4 juin 2024 | International, Sécurité

Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts

Critical security flaw discovered in Progress Telerik Report Server (CVE-2024-4358, CVSS 9.8/10). Remote attackers could bypass authentication.

https://thehackernews.com/2024/06/telerik-report-server-flaw-could-let.html

Sur le même sujet

  • The military wants many systems to share one language

    11 février 2019 | International, C4ISR

    The military wants many systems to share one language

    By: Mark Pomerleau The Army, Navy and Air Force secretaries recently signed a memorandum that would establish common standards of information in future weapon systems, a move that will allow for greater coordination on a future battlefield that will require faster decision making. As the military is shifting its focus to so-called great powers and simultaneously each pursing its own version of multidomain operations — a concept of operating more seamlessly across the five domains of warfare — there is a recognition for the need for closer cooperation. According to an Air Force release Feb. 8, older weapon systems were not developed with common interface standards, which made interoperability more difficult. “This is vital to our success,” said Mark Esper, the secretary of the Army. “After reviewing the capabilities of common standards, we have collectively determined that continued implementation, and further development of modular open systems approaches are necessary to keep our competitive advantage.” In recent years, the services have developed, demonstrated and validated common data standards through a cooperative partnership with industry and academia to allow for a modular open systems approach, the release said. When the services follow the standards, contractors can build interoperable systems. This approach can lead significantly reduce development timelines and shrink costs by as much as 70 percent, the release said. “The ability for our systems and forces to exchange information and communicate effectively gives our war fighters the best capabilities to deliver the fight tonight,” Richard Spencer, the secretary of the Navy, said. “This reform will make us a highly integrated and more lethal fighting force.” With new approaches, such as multidomain operations, Pentagon leaders say it is critical for systems and forces to communicate across domains as well as cyber and land systems. "Victory in future conflict will in part be determined by our ability to rapidly share information across domains and platforms," Heather Wilson, secretary of the Air Force, said. "Sharing information from machine to machine requires common standards." Some in industry are helping the military answer some tough problems. “How do you take all the platforms that are out there and link them together and then be able to create decisions that happen a lot faster or get to decisions that you couldn't have gotten to if you were looking at each of the domains independently,” Rob Smith, vice president of C4ISR & UAS, Rotary and Mission Systems at Lockheed Martin, told reporters in July. While linking systems together may sound easy, Smith said differences in planning cycles, technologies and classifications is challenging. Going forward, the Air Force release said the joint memorandum directs service acquisition executives to publish specific implementation guidance for acquisition programs, continue to identify gaps and develop new standards when needed. Additionally, capability requirements officers must write modular open systems into future requirements documents as to be able to communicate across domains. https://www.c4isrnet.com/c2-comms/2019/02/08/the-military-wants-many-systems-to-share-one-language

  • Space Development Agency builds vendor pool for future demo missions

    24 octobre 2024 | International, Aérospatial

    Space Development Agency builds vendor pool for future demo missions

    Through the effort, dubbed HALO, the agency will run rapid on-orbit demonstrations aimed at reducing risk for future operational missions.

  • Army to conduct thorough review of aviation fleet in FY23

    15 octobre 2020 | International, Aérospatial

    Army to conduct thorough review of aviation fleet in FY23

    Jen Judson WASHINGTON — As the Army looks to bring on two future helicopters by 2030, the service is planning to review its entire aviation fleet in fiscal 2023, Lt. Gen. James Pasquarette, the Army G-8, told Defense News in an Oct. 8 interview. Over the past several years, the Army has said it is at “an inflection point” when it comes to prioritizing modernization in order to ensure soldiers can fight in a multidomain environment against near-peer adversaries. Part of that is ensuring the Army is balanced properly when it comes to making sure the current fleet is ready while funding the ambitious development of two new aircraft along with a number of other enablers like a digital backbone, air-launched effects and a new engine, to name a few. In FY20, the Army took controversial steps to shift funding from the current fleet to the future one when it decided it would not buy Block II CH-47F Chinook cargo helicopters for the active force, opting to procure the variant just for special operations. Congress has pushed back on that decision in both its FY20 and FY21 defense bills, injecting funding into the program to keep the pump primed to build Block II Chinooks for the active component against the Army's wishes. So far the Army isn't planning on backing down on its decision to scale down and only buy the Block II variant for special operations. “The Army's position has not changed. I mean, our position is we don't have to make a decision,” Pasquarette said. “It's based on the age of the fleet and other factors,” Pasquarette said. “Our concern is that if Congress decides that we need to move down the Block II path here ... that starts to push out dollars against our modernization priorities that we're very concerned about.” The Army “must develop” both the Future Armed Reconnaissance Aircraft (FARA) and the Future Long-Range Assault Aircraft (FLRAA), he stressed. Army Secretary Ryan McCarthy also signaled during an Oct. 8 interview with Defense News that tough decisions on the aviation fleet would have to be made as the FLRAA and FARA aircraft begin to fly. The prototype aircraft for FARA are expected to start flying in the fourth quarter of FY22 and the engineering and manufacturing development phase is expected to begin in FY24. FLRAA prototypes will be delivered in roughly the summer of 2026. The last time the Army restructured its fleet was in 2013 to deal with impending budget cuts and reductions that would have been made through sequestration. The effort was a way to take control of what was cut rather than let every program across the board take salami-slice chops. As a result, the service decided to retire its OH-58D Kiowa Warrior helicopters and use AH-64E Apache attack helicopters paired with Shadow unmanned aircraft systems to fill the armed scout role until future aircraft could come online. https://www.defensenews.com/digital-show-dailies/ausa/2020/10/14/army-to-conduct-thorough-review-of-aviation-fleet-in-fy23/

Toutes les nouvelles