncover the Keys to Answering Our Greatest Questions

Looking through the mind of an unconventional genius, the user delves into the fascinating hidden worlds of numbers, connective logic, belief, and possibility




questions

Connect! Radio Welcomes Special Guest Seth Arsenault to Answer Listener Questions About Preparing for a Job Search

On-Air Sales Coach and Program Host Deb Calvert announces January 5 radio show will feature President of Your Hire Source. Listeners are invited to write in ahead or to call in live with questions about getting prepared for next level jobs.




questions

Are You Asking the Right Questions?

Few leaders have been trained to ask great questions. That might explain why they tend to be good at certain kinds of questions, and less effective at other kinds. Unfortunately, that hurts their ability to pursue strategic priorities. Arnaud Chevallier, strategy professor at IMD Business School, explains how leaders can break out of that rut and systematically ask five kinds of questions: investigative, speculative, productive, interpretive, and subjective. He shares real-life examples of how asking the right sort of question at a key time can unlock value and propel your organization. With his IMD colleagues Frédéric Dalsace and Jean-Louis Barsoux, Chevallier wrote the HBR article "The Art of Asking Smarter Questions."




questions

High Court Questions Viability of Defense Based on Worker's Failure to Disclose Prior Injury

The South Carolina Supreme Court upheld a finding that a worker was entitled to benefits for a back injury, but it questioned the continued viability of its case law allowing…




questions

How to tackle big goals by narrowing your focus with two simple questions

I made some poor decisions in my 20s. Or rather, a series of poor decisions that seemed to stack and compound. I took on tens of thousands of dollars of credit card, student loan, and tax debt. I gained 70 pounds since graduating high school, because I ate way too much fast food and pretty …

The post How to tackle big goals by narrowing your focus with two simple questions appeared first on Nathan Rice.




questions

Are You Buying a Lawsuit with ‘Big Data’? HR Must Ask the Right Questions

During a presentation at the 2017 SHRM Employment Law and Legislative Conference, Marko Mrkonich, Zev Eigen and Corinn Jackson discussed the risks employers face when using data analytics.

HR Daily Advisor

View Article




questions

4 Questions The Justices' Bias Ruling Leaves To Lower Courts

Alyesha Asghar discusses the potential impact for employers after the Supreme Court’s decision regarding Title VII in Muldrow v. St Louis.

Law360 Employment Authority

View (Subscription required.)




questions

Five Key Questions to Formulate a Top-Down Strategy for APAC Layoffs

Isha Malhotra, Trent Sutton and Nancy Zhang offer guidelines for in-house counsel when advising a business on a restructure in APAC.

ACC Docket

View 




questions

4 W&H Questions As We Enter Pandemic's 4th Year

Claire Deason weighs in on whether employers are obligated to pay for remote employees' commutes into work, business expenses and paid sick time.

Law360 Employment Authority

View (Subscription required.) 




questions

Untangling the Oregon Leave Quagmire – Answers to Common Compliance Questions in Light of Recent Legislative Changes

If you have employees working in Oregon, chances are you have heard about Oregon’s Paid Family and Medical Leave Insurance Program also known as Paid Leave Oregon (“PLO”). In addition to PLO, eligible Oregon employees may be entitled to leave under the Oregon Family Medical Leave Act (“OFLA”), Oregon Sick Time law (“OSTL”), and the federal Family Medical Leave Act (“FMLA”).




questions

Your Burning Employment Law Questions Answered




questions

Emergency Act Leaves Many Unanswered Questions

Law360.com

In this attorney-authored article, Steven Friedman of Littler's New York office and Ellen Sueda of Littler's San Francisco office discuss the ambiguities in the Emergency Economic Stabilization Act of 2008 and the changes that financial institutions must make to their current compensation practices in light of the current legislative language.




questions

OFCCP’s First Webinar on its New Contractor Portal Leaves Most Questions Unanswered

On February 1, 2022, the Office of Federal Contract Compliance Programs (OFCCP) presented a webinar on its new contractor portal through which covered contractors are being asked to certify whether they are meeting their requirement to develop and maintain annual affirmative action programs.




questions

OFCCP Revises Compensation Analysis Directive But Leaves Questions About Documentation Created Under Attorney-Client Privilege

On August 18, 2022, the Office of Federal Contract Compliance Programs (OFCCP) issued a revised version of its Directive 2022-01 - Advancing Pay Equity Through Compensation Analysis, which was originally issued on March 15, 2022.




questions

Questions surround proposed FAMLI rules as program preps for January launch

David Gartenberg said he is worried about the fact that the rule leaves the FAMLI benefits out of alignment with unpaid Family and Medical Leave benefits allowed under federal law. 

The Sum & Substance

View




questions

The New Telework Regime in Portugal: 50 Questions & Answers

Portugal recently approved significant changes to the country’s telework regime.




questions

4 Questions On Discrimination Attys' Minds In The New Year

Alyesha Dotson says the Supreme Court’s upcoming decision on whether to overrule a 2003 decision that upheld affirmative action in student admissions won’t set new precedent for employers, but may have repercussions in how diversity, equity and inclusion programming is conducted moving forward.

Law360 Employment Authority

View (Subscription required.)




questions

Love Your Lawyer: Littler Lawyers Answer Your Most Burning Labor and Employment Questions




questions

5 Questions About NY's Workplace Violence Prevention Law

Rebecca Goldstein and Terri Solomon comment on New York's Retail Worker Safety Act, which requires retail employers to adopt a violence prevention policy.

Law360 Employment Authority

View (Subscription required)




questions

CVE-2024-47575: Frequently Asked Questions About FortiJump Zero-Day in FortiManager and FortiManager Cloud

Frequently asked questions about a zero-day vulnerability in Fortinet’s FortiManager that has reportedly been exploited in the wild.

Background

The Tenable Security Response Team (SRT) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding a zero-day vulnerability in Fortinet’s FortiManager.

Update October 23: The blog has been updated with new information about in-the-wild exploitation and threat actor activity associated with this vulnerability.

View Change Log

FAQ

What is FortiJump?

FortiJump is a name given to a zero-day vulnerability in the FortiGate-FortiManager (FGFM) protocol in Fortinet’s FortiManager and FortiManager Cloud. It was named by security researcher Kevin Beaumont in a blog post on October 22. Beaumont also created a logo for FortiJump.

What are the vulnerabilities associated with FortiJump?

On October 23, Fortinet published an advisory (FG-IR-24-423) for FortiJump, assigning a CVE identifier for the flaw.

CVEDescriptionCVSSv3
CVE-2024-47575FortiManager Missing authentication in fgfmsd Vulnerability9.8

What is CVE-2024-47575?

CVE-2024-47575 is a missing authentication vulnerability in the FortiGate to FortiManager (FGFM) daemon (fgfmsd) in FortiManager and FortiManager Cloud.

How severe is CVE-2024-47575?

Exploitation of FortiJump could allow an unauthenticated, remote attacker using a valid FortiGate certificate to register unauthorized devices in FortiManager. Successful exploitation would grant the attacker the ability to view and modify files, such as configuration files, to obtain sensitive information, as well as the ability to manage other devices.

Obtaining a certificate from a FortiGate device is relatively easy:

Comment
by from discussion
infortinet

 

According to results from Shodan, there are nearly 60,000 FortiManager devices that are internet-facing, including over 13,000 in the United States, over 5,800 in China, nearly 3,000 in Brazil and 2,300 in India:

When was FortiJump first disclosed?

There were reports on Reddit that Fortinet proactively notified customers using FortiManager about the flaw ahead of the release of patches, though some customers say they never received any notifications. Beaumont posted a warning to Mastodon on October 13:

 

Was this exploited as a zero-day?

Yes, according to both Beaumont and Fortinet, FortiJump has been exploited in the wild as a zero-day. Additionally, Google Mandiant published a blog post on October 23 highlighting its collaborative investigation with Fortinet into the “mass exploitation” of this zero-day vulnerability. According to Google Mandiant, they’ve discovered over 50 plus “potentially compromised FortiManager devices in various industries.”

Which threat actors are exploiting FortiJump?

Google Mandiant attributed exploitation activity to a new threat cluster called UNC5820, adding that the cluster has been observed exploiting the flaw since “as early as June 27, 2024.”

Is there a proof-of-concept (PoC) available for this vulnerability/these vulnerabilities?

As of October 23, there are no public proof-of-concept exploits available for FortiJump.

Are patches or mitigations available for FortiJump?

The following table contains a list of affected products, versions and fixed versions.

Affected ProductAffected VersionsFixed Version
FortiManager 6.26.2.0 through 6.2.12Upgrade to 6.2.13 or above
FortiManager 6.46.4.0 through 6.4.14Upgrade to 6.4.15 or above
FortiManager 7.07.0.0 through 7.0.12Upgrade to 7.0.13 or above
FortiManager 7.27.2.0 through 7.2.7Upgrade to 7.2.8 or above
FortiManager 7.47.4.0 through 7.4.4Upgrade to 7.4.5 or above
FortiManager 7.67.6.0Upgrade to 7.6.1 or above
FortiManager Cloud 6.46.4 all versionsMigrate to a fixed release
FortiManager Cloud 7.07.0.1 through 7.0.12Upgrade to 7.0.13 or above
FortiManager Cloud 7.27.2.1 through 7.2.7Upgrade to 7.2.8 or above
FortiManager Cloud 7.47.4.1 through 7.4.4Upgrade to 7.4.5 or above
FortiManager Cloud 7.6Not affectedNot Applicable

Fortinet’s advisory provides workarounds for specific impacted versions if patching is not feasible. These include blocking unknown devices from attempting to register to FortiManager, creating IP allow lists of approved FortiGate devices that can connect to FortiManager and the creation of custom certificates. Generally speaking, it is advised to ensure FGFM is not internet-facing.

Has Tenable released any product coverage for these vulnerabilities?

A list of Tenable plugins for this vulnerability can be found on the individual CVE page for CVE-2024-47575 as they’re released. This link will display all available plugins for this vulnerability, including upcoming plugins in our Plugins Pipeline.

Get more information

Change Log

Update October 23: The blog has been updated with new information about in-the-wild exploitation and threat actor activity associated with this vulnerability.

Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.




questions

Dear Libby : will you answer my questions about friendship?.

How do we find lasting, trusting, and fulfilling friendships? Is it by being popular? Dazzling others with your genius? Looking for that ultimate BFF? Hiding all your imperfections and trying hard to fit in? Deep and enduring friendships are essential to our psychological and physical well-being. Unfortunately, between bullying, social anxiety, peer pressure, and other issues, many teens feel isolated. In Dear Libby, trusted columnist Libby Kiszner offers a breakthrough approach to friendship and connection. You can create friendships from the inside out-rather than from the outside in. You can experience friendships with vibrant self-expression in every stage of life, making Dear Libby a book that can be read and reread at any age. Containing seven core principles, this life-changing resource not only explains the dynamics of connections and friendships but also gives practical tools to develop them. Integrating contemporary issues, timeless insight, real-life skills, and unique perspectives, Dear Libby provides a hands-on guide for dealing with everyday friendship struggles faced by teens today. Teens and readers of all ages will gain insight and understanding on how to make profound, joyful relationships possible. Find answers to real questions like: What should I do when people who are supposed to be my friends call me names or embarrass me? What should I do I do if I'm being ignored at school? What is the best way to handle loneliness? Someone just stole my friend. What can I do? What can I do when my friends get together and "forget" to invite me?




questions

Your banking questions, answered

It's been a month since the collapse of Silicon Valley Bank touched off the worst episode of banking turmoil since 2008. While the financial system appears to have stabilized, we're still reckoning with what happened. Regulators are getting dragged before Congress. The Federal Reserve and the FDIC have promised reports on what went wrong with bank oversight. And judging by our inbox, you, our listeners, have a lot of lingering questions.

Questions like: Was it a bailout? Where were the regulators? Is it over yet? And what about those other banks that were teetering on the edge?

Today on the show, some answers for you.

This episode was produced by Sam Yellowhorse Kesler with help from Willa Rubin. It was engineered by Brian Jarboe. It was fact-checked by Sierra Juarez and edited by Molly Messick. Jess Jiang is our acting executive producer.

Help support Planet Money and get bonus episodes by subscribing to Planet Money+ in
Apple Podcasts or at plus.npr.org/planetmoney.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




questions

A trucker hat mystery, the curse of September and other listener questions

Ba-dee-yah! Say do you remember? Ba-dee-yah! Questions in September!

That's right - it's time for Listener Questions!

Every so often, we like to hear from listeners about what's on their minds, and we try to get to the bottom of their economic mysteries. On today's show, we have questions like:

Why is September historically the worst month for the stock market?
How did the Bass Pro Shops hat get so popular in Ecuador?
Are casinos banks?
What is the Federal Reserve's new plan to make bank transfers faster?

Today's show was hosted by Sarah Gonzalez and produced by James Sneed. The audio engineer for this episode was Josephine Nyounai. It was fact checked by Sierra Juarez and edited by Dave Blanchard. Alex Goldmark is our executive producer.

Help support Planet Money and get bonus episodes by subscribing to Planet Money+ in
Apple Podcasts or at plus.npr.org/planetmoney.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




questions

Before Using Internal Competition to Improve Employee Engagement, You Need to Answer These Questions

A little healthy competition is a good thing — under the right circumstances and with the right people. In many industries, internal competition has long been used to increase everything from productivity to profits. But what about using competition as part of your employee engagement strategy? Does pitting individual workers against each other really increase engagement across the board? While there are




questions

Security and the Smart Thermostat: Prepare for Customer Questions

The path to temperature control through smart thermostat technology is more involved than many customers realize.




questions

Questions about IPS-Policy

Posted by Bestell_E-Mail via Snort-sigs on Oct 22

Hello.

First of all, please excuse me if this question is asked a lot.

I am a beginner and currently using the IPS Policy with the Business License.

I am not sure if Personal or Business License is right for me. Are the IPS policies different in any way for these two
licenses?

Best regards

Waldemar Sager_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org...




questions

Donald Trump's win: YOUR questions answered

Donald Trump has won the 2024 US election and will be president for a second time from early next year. Lots of you had questions and we asked a BBC expert to answer them.





questions

Australian Rhyming Slang 2 (10 questions)

Title: Australian Rhyming Slang 2
Topic: Cockney Rhyming Slang
Level: Advanced
Information: Choose the correct answer.
Link: https://www.usingenglish.com/quizzes/570.html




questions

Which or Where? (10 questions)

Title: Which or Where?
Topic: Relative Clauses and Pronouns
Level: Intermediate
Information: Choose the correct answer.
Link: https://www.usingenglish.com/quizzes/571.html








questions

Idioms- Furniture and Household Fittings (10 questions)

Title: Idioms- Furniture and Household Fittings
Topic: Idioms
Level: Advanced
Information: Choose the correct answer.
Link: https://www.usingenglish.com/quizzes/576.html







questions

Phrasal Verbs- Finish (10 questions)

Title: Phrasal Verbs- Finish
Topic: Phrasal Verbs
Level: Intermediate
Information: Choose the correct answer.
Link: https://www.usingenglish.com/quizzes/580.html




questions

Phrasal Verbs - Take 2 (10 questions)

Title: Phrasal Verbs - Take 2
Topic: Phrasal Verbs
Level: Intermediate
Information: Choose the correct answer.
Link: https://www.usingenglish.com/quizzes/581.html




questions

Phrasal Verbs - Back (10 questions)

Title: Phrasal Verbs - Back
Topic: Phrasal Verbs
Level: Intermediate
Information: Choose the correct answer.
Link: https://www.usingenglish.com/quizzes/582.html