433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 563-2652

Lawsuit contends Schedule Policy/Career exceeds presidential authority

An expanded lawsuit comes just days ahead of President Donald Trump’s anticipated finalization of federal employee transfers into Schedule Policy/Career.
http://news.poseidon-us.com/TRJ1zL

World’s smallest OLED pixel could transform smart glasses

Researchers have built the smallest OLED pixel ever made—just 300 nanometers across—without sacrificing brightness. By redesigning the pixel with a nano-sized optical antenna and a protective insulation layer, they prevented the short circuits that normally plague devices at this scale. The result is a stable, ultra-tiny light source that could allow full HD displays to fit on an area the size of a grain of sand.
http://news.poseidon-us.com/TRHxdS

Quantity Surveying in Construction: Process, Outcomes & Roles

Construction projects involve hundreds of cost decisions long before a building takes shape. Materials must be measured, budgets must be forecast and contracts must align with the real scope of work. Quantity surveying sits at the centre of those decisions,… Read More The post Quantity Surveying in Construction: Process, Outcomes & Roles appeared first on ProjectManager.
http://news.poseidon-us.com/TRHxQN

Noem, top DHS officials to be deposed in FEMA staffing cut lawsuit

The order comes after a DoJ lawyer contradicted a top FEMA official’s statement about whether DHS made the final call on staffing cuts.
http://news.poseidon-us.com/TRHxCz

Noem, top DHS officials to be deposed in FEMA staffing cut lawsuit

The order comes after a DoJ lawyer contradicted a top FEMA official’s statement about whether DHS made the final call on staffing cuts.
http://news.poseidon-us.com/TRHx27

New bill would protect domestic violence survivors during the federal retirement process

Currently, retired feds must get consent from their current or former spouse if updating their benefits, which can expose contact information to abusers.
http://news.poseidon-us.com/TRHsds

Cisco Secure Firewall Management Center Software SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, an attacker must have a valid account on the device with the role of Security Approver, Intrusion Admin, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to read the contents of databases on the affected device and also obtain limited read access to the underlying operating system.  Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sql-inject-2EnmTC8v This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. Security Impact Rating: Medium CVE: CVE-2024-20340
http://news.poseidon-us.com/TRHptn

Cisco Adaptive Security Appliance and Firepower Threat Defense Software Command Injection Vulnerability

A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.  This vulnerability exists because the contents of a backup file are improperly sanitized at restore time. An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system as root. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.  This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-cmd-inj-ZJV8Wysm For more information on the vulnerability that is described in this advisory, see Cisco Event Response: Attacks Against Cisco Firewall Platforms. Security Impact Rating: Medium CVE: CVE-2024-20358
http://news.poseidon-us.com/TRHprh