up

Volume 47, Issue 38 (Supp-2)




up

El Kupferstichkabinett presenta «El otro impresionismo”

El Kupferstichkabinett presenta «El otro impresionismo” Del 25 de septiembre de 2024 al 12 de...




up

Kupferstichkabinett presents “The Other Impressionism”

Kupferstichkabinett presents “The Other Impressionism” From 25 September 2024 to 12 January 2025, the Kupferstichkabinett...




up

File Transfer Solutions Targeted by CL0P Ransomware Group

The CL0P Ransomware Group, also known as TA505, has exploited zero-day vulnerabilities across a series of file transfer solutions since December 2020. File transfer solutions often contain sensitive information from a variety of organizations. This stolen information is used to extort victims to pay ransom demands. In 2023, CL0P claimed credit for the exploitation of vulnerabilities in both Fortra’s GoAnywhere Managed File Transfer (MFT) and Progress Software’s MOVEit Transfer solutions.

Research conducted as part of security audits has revealed additional vulnerabilities. This dashboard contains a list of vulnerabilities known to be exploited by the CL0P ransomware group as well as other vulnerabilities that could be leveraged by CL0P and other threat actors. Operations teams can use this data to identify the assets affected by the associated CVEs targeted by the CL0P ransomware group. The following Nessus plugins identify the affected vulnerabilities:

  •  90190: Progress MOVEit Transfer Installed (Windows)
  • 176735: Progress MOVEit Transfer Web Interface Detection
  • 176736: Progress MOVEit Transfer FTP Detection
  • 176567: Progress MOVEit Transfer
  • 177371: Progress MOVEit Transfer Critical Vulnerability (June 15, 2023)

The dashboard and its components are available in the Tenable.sc Feed, a comprehensive collection of dashboards, reports, assurance report cards and assets. The dashboard can be easily located in the Tenable Security Center Feed under the category Security Industry Trends.

The requirements for this dashboard are:

  • Tenable Security Center 6.1.1
  • Tenable Nessus 10.5.2

The Security Response Team (SRT) in Tenable Research digs into technical details and tests proof-of-concept attacks, when available, to ensure customers are fully informed of risks. The SRT also provides breakdowns for the latest vulnerabilities in the Tenable blog.

Tenable Research has posted the FAQ for MOVEit Transfer Vulnerabilities and CL0P Ransomware Gang blog post to provide the latest information about this threat.

Components

CL0P Ransomware Group MOVEit – This table displays assets that are vulnerable to recent targeted attacks by the CL0P Ransomware Group (aka TA505) related to Progress Software’s MOVEit Transfer solutions. The component specifically provides results for pluginIDs 90190, 176735, 176736, 176567, 177082, and 177371. These vulnerabilities are associated with a zero-day that is actively being exploited. The table displays the IP address, NetBIOS, DNS, and OS CPE of any identified vulnerable assets, and the Vulnerabilities severity bar.

CL0P Ransomware Group Fortra GoAnywhere MFT – This table displays assets that may be vulnerable to recent targeted attacks by the CL0P Ransomware Group (aka TA505) related to Fortra GoAnywhere Managed File Transfer (MFT). The component specifically provides results for pluginIDs 171845, 171558, 171771, and 113896. These vulnerabilities are associated with a zero-day that is actively being exploited. The table displays the IP address, NetBIOS, DNS, OS CPE of any identified vulnerable assets, and the Vulnerabilities severity bar. 

CL0P Ransomware Group Accellion File Transfer – This table displays assets that may be vulnerable to recent targeted attacks by the CL0P Ransomware Group (aka TA505) for CGI abuses related to Accellion Secure File Transfer. The component specifically provides results for pluginIDs 85007, 146927, and 154933. These vulnerabilities are associated with a zero-day that is actively being exploited by the CL0P Ransomware Group, also known as TA505. The table displays the IP address, NetBIOS, DNS, and OS CPE of any identified vulnerable assets, and the Vulnerabilities severity bars.

CL0P Ransomware Group Patched Assets – This table displays vulnerabilities that have been remediated related to recent targeted attacks by the CL0P Ransomware Group (aka TA505). The remediated vulnerabilities displayed are specifically related to the vulnerabilities related to Progress Software’s MOVEit Transfer solutions, Fortra GoAnywhere Managed File Transfer, and Accellion Secure File Transfer. These vulnerabilities are associated with a zero-day that is actively being exploited. The table displays the PluginID, Vulnerability Name, Plugin Family, Severity, and Total of remediated vulnerabilities.





up

Global Food Policy Report 2024: Improving governance to create supportive environments for diet and nutrition policies

Global Food Policy Report 2024: Improving governance to create supportive environments for diet and nutrition policies

Key steps to strengthen institutions and relationships

The post Global Food Policy Report 2024: Improving governance to create supportive environments for diet and nutrition policies appeared first on IFPRI.




up

Eyewitness travel. Canary Islands, [2017] / main contributors, Piotr Paszkiewicz, Hanna Faryna-Paszkiewicz, Gabriele Rupp.

Provides background information on the Canary Islands; describes the major sights, and suggests hotels, restaurants, entertainment, and outdoor activities.




up

Residence Hall Pop-up Advising (November 13, 2024 5:00pm)

Event Begins: Wednesday, November 13, 2024 5:00pm
Location: East Quadrangle
Organized By: Newnan LSA Academic Advising Center


Registration starts soon, and LSA Newnan advisors are coming to you! We'll be in residence halls discussing course planning for the winter term and answering any questions you may have.

Join us from 5-8 on select nights. We're looking forward to seeing you!




up

Maize & Blue Cupboard Volunteering (November 13, 2024 12:45pm)

Event Begins: Wednesday, November 13, 2024 12:45pm
Location: Maize and Blue Cupboard inside Betsy Barbour
Organized By: Sessions @ Michigan


Come help us during normal operating hours; as well as, unload our weekly Food Gatherers deliveries and stock our shelves! If you are outside the U-M community, please reach out to maize.blue.cupboard@umich.edu to sign up.




up

You Don't Belong Here: The Stories Our Systems Tell (and Why We have to Disrupt Them) (November 13, 2024 12:00pm)

Event Begins: Wednesday, November 13, 2024 12:00pm
Location: Rackham 4th Floor Assembly Hall
Organized By: Sessions @ Michigan


You Don't Belong Here: The Stories Our Systems Tell (and Why We Have to Disrupt Them)
There is a widespread story that institutions of higher education value diversity and will actively foster belonging for all in the community. In actuality, though, many members of the higher education community continue to face marginalization and othering within their professional and educational spaces. This session centers around an embodied case study depicting one woman’s reflections on her experiences of higher education that sent a persistent, systemic message that she didn’t belong. Through session activities, participants will consider how these messages manifest and why they continue to occur despite the extensive labor of individuals sincerely committed to advancing equity. Together, they brainstorm possibilities for changes that could increase equity at a systems level. This session is appropriate for faculty, graduate students, and academic leaders.
This session can be offered in a fully virtual, synchronous format (90 minutes) or a fully in-person synchronous format (120 minutes).
**The video performance portion of this session contains strong language. It includes explicit descriptions of racist and classist behaviors and the impact of systemic inequities on individuals and communities.




up

Winter Solstice Isn’t Complete Without a Bowl of Tang Yuan Soup

When you can’t celebrate Dong Zhi with family, a well-prepared bowl of soup can keep traditions alive—and even make new ones.




up

Supporting and shaping the global nutrition agenda with evidence: A three-decade journey of research and partnerships for impact

Supporting and shaping the global nutrition agenda with evidence: A three-decade journey of research and partnerships for impact

This year’s Forman Lecture will be delivered by Dr. Marie Ruel, Senior Research Fellow in the Nutrition, Diets, and Health Unit at IFPRI. She served as the Director of IFPRI’s Poverty, Health, and Nutrition Division from 2004 to 2023, after serving as Senior Research Fellow and Research Fellow in that division beginning in 1996. Dr. […]

The post Supporting and shaping the global nutrition agenda with evidence: A three-decade journey of research and partnerships for impact appeared first on IFPRI.




up

Learning Support for a Multi-Country Climate Resilience Programme for Food Security

Learning Support for a Multi-Country Climate Resilience Programme for Food Security

The Learning Support for a Sub-Saharan Africa Multi-Country Climate Resilience Program for Food Security, launched in 2023, aims to enhance food security and climate resilience across 14 African countries. This collaboration among CGIAR, the World Food Programme, and the Norwegian Agency for Development Cooperation (Norad) has three pillars: scaling disaster risk financing, transforming food systems […]

The post Learning Support for a Multi-Country Climate Resilience Programme for Food Security appeared first on IFPRI.




up

Trade can support climate change mitigation and adaptation in Africa’s agricultural sector, new data shows

Trade can support climate change mitigation and adaptation in Africa’s agricultural sector, new data shows

New report analyzes trade performance amid pressure points from climate change, water use, and carbon emissions, with recommendations for sustainable practices.

The post Trade can support climate change mitigation and adaptation in Africa’s agricultural sector, new data shows appeared first on IFPRI.




up

At high level dialogue, Stakeholders Rally Support for Women’s Empowerment in Agriculture (National Update/Punch)

At high level dialogue, Stakeholders Rally Support for Women’s Empowerment in Agriculture (National Update/Punch)

This article published by National Update (Nigeria) wrote about a recent high-level dialogue on the CGIAR HER+ initiative in Abuja held on October 9, 2024, that aimed to address barriers women face in Nigeria’s agrifood sector.

The post At high level dialogue, Stakeholders Rally Support for Women’s Empowerment in Agriculture (National Update/Punch) appeared first on IFPRI.












up

Updated Dates & Impacts with Extended Parking Lane Closures & Traffic Shifts at W. Foster Avenue between N. Broadway and N. Winthrop Avenue

Updated Dates & Impacts with Extended Parking Lane Closures & Traffic Shifts at W. Foster Avenue between N. Broadway and N. Winthrop Avenue for Street Reconstruction & Shoring Tower Construction & Staging.




up

Updated Dates, Extended Partial Alley Closure at the alley east of 4801thru 4838 N. Broadway

Updated Dates, Extended Partial Alley Closure at the alley east of 4801 – 4838 N. Broadway for station foundation construction.




up

Updated Dates, Extended Street Closures, W. Ardmore Avenue between N. Broadway and N. Winthrop Avenue

Updated Dates, Extended Street Closures, W. Ardmore Avenue between N. Broadway and N. Winthrop Avenue for street, sidewalk restoration and screen wall installation.




up

New U-Pass Plus with Metra popular with UIC students; Thousands sign up for joint Metra/CTA fare product

More than 4,100 University of Illinois Chicago students have signed up to receive the new U-Pass + Metra, a pass that gives them unlimited rides on Metra and the CTA for a reduced fare price under a one-year pilot program.




up

Update Dates and Impacts with Parking Lane and Partial Sidewalk Closure at 5600 thru 5605 N. Broadway

Update Dates and Impacts with Parking Lane and Partial Sidewalk Closure at 5600 – 5605 N. Broadway




up

Updated Dates Daily Alley Closures for the alley west of 4700 thru 4748 N. Winthrop Avenue (W. Leland Avenue to W. Lawrence Avenue)

Updated Dates Daily Alley Closures for the alley west of 4700 thru 4748 N. Winthrop Avenue (W. Leland Avenue to W. Lawrence Avenue) for wall cap installation.




up

Updated Dates for Extended Partial Alley Closure for the alley west of 4700 thru 4748 N. Winthrop Avenue (W. Leland Avenue to W. Lawrence Avenue)

Updated Dates for Extended Partial Alley Closure for the alley west of 4700 thru 4748 N. Winthrop Avenue (W. Leland Avenue to W. Lawrence Avenue)




up

CTA Joins Government Agencies and Nonprofit and Private Groups to Host A Second Citywide Career Fair

Following the success of the first Citywide Career Fair last Spring, where over 60 employers and more than 400 job seekers attended, the Chicago Transit Authority (CTA) is joining local and state government agencies, nonprofits and private sector leaders to host a second joint hiring event next week.




up

Updated Dates Parking Lane and Partial Sidewalk Closure at 5600 thru 5605 N. Broadway

Updated Dates Parking Lane and Partial Sidewalk Closure at 5600 – 5605 N. Broadway for Decorative Sidewalk Paver Installation.




up

Updated Dates for Extended Alley Closure for The alley behind 5300 thru 5358 N. Winthrop Avenue (W. Berwyn Avenue to W. Balmoral Avenue)

Updated Dates for Extended Alley Closure for The alley behind 5300 thru 5358 N. Winthrop Avenue (W. Berwyn Avenue to W. Balmoral Avenue) for alley reconstruction.




up

Updated Dates and Extended Street Closure at W. Balmoral Avenue between N. Broadway and N. Winthrop Avenue

Updated Dates and Extended Street Closure at W. Balmoral Avenue between N. Broadway and N. Winthrop Avenue for street and sidewalk restoration.




up

Updated Dates Parking Lane and Sidewalk Closure for - W. Newport Avenue between N. Clark Street and 927 W. Newport Avenue - N. Clark Street between W. Roscoe Street and W. Newport Avenue

Updated Dates Parking Lane and Sidewalk Closure for - W. Newport Avenue between N. Clark Street and 927 W. Newport Avenue - N. Clark Street between W. Roscoe Street and W. Newport Avenue




up

Updated dates: Alley closure & construction work W Balmoral to W Berwyn

The alley behind 5300 – 5358 N. Winthrop Avenue will be closed through Oct. 26 for reconstruction as part of the Red and Purple Modernization Project.




up

Updated dates and new work activity W Ardmore Ave

There will be intermittent street closures on W Ardmore at the CTA tracks to allow crews to hoist construction materials to track level.




up

Updated Dates and Extended Street Closure for W. Balmoral Avenue between N. Broadway and N. Winthrop Avenue

Updated Dates and Extended Street Closure for W. Balmoral Avenue between N. Broadway and N. Winthrop Avenue for Street and Sidewalk Restoration.




up

Updated Dates Alley Entrance Relocation & Daily Short-term Street Closures Crane Staging & Material Deliver

Updated Dates Alley Entrance Relocation & Daily Short-term Street Closures Crane Staging & Material Deliver




up

Red and Purple Line Trains Share Track between Thorndale and Belmont (Updated) (Service Change)

(Sun, May 16 2021 12:01 AM to TBD) Red and Purple line trains share tracks btwn Thorndale and Belmont. Purple Line Express trains continue to make only express stops between Howard and Belmont.




up

Red and Purple Line Trains Share Track between Thorndale and Belmont (Updated) (Service Change)

(Sun, May 16 2021 12:01 AM to TBD) Red and Purple line trains share tracks btwn Thorndale and Belmont. Purple Line Express trains continue to make only express stops between Howard and Belmont.




up

We set up an offshore company in a tax haven (Classic)

The Pandora Papers released this week reveal how many world leaders allegedly hold wealth through the use of shell companies. We listen back to when we set up our very own Planet Money shell companies.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




up

A trunk full of truffles (Update)

Truffles are one of the most expensive and sought after ingredients in the world. Today, we look back at our NYC adventure with a truffle smuggler and how the market has changed since we last talked to him. | Subscribe to our weekly newsletter here.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




up

Planet Money's Supply Chain Holiday Extravaganza

Planet Money's Supply Chain Holiday Extravaganza Did the supply chain wreck your holiday shopping? Planet Money comes to the rescue. | Subscribe to our weekly newsletter here.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




up

Two indicators: supply chain solutions

Two stories about people trying to overcome supply chain challenges. We follow a ship that is forced to get creative to bypass clogged ports, and we visit a warehouse that is running out of space. | Subscribe to our weekly newsletter here.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




up

We Buy a Superhero 6: The Comic Book

After many, many delays, the Micro-Face comic book is here! And we answer the burning question: Why did it take so long to make a comic book? | Come see Planet Money Live in NYC on May 10th! One night only. Tickets on sale here. And buy our now-ready Micro-Face comic book.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




up

A 12-year-old girl takes on the video game industry (UPDATE)

When Maddie Messer was 12 years old, she noticed an unfair dynamic in the video games she loved: playing as a man was often free, but she had to pay to play as a woman. So ... she decided to take on the video game industry. | Subscribe to our weekly newsletter here.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy




up

We Buy a Superhero 7: Collectibles (Live Show!)

What transforms a regular object into a collectible? At our live show earlier this month, we went on a journey through collectibles history. And we had a goal: to turn our Micro-Face comic book into the most collectible item of all time. | Bid on our collectible Micro-Face comic book here!

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy





up

We Buy a Superhero 8: Micro-Face: The Musical

This episode, Micro-Face: The Musical. A full concert recording of a one-of-a-kind Planet Money superhero musical, taped during our recent live show at the Roulette Theater in Brooklyn, New York.

Here's more from our project We Buy A Superhero.

Subscribe to Planet Money+ in Apple Podcasts or at plus.npr.org/planetmoney.

Learn more about sponsor message choices: podcastchoices.com/adchoices

NPR Privacy Policy