Back to news

May 21, 2024 | International, Security

NextGen Healthcare Mirth Connect Under Attack - CISA Issues Urgent Warning

CISA has flagged a critical security flaw in NextGen Healthcare Mirth Connect, linked to remote code execution.

https://thehackernews.com/2024/05/nextgen-healthcare-mirth-connect-under.html

On the same subject

  • Citing TransDigm, DoD seeks new acquisition powers, and trade groups oppose

    May 19, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

    Citing TransDigm, DoD seeks new acquisition powers, and trade groups oppose

    By: Joe Gould WASHINGTON ― Four defense industry trade associations “strongly oppose" a handful of Pentagon-backed procurement reform proposals that they say would harm the defense industrial base, and they're asking Congress to reject them. Two of the proposals aim at controversial pricing practices used by TransDigm by requiring contractors to submit cost information for commercial items and by requiring contracting officers to conduct a commercial item determination for every procurement. Others would set a preference for performance-based contract payments and authorize the Defense Department to release or disclose detailed manufacturing or process data. The May 6 protest letter came from the Acquisition Reform Working Group — made up of the National Defense Industrial Association, American Council of Engineering Companies, the Computing Technology Industry Association and the Information Technology Industry Council — to the the House and Senate armed services committees. It comes as the panels were readying their drafts of the 2021 National Defense Authorization Act. The Pentagon has worked to monitor its network of suppliers from the economic shocks associated with the coronavirus pandemic and to protect suppliers by using emergency funding from Congress to speed payments and improve cash flow along the supply chain. The trade groups noted they represent “thousands of small, mid-sized, and large companies in addition to hundreds of thousands of employees that provide goods, services, and personnel to the Department of Defense,” and said the four proposals a “could have significant consequences for the defense industrial base.” Congress focused ire at TransDigm last year after the Defense Department's Inspector General found for $26.2 million in parts the military bought from TransDigm, it earned $16.1 million in excess profit. Transdigm was the only manufacturer of the majority of the parts, which let it set the market prices even for competitively awarded parts. Though DoD has argued its contractors need new latitude to make commercial item determinations and obtain cost or pricing information to prevent the excessive pricing TransDigm was accused of, the trade groups argue the TransDigm's actions weren't facilitated by an inappropriate reliance on improper commercial item determinations, or insufficient access to pricing data. “As illustrated by the TransDigm Group, Inc's pricing practices, generally once a conversion to a commercial product or commercial service is made, it is common for prices to increase and subsequent contracting officers find it difficult to obtain data necessary to determine price reasonableness and negotiate fair and reasonable prices on behalf of the taxpayer,” the department said in its proposal. Another proposal would require a contractor to submit uncertified cost information for commercial item proposals or contracts less than $2 million. The idea behind the reform is DoD wants to be able to get more insight into the costs of sole-source items and put itself in a more favorable position to negotiate with sole-source companies. Congressional hearings on TransDigm's excessive pricing showed Defense leaders need the authority to obtain the data “to the extent necessary to determine price reasonableness is paramount in ensuring that such excessive pricing practices are curtailed.” But the trade groups argue that levying the new regulations would “add a significant barrier to commercial item acquisition, reduce information sharing, further burden the system, and impede—rather than enable—the delivery of capabilities to the warfighter at the ‘speed of relevance'—all with little to no added protection for the government or the taxpayer." The trade associations also opposed DoD's legislation to set a preference for performance-based contract payments. The groups said a DoD proposal to “recouple” total performance-based payments to total cost incurred would reverse Congress's previous work to emphasize performance over cost and contradict a spate of defense acquisitions rules. DoD's argument is that it shouldn't be reimbursing a contractor more than its actual costs, or it “would result in negative levels of contractor investment,” and create a disincentive for contractors to deliver. Another disputed proposal would let DoD release detailed manufacturing or process data, or DPMD, pertaining to privately funded commercial or noncommercial items outside of the government to third parties seeking to compete against the original equipment manufacturer. It's the latest episode in a running game of tug-of-war between industry and DoD over intellectual property. While Congress has in recent years prodded DoD to set intellectual property strategies early in acquisition programs and negotiate for IP rights on a case-by-case basis, the trade groups argue the proposal would give DoD “an automatic default authority” and “eliminate the possibility of a negotiated solution.” https://www.defensenews.com/congress/2020/05/15/citing-transdigm-dod-seeks-new-acquisition-powers-and-trade-groups-oppose/

  • The Air Force will need terminals that work with more than GPS

    December 26, 2019 | International, Aerospace

    The Air Force will need terminals that work with more than GPS

    By: Nathan Strout Congress wants the Air Force to develop a prototype receiver capable of using navigation signals provided by other countries, which could increase the resilience of the military's position, navigation and timing equipment. The primary source of the military's PNT data is the Global Positioning System, a satellite system operated by the Air Force. But with adversaries developing GPS jamming technology and anti-satellite weapons that could potentially knock out one or more of those satellites, Congress wants a receiver capable of utilizing other global navigation satellite systems. The annual defense policy bill, which was passed by both chambers of the legislature this week, calls on the Air Force to develop a prototype receiver capable of utilizing multiple global navigation satellite systems in addition to GPS, such as the European Union's Galileo and Japan's QZSS satellites. The belief is that if the GPS signal is degraded or denied, war fighters could switch to one of those other systems to get the PNT data they need. According to Brian Weeden, director of program planning at the Secure World Foundation, the provision represents an evolution from the Department of Defense's stance on foreign GNSS signals from 15 years ago. “When Galileo was first announced, there was a big debate within the Pentagon about whether to cooperate with the Europeans or try and kill it,” Weeden wrote to C4ISRNET in a Dec. 18 email. “The big driver there was that the Europeans were going to park their protected signal on top of M-code and then sell their service as being unjammable by the Americans (assuming that the US couldn't jam the protected Galileo signal without also interfering with M-Code).” Efforts to kill Galileo ultimately died, Weeden noted, although the EU did move their protected GNSS signal off of M-Code, a more secure military version of the GPS signal that is in development. That concession and the subsequent development of GPS jamming capabilities by Russia and China has changed the thinking on Galileo and other GNSS signals. “It seems the Pentagon has decided that leveraging Galileo will make their PNT capabilities more robust as Russia or China would need to jam both of the separate military signals,” said Weeden. “There's some engineering and technical wizardry still to be worked out to create a good multi-GNSS receiver but it's doable.” Congress wants the Air Force to report on the benefits and risks of each potential GNSS signal, and it fences 90 percent of the funding for the Military GPS User Equipment Program until lawmakers receive that report. https://www.c4isrnet.com/battlefield-tech/space/2019/12/19/the-air-force-will-need-terminals-that-work-with-more-than-gps

  • Pentagon wants competition within $9B Joint Warfighting Cloud contract

    December 8, 2022 | International, C4ISR

    Pentagon wants competition within $9B Joint Warfighting Cloud contract

    The Pentagon on Dec. 7 picked Amazon, Google, Microsoft and Oracle for the highly anticipated cloud computing deal.

All news