ddr

Consumers seek deals, shop around to address inflation-related impacts on food prices

Consumers are adapting their shopping strategies to include more flexibility as they attempt to control their grocery spending heading into the fall, according to the latest survey conducted by FMI – The Food Industry Association and The Hartman Group.




ddr

SupplySide West addresses timely, relevant topics

SupplySide West, which took place Oct. 25-26 in Las Vegas, hosted more than 1,400 exhibitors, up 27% from 2022. Exhibitors showcased the latest developments in ingredients, formulation, manufacturing and packaging covering categories including dietary supplements, food, beverage, personal care and animal nutrition.




ddr

Sleeve labels offers billboard effect while addressing recyclability

The eye-catching design of shrink and stretch labels make them desirable to beverage-makers, but experts add that sustainability is playing a greater role in the future of this market.




ddr

BiCupid Addresses the Struggles of Bisexual Daters in Going on Queer Dates

As a dating site for bisexual singles and couples, BiCupid offers solutions to the challenges faced by bisexual daters when it comes to going on queer dates.




ddr

Heidi Kling: Addressing the Mental Health Needs of Young Women in New York Through Her Efforts as a Psychotherapist

Heidi Kling psychologist




ddr

LEAX Telecom USA President, Richard Qu, Addresses PIKOM Leadership Summit in Malaysia

Empowering Private Network to Metaverse




ddr

Clinical Validation in Dark Pigmented Individuals Finds CIRCUL™ Pulse Oximetry Ring Provides Reliable Oxygen Saturation Readings Addressing Potential Discrimination in Traditional Pulse Oximeters

CIRCUL™ Pulse Oximetry Wearable Technology Demonstrated Statistically Significant Correlation in Delivering Stable Oxygen Saturation Value in Dark-Pigmented Individuals




ddr

CEI Institute partners with Filene Research Institute to Address Racial Economic Equity

An Outreach to Those Not Previously Reached




ddr

The Trauma Of Aging And The Possibility Of A Full Life Addressed By Dr. Kixx Goldman, Author Of Bestselling Book, Speak From Your Heart And Be Heard

'Speak From Your Heart And Be Heard' contains fictionalized inspiring stories, based on real life and professional experience. The ebook version is a bestseller in the Single Author Short Stories category.




ddr

Softhread Inc. Announces Prestigious NSF Phase II SBIR Grant to Fund Development of Chios™ QR-Exchange Platform Tailored to Address Complex Healthcare Interoperability and Data Exchange Challenges

Artificial Intelligence-Enabled and Blockchain-Powered Innovative Technology Platform Catalyzing a Major Shift Towards Precision Health and Personalized Medicine.




ddr

Social Gratitude App Addresses Negative Effects of Social Media

Gracefill helps resolutions to be kinder and more grateful in 2024




ddr

Jack Billups, Bestselling Author Of My Vietnam And Christian's Walk, Addresses The Worry Anguished Parents And Grandparents Experience Over The Change In Traditional American Values

Author Jack Billups' first book, 'My Vietnam' was a bestseller in the Vietnam War Memoir category. The new book was inspired by John Bunyan's immortal classic, 'Pilgrims Progress'.




ddr

Van Dam: Biden's State Of The Union Address Is Devoid From Reality

Lacking The Vision And Hope America and the World Needs




ddr

Addressing How This New Crypto Technology Could Change the Landscape of Traditional Institutions

Could this new technology change traditional institutions for the better?




ddr

The Anguish Of Traumatic Brain Injury (TBI) And The Path To Healing Addressed By Dr. Kixx Goldman, Author Of Bestselling Book, Speak From Your Heart And Be Heard

'Speak From Your Heart And Be Heard' contains fictionalized inspiring stories, based on real life and professional experience. The ebook version is a bestseller in the Single Author Short Stories category.




ddr

Bullying As A Social Norm Is Addressed By Bestselling Magical Realism Author Jody Sharpe

As a former teacher of special needs children, Sharpe has direct experience regarding the effect bullying has on children. Her award-winning, bestselling books help readers find hope, inspiration and gratitude.




ddr

CCC to partner with Morressier to address and validate research integrity

CCC is developing a beta version of a new Ringgold Service to help disambiguate and validate the identity of researchers




ddr

Adopting RAG while addressing its complexities with Shelf, Coveo, and Progress Semaphore

Experts from Shelf, Coveo, and Progress Semaphore joined KMWorld's webinar, Unlocking the Power of RAG, to speak to the nuance of extracting value from RAG at scale while mitigating its complications




ddr

Supreme Court to Address Exception to Going-and-Coming Rule

The Pennsylvania Supreme Court will weigh in on the applicability of the “no-fixed-place-of-work” exception to the “going-and-coming rule” for a tree-trimming supervisor. In February, the Commonwealth Court issued a decision finding that Jorge Martinez…




ddr

Lawmaker Introduces Bill to Address Surviving Spouse Benefits

Pennsylvania Rep. Lindsay Powell introduced legislation that would require that the same eligibility standards apply when awarding death benefits to widows and widowers while also exempting spouses of first responders…




ddr

CMS Clarifies Use of Non-Submit WCMSAs To Address Future Medical

As a national leader on all components of workers compensation education, WorkCompCentral continues to provide exceptional opportunities to learn about all aspects of work comp law, policy, procedures, and practice.




ddr

Website tracking & addressing your privacy

On our website designworkplan we used Google Analytics for collecting visitors data. When we started the blog way back in 2008 it was a good way to find out which content viewers of our website liked and disliked. A user-friendly dashboard to find out important metrics related to viewers of the website.

Google Analytics gave us insights on popular pages and were people visited our website from. This allowed us to target those audiences more and as a result we gained traction to our (design) website. Our content evolves around design, typography and wayfinding. Wayfinding is a design niche that focusses at connecting people to information and environments.

If you want to learn more about wayfinding, please read our page Introduction to Wayfinding.

Over time Google Analytics grew in complexity to an extend we have a hard time understanding the metrics shown in the dashboards.

Google Analytics back to the future

In the beginning Google Analytics was plain and simple, the right fit for our design content. As a content creator we are interested in how visitors perceive information on our website. Information about popular pages, demographics and referral sources are meaningful for establishing an understanding of what visitors are looking for.

Privacy and data collection

Over time we realized Google used our collected data for their benefits. Although Google says to “never” sell any personal information. The collective gathered information through Google Analytics is an immense source of valuable information about browser behaviour online. Not only it provides information on topics people are interested in, it also gives information about reading time, bounce rates and related information people are interested in. Maybe Google doesn’t use the information gathered from our website, but sure it can create a broader sense of what people in general are interested in.

As Google remains to control most of the internet search queries and related internet services such as advertising. Google can combine Analytics and Adwords to maximize their profit ratio. In other words, we believe as Google has a tremendous amount of information from the Analytics part of their database. The Adwords part of Google will benefit from this information, as they are familiar with what people search for and what related information people would be interested in.

Our most popular posts on the blog

Over the years we have published many articles on the blog. Via our visitors data tracking we could see these are our most popular posts:

Our series about typography did very well over the last years, including the following articles:

Our book series are popular with the following reviews:

Over the years we have continued our writing, consider looking at our blog to learn more about wayfinding.

Seamless reading experience

We are wayfinding and information designers. Our core services evolve around information, people and places. Connecting information at the right time and place. As we are browsing the internet, the reading experiences are mostly dreadful. Pop-ups, reminders, boxes, ads, etc.

At our website we want people to enjoy our content, without having to read privacy policies and forcing visitors to click "Accept" buttons. We want to create a seamless reading experience without distractions.

The brilliant website How I Experience Web Today is a fantastic example of most browsing experiences today. So familiar, yet so disappointing experiences.

According to research the average internet user spends ~3 hours online every day, visiting anywhere from 5 up-tp 100 website each day. Imagine the time lost for accepting all those cookies each and every day.

Recently it came to our attention that Google Analytics is in conflicts with European regulations and is not fully GDPR complaint. In relationship to the cookie, accept privacy terms and UX issues it got us to rethink the analytics part of our website.

From past to present

As we want to comply to European guidelines regarding data collection and to create a seamless reading experience, we started to seek an alternative for Google Analytics.

As also found Google Analytics was found illegal in an Austrian court decision. The details of that decision can be found here

From here our search began looking for an alternative way to collect visitors data at our website. We have tried other different analytics services, which include:

  • Matomo analytics, a self hosted analytics service. Comes with many features and is free to use. We have found installing the software and dashboard somewhat complicated to use.
  • Statscounter, great alternative. The dashboard has a good UX design and the service has many features to track visitors behaviour. Statscounter is an anonymous web tracking service which is good to become GDPR compliant. The paid version starts at $19,- per month.
  • Fathom, a very user friendly interface, cookie-free and GDPR proof with anonymous web tracking. Starting at $14,- per month. ($140,- p/y)

Our research was plain simple, trying out the services as mentioned above for ~14 days. The experiment gave us insights on what we wanted to see in our analytics, useful metrics, ease of use, GDPR free. As running websites is NOT our daily focus, we found out our needs are UX and ease of use based. Meaning a single dashboard solution, main metrics and great UX design. In our quest for the Google Analytics alternative we landed at Fathom Analytics.

Example Fathom Analytics Dashboard

Use Fathom Analytics

Our basic requirements are formulated as following:

  • GDPR Proof and anonymous pageview tracking
  • Fast loading script, by-passing ad blockers and no cookies
  • Easy to use dashboard, in one overview
  • Information about pages, average time on site/page and traffic sources
  • Information about devices, browsers and countries
  • Possibility to track specific actions or events on webpages (easy funnel)
  • Track multiple websites in one dashboard/account

As we deploy multiple websites, a single dashboard solution is ideal to gain overview insights on performance.

Reading experience & privacy

Our website and content creation is focussed on providing niche information for design, typography and wayfinding. In our opinion Google Analytics has become a complex platform with too many functionalities. We understand that professional website creators and builders could use Google Analytics to its full potential. We simply want to put out great content and gather information about the visitors to our website.

Our goal is provide a visitor to our website a seamless reading experience and enjoying our content without annoying pop-ups or related privacy issues.

From now on forward we have disabled Google Analytics from our websites and are fully compliant with European regulation around collecting information from visitors on our website.

Fathom is a paid service which collects anonymous data from visitors on our websites. We are using a $140,- yearly plan for collecting visitors data from our websites.

Full disclosure

We work as a designers for Google Offices, where we develop and create wayfinding solutions for their visitors and employees. We respect Google for their vision and the way how they organize their workplaces, people and environments. At our website (designworkplan) we have chosen to use fathom for reasons stated in this article. We are not paid or sponsored by usefathom. If you want to support us, please use our affiliate link below.

Final thoughts

This post is different from our usual design content, we wanted to be fully transparant in the way how we collect visitors data from our websites. Consider thinking about the way you collect visitors data at your website(s).


If you are planning to use Fathom, consider using our referral link (highly appreciated) Use Fathom referral code CCPSXY


Frequently Asked Questions (FAQ)

What is GDPR?

Regulation on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (Data Protection Directive). Link to GDPR




ddr

Millions Of People No Longer Have An Address. Yet We Know How To Reach Them.

Imagine an empty apartment block, stark and desolate, with just a single light flickering in the overwhelming darkness. This is not a scene from a movie; it ...




ddr

A4: Web 2.0: Addressing Institutional Barriers

Brian Kelly, UKOLN and Lawrie Phipps, JISC will review the barriers which we may face when implementing a Web 2.0 strategy and will outline a model and strategies which can be be used in order to address such barriers.




ddr

Ontario, Canada Court Addresses Statutory Tort of Human Trafficking in Labour Context

  • Temporary foreign worker made a claim for damages against employer for the statutory tort of human trafficking under the Prevention of and Remedies for Human Trafficking Act.




ddr

8 Steps for Addressing Bullying in the Workplace

Kevin O’Neill co-authored this article about how employers can combat workplace bullying.

Corporate Counsel

View Article (subscription required)




ddr

8 Steps for Addressing Bullying in the Workplace

Katherine Cooper Franklin co-authored this article about how employers can combat workplace bullying.

Corporate Counsel

View Article (subscription required)




ddr

SLAPP Back: Colorado Court of Appeals Addresses Protection Against “Vengeful” Online Posts

On November 30, 2023, the Colorado Court of Appeals in Tender Care v.




ddr

How CEOs Can Address Politics In The Workplace Ahead Of The 2024 Election

Bradford J. Kelley and Michael J. Lotito discuss key steps to consider when business leaders work with their teams and HR departments to develop political speech policies and enforcement strategies.

Chief Executive

View




ddr

NLRB Decision Addresses Interaction between Confidentiality and Nondisparagement Provisions in Severance Agreements and Section 7 Rights

  • In McLaren Macomb, the NLRB overturned two decisions that had permitted employers to include confidentiality and nondisparagement provisions in severance agreements.
  • “Mere proffer” of a severance agreement that conditions receipt of benefits on the “forfeiture of statutory rights” violates the NLRA.
  • This Insight includes key takeaways from the Board’s decision and answers to common employer questions.




ddr

Ontario, Canada Court of Appeal Addresses How Employers Can Preserve Right to Unilaterally Lay Off Employees Without Being Found to Have Constructively Dismissed Them




ddr

How can employers address varying sensitivities to DEI issues in a multinational workforce?




ddr

Second Chance Employment: Addressing Concerns About Negligent Hiring Liability

Rod Fliegel co-authors a report that explains negligent hiring, employers’ risks and how they can protect their company. 

Legal Action Center

View




ddr

A Look at the Proliferation of New Legislation Addressing IE&D Across the Country

  • There has been an explosion of inclusion, equity and diversity-based legislation over the last two years.
  • Since 2023, dozens of “anti-IE&D” bills have been introduced and 12 have become law, attempting to restrict IE&D-related activities.
  • At the same time, several jurisdictions have recently sought to introduce “pro-IE&D” bills that would require IE&D training and other IE&D-related activities.




ddr

Connecticut Addresses E-Cigarettes and Vapor Products, Imposes Signage Requirements on Select Employers

Connecticut has passed a new law regulating electronic nicotine delivery systems and vapor products in various venues, including numerous places of employment.  Effective October 1, 2015, Public Act No. 15 206 (the Act) supersedes and preempts any relevant provisions of municipal laws or ordinances regarding the use of these products. 

The Law

The Act prohibits the use of electronic nicotine delivery systems and vapor products in:

1. buildings owned or leased and operated by the state or its political subdivisions,




ddr

ETSI standardizes new Secure Platform to address IoT, 5G, and security sensitive sectors

ETSI standardizes new Secure Platform to address IoT, 5G, and security sensitive sectors

Sophia Antipolis, 18 November 2019

Trust and privacy together with cost and flexibility are key to security solutions for many applications in today’s digital world. To address this challenge, ETSI Technical Committee Smart Card Platform, who standardized the former generations of SIM cards, has been working on a brand-new security platform called Smart Secure Platform (SSP). The ETSI committee is pleased to unveil the first three technical specifications to launch this new security platform.

Read More...




ddr

ETSI launches new group on Non-IP Networking addressing 5G new services

ETSI launches new group on Non-IP Networking addressing 5G new services

Sophia Antipolis, 7 April 2020

ETSI is pleased to announce the creation of a new Industry Specification Group addressing Non-IP Networking (ISG NIN). The kick-off-meeting took place on 25 March and John Grant, BSI, was elected as the ISG Chair, and Kevin Smith, Vodafone, was elected as ISG Vice Chair.

With the increasing challenges placed on modern networks to support new use cases and greater connectivity, Service Providers are looking for candidate technologies that may serve their needs better than the TCP/IP-based networking used in current systems.

ISG NIN intends to develop standards that define technologies to make more efficient use of capacity, have security by design, and provide lower latency for live media.

Read More...




ddr

ETSI Multi-Access Edge Computing extends services to WiFi to address enterprise needs

ETSI Multi-Access Edge Computing extends services to WiFi to address enterprise needs

Sophia Antipolis, 16 July 2020

The ETSI Industry Specification Group on Multi-Access Edge Computing, ISG MEC, has recently released ETSI MEC GS 028 to extend network information services to the world of WiFi and thus squarely into enterprises space.

Read More...




ddr

Microsoft’s November 2024 Patch Tuesday Addresses 87 CVEs (CVE-2024-43451, CVE-2024-49039)

  1. 4Critical
  2. 82Important
  3. 1Moderate
  4. 0Low

Microsoft addresses 87 CVEs and one advisory (ADV240001) in its November 2024 Patch Tuesday release, with four critical vulnerabilities and four zero-day vulnerabilities, including two that were exploited in the wild.

Microsoft patched 87 CVEs in its November 2024 Patch Tuesday release, with four rated critical, 82 rated important and one rated moderate.

This month’s update includes patches for:

  • .NET and Visual Studio
  • Airlift.microsoft.com
  • Azure CycleCloud
  • Azure Database for PostgreSQL
  • LightGBM
  • Microsoft Exchange Server
  • Microsoft Graphics Component
  • Microsoft Office Excel
  • Microsoft Office Word
  • Microsoft PC Manager
  • Microsoft Virtual Hard Drive
  • Microsoft Windows DNS
  • Role: Windows Hyper-V
  • SQL Server
  • TorchGeo
  • Visual Studio
  • Visual Studio Code
  • Windows Active Directory Certificate Services
  • Windows CSC Service
  • Windows DWM Core Library
  • Windows Defender Application Control (WDAC)
  • Windows Kerberos
  • Windows Kernel
  • Windows NT OS Kernel
  • Windows NTLM
  • Windows Package Library Manager
  • Windows Registry
  • Windows SMB
  • Windows SMBv3 Client/Server
  • Windows Secure Kernel Mode
  • Windows Task Scheduler
  • Windows Telephony Service
  • Windows USB Video Driver
  • Windows Update Stack
  • Windows VMSwitch
  • Windows Win32 Kernel Subsystem

Remote code execution (RCE) vulnerabilities accounted for 58.6% of the vulnerabilities patched this month, followed by elevation of privilege (EoP) vulnerabilities at 29.9%.

Important

CVE-2024-43451 | NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-43451 is a NTLM hash spoofing vulnerability in Microsoft Windows. It was assigned a CVSSv3 score of 6.5 and is rated as important. An attacker could exploit this flaw by convincing a user to open a specially crafted file. Successful exploitation would lead to the unauthorized disclosure of a user’s NTLMv2 hash, which an attacker could then use to authenticate to the system as the user. According to Microsoft, CVE-2024-43451 was exploited in the wild as a zero-day. No further details about this vulnerability were available at the time this blog post was published.

This is the second NTLM spoofing vulnerability disclosed in 2024. Microsoft patched CVE-2024-30081 in its July Patch Tuesday release.

Important

CVE-2024-49039 | Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-49039 is an EoP vulnerability in the Microsoft Windows Task Scheduler. It was assigned a CVSSv3 score of 8.8 and is rated as important. An attacker with local access to a vulnerable system could exploit this vulnerability by running a specially crafted application. Successful exploitation would allow an attacker to access resources that would otherwise be unavailable to them as well as execute code, such as remote procedure call (RPC) functions.

According to Microsoft, CVE-2024-49039 was exploited in the wild as a zero-day. It was disclosed to Microsoft by an anonymous researcher along with Vlad Stolyarov and Bahare Sabouri of Google's Threat Analysis Group. At the time this blog post was published, no further details about in-the-wild exploitation were available.

Important

CVE-2024-49019 | Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2024-49019 is an EoP vulnerability affecting Active Directory Certificate Services. It was assigned a CVSSv3 score of 7.8 and is rated as important. It was publicly disclosed prior to a patch being made available. According to Microsoft, successful exploitation would allow an attacker to gain administrator privileges. The advisory notes that “certificates created using a version 1 certificate template with Source of subject name set to ‘Supplied in the request’” are potentially impacted if the template has not been secured according to best practices. This vulnerability is assessed as “Exploitation More Likely” according to Microsoft’s Exploitability Index. Microsoft’s advisory also includes several mitigation steps for securing certificate templates which we highly recommend reviewing.

Important

CVE-2024-49040 | Microsoft Exchange Server Spoofing Vulnerability

CVE-2024-49040 is a spoofing vulnerability affecting Microsoft Exchange Server 2016 and 2019. It was assigned a CVSSv3 score of 7.5 and rated as important. According to Microsoft, this vulnerability was publicly disclosed prior to a patch being made available. After applying the update, administrators should review the support article Exchange Server non-RFC compliant P2 FROM header detection. The supplemental guide notes that as part of a “secure by default” approach, the Exchange Server update for November will flag suspicious emails which may contain “malicious patterns in the P2 FROM header.” While this feature can be disabled, Microsoft strongly recommends leaving it enabled to provide further protection from phishing attempts and malicious emails.

Critical

CVE-2024-43639 | Windows Kerberos Remote Code Execution Vulnerability

CVE-2024-43639 is a critical RCE vulnerability affecting Windows Kerberos, an authentication protocol designed to verify user or host identities. It was assigned a CVSSv3 score of 9.8 and is rated as “Exploitation Less Likely.”

To exploit this vulnerability, an unauthenticated attacker needs to leverage a cryptographic protocol vulnerability in order to achieve RCE. No further details were provided by Microsoft about this vulnerability at the time this blog was published.

Important

29 CVEs | SQL Server Native Client Remote Code Execution Vulnerability

This month's release included 29 CVEs for RCEs affecting SQL Server Native Client. All of these CVEs received CVSSv3 scores of 8.8 and were rated as “Exploitation Less Likely.” Successful exploitation of these vulnerabilities can be achieved by convincing an authenticated user into connecting to a malicious SQL server database using an affected driver. A full list of the CVEs are included in the table below.

CVEDescriptionCVSSv3
CVE-2024-38255SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-43459SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-43462SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48993SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48994SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48995SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48996SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48997SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48998SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-48999SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49000SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49001SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49002SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49003SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49004SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49005SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49006SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49007SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49008SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49009SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49010SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49011SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49012SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49013SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49014SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49015SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49016SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49017SQL Server Native Client Remote Code Execution Vulnerability8.8
CVE-2024-49018SQL Server Native Client Remote Code Execution Vulnerability8.8
Important

CVE-2024-43602 | Azure CycleCloud Remote Code Execution Vulnerability

CVE-2024-43602 is a RCE vulnerability in Microsoft’s Azure CycleCloud, a tool that helps in managing and orchestrating High Performance Computing (HPC) environments in Azure. This flaw received the highest CVSSv3 score of the month, a 9.9 and was rated as important. A user with basic permissions could exploit CVE-2024-43602 by sending specially crafted requests to a vulnerable AzureCloud CycleCloud cluster to modify its configuration. Successful exploitation would result in the user gaining root permissions, which could then be used to execute commands on any cluster in the Azure CycleCloud as well as steal admin credentials.

Tenable Solutions

A list of all the plugins released for Microsoft’s November 2024 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.

For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.

Get more information

Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.




ddr

Canadian roundtable on audit quality addresses current state and trends

Toronto ─ On October 21, the Canadian Securities Administrators (CSA), the Canadian Public Accountability Board (CPAB), and the Office of the Superintendent of Financial Institutions (OSFI) co-hosted the sixth annual Canadian Audit Quality Roundtable.




ddr

Corrected Address - Extended Partial Alley Closure for the alley west of 5600 thru 5614 N. Winthrop Avenue & 1114 W. Bryn Mawr Avenue

Corrected Address - Extended Partial Alley Closure for the alley west of 5600 thru 5614 N. Winthrop Avenue & 1114 W. Bryn Mawr Avenue for alley reconstruction.




ddr

Extended Alley Closure for the alley east of the following addresses will be closed: 947 thru 957 W. Cornelia Avenue, 3433 thru 3457 N. Sheffield Avenue & 946 thru 956 W. Newport Avenue

Extended Alley Closure for the alley east of the following addresses will be closed: 957 W. Cornelia Avenue, 3433 thru 3457 N. Sheffield Avenue & 946 – 956 W. Newport Avenue




ddr

Employment rights reforms fail to address workplace bullying

The lack of a distinct statutory definition of workplace bullying, and of bespoke protections addressing it must be rectified, argues Thomas Beale.

The post Employment rights reforms fail to address workplace bullying appeared first on Personnel Today.




ddr

Designing the engineer of 2050: Canadian engineering educators meet in Toronto - National conference will spark discussion on reinventing education to prepare tomorrow’s diverse engineering leaders to address challenges we can’t yet imagine

National conference will spark discussion on reinventing education to prepare tomorrow’s diverse engineering leaders to address challenges we can’t yet imagineToronto, ON – The toughest problems facing humanity in the 21st century — from water scarcity to urban intensification to personalized medicine — will be tackled by tomorrow’s engineers. Many of the issues they will work to solve […]




ddr

New Network Launched to Address Diabetes Complications - Partnership unites nine institutions in fight against diabetes

Partnership unites nine institutions in fight against diabetesToronto, ON — A new national research network was launched today to transform the health outcomes of individuals with diabetes and its related complications. It will be led by two of Canada’s top researchers in the field and includes researchers conducting leading-edge health and biomedical research at nine institutions […]




ddr

How CT Quality Analysis of EV Batteries Can Help Address Demand and Performance

EVs could represent 45 to 58 percent of all vehicles by 2030, with the lithium-ion battery market expected to grow over 30 percent annually. The question is whether battery quality can keep up with this surge.




ddr

How AI is Addressing Vital Challenges Across the Metrology Value Chain

In March 2023, after a GPT model passed a biology exam, Bill Gates noted on his blog that AI could save lives and address climate change. If AI can tackle such significant challenges, it can also help with issues faced by manufacturers, metrologists, and quality control professionals. This article will examine the challenges metrologists encounter and highlight potential AI-driven solutions in the metrology value chain.




ddr

President Biden Proposes Rule to Address Excessive Heat in Workplace

In early July, the Biden administration proposed a rule that addresses excessive heat in the workplace, as tens of millions of them were under heat advisories — the nation’s No. 1 weather-related cause of death.




ddr

Remove this email address

Posted by Jose Dominguez via Snort-sigs on Oct 22

Please remove this email address from future notifications




ddr

Re: Remove this email address

Posted by Joel Esler via Snort-sigs on Oct 23

Thank you for writing in.

Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-sigs

or by sending an email to snort-sigs-leave () lists snort org

Thanks!