j

RICOH SP 4510DN Printer HTML Injection

An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.




j

RICOH SP 4520DN Printer HTML Injection

An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter.




j

Barco WePresent file_transfer.cgi Command Injection

This Metasploit module exploits an unauthenticated remote command injection vulnerability found in Barco WePresent and related OEM'ed products. The vulnerability is triggered via an HTTP POST request to the file_transfer.cgi endpoint.




j

Keep Your Data Safe: The Joy of Locking Your Computer

Here's a simple way to keep your data safe from potential bad actors in one easy step. Are you ready? Here it is: Log out and lock your computer whenever you're not in front of it.

That's right, it's so simple it can almost be seen as an analog approach to cybersecurity. But make no mistake, all those in-depth disk encryption efforts can be rendered pointless. If you step away from your computer while it's on and unlocked, anyone passing by can access it.

Working Remotely Promotes Data Vulnerability

What's perhaps most insidious about someone gaining physical access to your computer is the fact that the attacker doesn't need any advanced technical know-how to steal sensitive information. A momentary lapse in vigilance at work or a coffee shop can result in a data breach of epic proportions.

Let's say you're working remotely at your favorite café down the street from your apartment and you get up to put in an order for a late breakfast, forgetting to lock your laptop. During that brief moment, a low-key cybervillian could easily stick a USB drive into your computer and copy any sensitive files about you — or your organization — and leave undetected.

Furthermore, if you were logged in to Gmail, your medical records, or your bank account, that malefactor could wreak havoc on your personal and professional life in a matter of minutes.

Tips for Protecting Yourself

The good news about all of this is that warding off these types of would-be data plunderers is really, really easy — it's simply a matter of using your operating system's screen locking functionality. If you don't want to do this, then at the very least you should log out of any sensitive online accounts whenever you step away from your machine.

For each of the following options, be sure you are aware of the password connected to your user login before locking yourself (or anyone else) out.

Screen Locking in Microsoft Windows

  • Press Ctrl+Alt+Delete and select Lock this computer
  • Press Windows+L

Either of these will lock your computer and require a password to log back in. You can choose Control Panel > Personalization > Screen Saver Settings and set up a screen saver that provides a login screen to get back in once it's been initiated.

Screen Locking in macOS

  • On an external keyboard or older laptops, press Ctrl+Shift+Eject
  • On a MacBook Air or Pro Retina, press Ctrl+Shift+Power

You can also go to System Preferences > Security & Privacy > General and select Require password immediately after sleep or screen saver begins (provided you have already set up a screen saver by clicking System Preferences > Desktop & Screen Saver).

Additional Cybersecurity Resources

Get more security tips from the National Cyber Security Alliance. National Cyber Security Awareness Month — observed every October — was created as a collaborative effort between government and industry to ensure that all Americans have the resources they need to stay safer and more secure online. Find out how you can get involved.

Image: National Cyber Security Alliance





j

Low-Orbit Internet Banking Fraud Claim Alleged To Be Space Junk





j

fDi Index: investors carried weak sentiment into January as coronavirus threat emerged

Announced greenfield projects into China plummeted in early 2020 with the US and Europe taking the lion's share of global foreign investment. 




j

fDi's European Cities and Regions of the Future 2020/21 - FDI Strategy: London and Glasgow take major prizes

London is crowned best major city in Europe in fDi's FDI Strategy category, with Glasgow, Vilnius, Reykjavik and Galway also winning out.




j

Safari Webkit Proxy Object Type Confusion

This Metasploit module exploits a type confusion bug in the Javascript Proxy object in WebKit. The DFG JIT does not take into account that, through the use of a Proxy, it is possible to run arbitrary JS code during the execution of a CreateThis operation. This makes it possible to change the structure of e.g. an argument without causing a bailout, leading to a type confusion (CVE-2018-4233). The type confusion leads to the ability to allocate fake Javascript objects, as well as the ability to find the address in memory of a Javascript object. This allows us to construct a fake JSCell object that can be used to read and write arbitrary memory from Javascript. The module then uses a ROP chain to write the first stage shellcode into executable memory within the Safari process and kick off its execution. The first stage maps the second stage macho (containing CVE-2017-13861) into executable memory, and jumps to its entrypoint. The CVE-2017-13861 async_wake exploit leads to a kernel task port (TFP0) that can read and write arbitrary kernel memory. The processes credential and sandbox structure in the kernel is overwritten and the meterpreter payloads code signature hash is added to the kernels trust cache, allowing Safari to load and execute the (self-signed) meterpreter payload.




j

Total.js CMS 12 Widget JavaScript Code Injection

This Metasploit module exploits a vulnerability in Total.js CMS. The issue is that a user with admin permission can embed a malicious JavaScript payload in a widget, which is evaluated server side, and gain remote code execution.







j

Editorial view: Why FDI is no longer about job creation

The documentary "American Factory" tells us communities need to go beyond the job creation narrative when it comes to attracting foreign investment. 




j

Auckland’s tourism draws major investment opportunities

Steve Armitage, general manager of destination at Auckland Tourism, Events and Economic Development explains why the New Zealand city’s international profile is growing so fast.




j

BASF kicks off China megaproject

German chemical giant BASF has begun construction of its $10bn mega project in southern China, which will be the country’s first wholly foreign-owned chemical complex. 




j

OpenSSH Distribution Trojaned




j

Jamaican tourism minister seeks to explode myths

Edmund Bartlett, Jamaica’s minister of tourism, talks about key investment opportunities and the need for better international reporting when natural disasters strike.




j

China's Jinko Solar sees more foreign sales as domestic market shaky

JinkoSolar Holding Co., the world’s biggest solar panel maker, sees China’s photovoltaic power additions slumping this year and a greater share of its revenue coming from overseas amid uncertainties over Beijing’s new policies.




j

President inaugurates Bolivia’s 69-MW San Jose II Hydroelectric Plant

Bolivian President Evo Morales has inaugurated the 69-MW San Jose II Hydroelectric Power Plant in the municipality of Colomi, department of Cochabamba.





j

Corani seeking financing to develop 147-MW Banda Azul hydro project in Bolivia

Jose Maria Romay, general manager of Corani (a subsidiary of Ende), has announced the company is seeking financing from Latin American development bank CAF and French development agency AFD for the 147-MW Banda Azul hydro project.




j

Women are missing out on the clean energy job boom in America

While the industry is welcoming more women leaders, its rank-and-file workforce is still a lot like those at fossil-fuel companies: white and dominated by men. The lack of gender diversity is being driven by manufacturing jobs, and that means women are now missing out on the biggest jobs boom America has to offer.




j

Integrating rooftop solar just got easier for utilities

Homeowners and businesses may now have an easier time getting solar panels on rooftops thanks to software developed at Sandia.




j

Giant offshore wind farm takes further steps toward construction in New Jersey

Last week, the New Jersey Board of Public Utilities announced it selected Ocean Wind, an offshore wind energy project proposed by Ørsted with support from PSEG, to develop an 1,100 MW offshore wind farm. Ocean Wind will be located 15 miles off the coast of Atlantic City. Construction is expected to commence in the early 2020s, with the wind farm operational in 2024.




j

NV Energy's new 540-MWh storage and 475-MW solar project comes at a very low price

8minute Solar Energy, NV Energy and the Moapa Band of Paiutes announced that NV Energy selected 8minute to develop the largest solar plus storage project ever built in Nevada and one of the largest in the world.




j

Massachusetts approves contracts for hydroelectricity through NECEC project

The Massachusetts Department of Public Utilities has issued an order approving long-term contracts for 9,554,940 MWh annually of hydropower between H.Q. Energy Services (U.S.) Inc. and the Commonwealth’s electric distribution companies through the New England Clean Energy Connect 100% Hydro project (NECEC Hydro).




j

Dominion Energy begins construction on Coastal Virginia Offshore Wind project

Dominion Energy has begun construction on the Coastal Virginia Offshore Wind (CVOW) project, which will feature two 6-MW wind turbines and power about 3,000 homes.




j

Clean Power Alliance signs PPA for 12-MW Isabella small hydro project in California

The Clean Power Alliance (CPA) has signed three long-term power purchase agreements, including two new solar projects and one existing small hydro project.

 




j

AEP units looking to invest $2B in 1,500 MW of Oklahoma wind projects

The projects include a 999-MW wind facility being built north of Weatherford, a 287-MW wind facility being built southwest of Enid, and a 199-MW facility being built south of Alva. They are being developed by Invenergy.




j

Turkeler and RT Enerji choose supplier for five onshore wind farms in Turkey

Turkeler and RT Enerji have chosen GE Renewable Energy to supply equipment for five onshore wind farms being built in Turkey.




j

Lincoln Clean Energy: Texas' Lockett Wind project commercially operational

The Lockett Wind farm in Wilbarger has the potential to generate more than 700,000 MWh of renewable energy per year, enough to power the equivalent of 70,000 homes. 




j

NY governor announces $1.1 billion project to extend life of Niagara Power Project

Governor Andrew M. Cuomo has announced that the New York Power Authority is launching a 15-year modernization and digitization program to significantly extend the operating life of the Niagara Power Project.





j

100 MW of solar and 10 MW of battery storage coming to San José CCA in 2022

This week, San José’s Community Choice Aggregator (CCA) which is called San José Clean Energy (SJCE) and EDP Renewables SA (EDPR), through its fully owned subsidiary EDP Renewables North America LLC (EDPR NA), signed a 20-year power purchase agreement (PPA) for 100 MW of new solar energy capacity and 10 MW of battery storage at the Sonrisa Solar Park in Fresno County, California. The project is anticipated to be operational in 2022.




j

First major US offshore wind farm delayed by government

The Trump administration cast the fate of the nation’s first major offshore wind farm into doubt by extending an environmental review for the $2.8 billion Vineyard Wind project off Massachusetts.




j

The IEA’s hydrogen report doesn’t miss the point. It just buries It.

The International Energy Agency (IEA) recently released a major new report on hydrogen, underscoring the remarkable political and business momentum surrounding the fossil fuel alternative, and touting its potential as a vital component of global efforts to build a “clean, secure, and affordable energy future.” The report takes a bold and prescient stance, and has rightfully inspired a torrent of press coverage about the future of hydrogen and its role in the renewable energy mix.




j

Lekela reaches financial close for its West Bakr Wind project

Lekela announced that it has reached financial close on its first wind project in Egypt, West Bakr Wind. Construction will begin shortly, delivering 250 MW of clean, reliable power at a highly competitive price.




j

Nine solar projects go live in Georgia

Duke Energy Renewables, a subsidiary of Duke Energy, announced that nine solar projects developed with SolAmerica Energy totaling 14.1 megawatts (MW) have begun commercial operations across central Georgia under Georgia Power’s Renewable Energy Development Initiative. These projects bring Duke Energy Renewables, operating through its REC Solar business unit, to 27.4 MW of solar projects in Georgia.




j

DOE: U.S. onshore wind projects achieving record capacity, employment

The U.S. land-based wind industry installed 7,588 MW of capacity last year, bringing the overall utility-scale total to more than 96 GW. 




j

World’s largest hospital solar PV project online now in Aman, Jordan

This week Aman, Jordan-based Philadelphia Solar announced that the 8.2-MW solar PV project that it installed at the Abdali Medical Center in Jordan has entered commercial operation.




j

FERC issues license for 5-MW Grant Lake Hydroelectric Project in Alaska

The Federal Energy Regulatory Commission in the U.S. has issued an original operating license to Kenai Hydro LLC for its proposed 5-MW Grant Lake Hydroelectric Project in Kenai Peninsula Borough, Alaska.




j

Fifth GE wind turbine collapse leaves worker injured

A utility worker at the Delta 6 wind park in Brazil has been injured following yet another collapse of a General Electric (GE) turbine, bringing the total number of turbines to have failed in the America’s to five in 2019.

 




j

Australia in planning for multiple massive battery projects

France’s Neoen SA has outlined plans to build a giant renewables complex in South Australia, including battery storage with up to nine times more capacity than the Tesla Inc. design at its nearby Hornsdale plant, which is billed as the world’s largest lithium-ion battery.




j

Holtec, Eos create battery manufacturing JV

Eos Energy Storage and energy equipment firm Holtec International are creating a joint venture to produce Eos’ next generation of large-scale zinc batteries.




j

Japanese businesses test blockchain to trade renewable energy

This week independent power producer Marubeni and LO3 Energy said they have started a pilot project in Japan where LO3 will administer an energy marketplace using blockchain to connect a number of Marubeni’s power production facilities, including renewables, with offices and factories around Japan in a virtual marketplace. The project will simulate energy transactions to test the viability of the concept with the ultimate goal of creating a full-scale commercially operational network in the future.




j

Georgia will be home to largest solar PV project in the US to use bifacial modules and tracking

This week LONGi announced that it would be supplying modules to what it says is the largest “bifacial+tracker” power generation project in the United States. The 224-MW project will be built in Mitchell County, Georgia and is expected to be complete this year.





j

Pennsylvania joins electric vehicle race with new ‘roadmap’ for transition

Pennsylvania is promoting a new roadmap to electrify transportation by designing policies and setting targets to get more electric vehicles on the roads.