<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>New England Safety Partners, LLC</title>
	<atom:link href="https://www.newenglandsp.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.newenglandsp.com</link>
	<description>New England Safety Partners, LLC</description>
	<lastBuildDate>Tue, 06 Jan 2026 16:41:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>SOC 2 Success Story: From Pressure to Proof</title>
		<link>https://www.newenglandsp.com/2026/01/soc-2-success-story-from-pressure-to-proof/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=soc-2-success-story-from-pressure-to-proof</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 06 Jan 2026 16:41:11 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=19580</guid>

					<description><![CDATA[When a fast-growing call center technology company faced increasing pressure from enterprise and Fortune 500 customers, SOC 2 compliance became a business requirement rather than a nice-to-have. By partnering with New England Safety Partners, they achieved:&#x2714;&#xfe0f; SOC 2 Type I (Security &#38; Availability)&#x2714;&#xfe0f; Multiple successful SOC 2 Type II reports in subsequent years&#x2714;&#xfe0f; Stronger security [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>When a fast-growing call center technology company faced increasing pressure from enterprise and Fortune 500 customers, SOC 2 compliance became a business requirement rather than a nice-to-have.</p>



<p>By partnering with <strong>New England Safety Partners</strong>, they achieved:<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> SOC 2 Type I (Security &amp; Availability)<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Multiple successful SOC 2 Type II reports in subsequent years<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Stronger security operations, training, and documentation<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Increased confidence from customers, auditors, and acquirers</p>



<p>The result? A repeatable, audit-ready security program and a smoother path through due diligence during a successful acquisition.</p>



<p>SOC 2 done right doesn’t slow growth. It enables it.</p>



<p>#SOC2 #Compliance #CyberSecurity #StartupGrowth #EnterpriseSales #Trust</p>



<p><a href="https://www.newenglandsp.com/category/compliance/" data-type="category" data-id="20">Download the Case Study</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SOC 2 Compliance: More Than a Checkbox</title>
		<link>https://www.newenglandsp.com/2026/01/soc-2-compliance-more-than-a-checkbox/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=soc-2-compliance-more-than-a-checkbox</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 06 Jan 2026 16:21:41 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=19578</guid>

					<description><![CDATA[SOC 2 isn’t just about passing an audit—it’s about earning trust. For growing companies, achieving SOC 2 compliance means proving to customers, partners, and investors that security, availability, and operational discipline are built into how you operate every day, not bolted on at the last minute. Done right, SOC 2 can:&#x2705; Shorten security questionnaires&#x2705; Accelerate [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>SOC 2 isn’t just about passing an audit—it’s about earning trust.</p>



<p>For growing companies, achieving SOC 2 compliance means proving to customers, partners, and investors that security, availability, and operational discipline are built into how you operate every day, not bolted on at the last minute.</p>



<p>Done right, SOC 2 can:<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Shorten security questionnaires<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Accelerate enterprise sales cycles<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Strengthen internal processes and accountability<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Demonstrate long-term commitment to protecting customer data</p>



<p>Whether you’re preparing for your first Type I or maintaining a mature Type II program, the key is treating compliance as an ongoing business process, not a one-time event.</p>



<p>Security builds trust. Trust drives growth.</p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Alyce receives 2023 SOC2 attestation</title>
		<link>https://www.newenglandsp.com/2023/08/alyce-receives-2023-soc2-attestation/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=alyce-receives-2023-soc2-attestation</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Wed, 23 Aug 2023 17:38:47 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=17959</guid>

					<description><![CDATA[For Immediate Release 23 August 2023 Alyce achieves critical information security milestone Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation, today announced that it has helped its client, Alyce, Inc., complete the Service Organization Control (SOC) 2 Type [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p><strong>23 August 2023</strong></p>



<p><em>Alyce achieves critical information security milestone</em></p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation, today announced that it has helped its client, Alyce, Inc., complete the Service Organization Control (SOC) 2 Type 2 audit for 2023, earning an unqualified opinion.</p>



<p>Alyce is the only Smart Gifting platform, enabling sales, marketing, and customer success teams to create memorable moments and greater impact through a relational, recipient-first approach to gifting. With an AI-powered platform and a global network of partners, Alyce bridges the physical and digital world of marketing and revenue generation so that enterprises can better engage prospects, customers, and employees while delivering measurable results. Alyce is a venture-backed, privately held company headquartered in Boston, MA.</p>



<p>The audit affirms that Alyce’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security. These audits are critical to demonstrating the ongoing operation of critical security controls crucial for Alyce’s customers, especially those in highly regulated industries.</p>



<p>“We were grateful for NESP&#8217;s help navigating the SOC2 audit and providing support as our vCISO. Their help freed our team to concentrate on running the business and keeping it secure while they worked with our external audit partner to get through the evidence required to satisfy the control testing,” Says Brett Zucker, CEO at Alyce. “We&#8217;re looking forward to continuing our success!&#8221;</p>



<p>Founded in 2013 and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong><em>For more information, contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com</a><br><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>



<p>Alyce, Inc<br>Peter Lorenco<br><a href="mailto:press@alyce.com">press@alyce.com</a><br><a href="https://www.alyce.com/">https://www.alyce.com/</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>H2O.ai receives SOC2 Type 2 report</title>
		<link>https://www.newenglandsp.com/2023/07/h2o-ai-receives-soc2-type-2-report/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=h2o-ai-receives-soc2-type-2-report</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Thu, 27 Jul 2023 13:50:31 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=17952</guid>

					<description><![CDATA[For Immediate Release 27 July 2023 H2O.ai receives a SOC 2 Type 2 Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped H2O.ai., successfully complete the Service Organization Control (SOC) 2 Type 2 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p><strong>27 July 2023</strong></p>



<p><em>H2O.ai receives a SOC 2 Type </em>2</p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped H2O.ai., successfully complete the Service Organization Control (SOC) 2 Type 2 audit for 2023. </p>



<p>H2O.ai is a privately held technology company founded in 2011 and headquartered in Mountain View, California. H2O.ai is an open-source machine learning platform that makes it easy to build smart applications. They provide a fully managed artificial intelligence cloud infrastructure solution. Customers use the H2O.ai Cloud – Fully Managed platform to rapidly solve complex business problems and accelerate the discovery of new ideas.</p>



<p>The audit affirms that H20.ai information security practices, policies, procedures, and operations meet the SOC 2 standards for security. These audits are key to demonstrating the design and ongoing operation of critical security controls that are crucial for H2O.ai&#8217;s customers. &#8220;H2O.ai&#8217;s achievement is a significant step forward in their ongoing commitment to data security. Their dedication to protecting customer data and privacy is praiseworthy. As a consultant, it&#8217;s encouraging to see a company like H2O.ai leading the way in implementing robust security measures.&#8221; &#8211; <em>Edward Gardner, Principal, New England Safety Partners.</em></p>



<p>&#8220;We&#8217;re incredibly grateful for the expertise and support provided by New England Safety Partners, LLC. Their team played an instrumental role in our journey toward this security milestone. Without their guidance, the process would have undoubtedly taken months longer. Their dedication and proficiency in data security are truly top-notch, and we&#8217;re fortunate to have partnered with them. This achievement is as much theirs as it is ours.&#8221; &#8211; <em>David Epperson, CISO, H2O.ai</em></p>



<p><strong>About New England Safety Partners</strong></p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong><em>For more information contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com<br></a><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>H2O.ai receives SOC2 attestation</title>
		<link>https://www.newenglandsp.com/2023/03/h2o-ai-receives-soc2-attestation/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=h2o-ai-receives-soc2-attestation</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 28 Mar 2023 12:34:11 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=17916</guid>

					<description><![CDATA[For Immediate Release 28 March 2023 H2O.ai receives a SOC 2 Type 1 Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped H2O.ai., successfully complete the Service Organization Control (SOC) 2 Type 1 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p><strong>28 March 2023</strong></p>



<p><em>H2O.ai receives a SOC 2 Type 1</em></p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped H2O.ai., successfully complete the Service Organization Control (SOC) 2 Type 1 audit for 2023.</p>



<p>H2O.ai is a privately held technology company founded in 2011 and headquartered in Mountain View, California. H2O.ai is an open-source machine learning platform that makes it easy to build smart applications. They provide a fully managed artificial intelligence cloud infrastructure solution. Customers use the H2O.ai Cloud – Fully Managed platform to rapidly solve complex business problems and accelerate the discovery of new ideas.</p>



<p>The audit affirms that H20.ai information security practices, policies, procedures, and operations meet the SOC 2 standards for security. These audits are key to demonstrating the design and operation of critical security controls that are crucial for H2O.ai&#8217;s customers.</p>



<p>&#8220;The NESP team is the number one reason for the success of our compliance efforts.&nbsp; They are&nbsp;professional, knowledgeable, helpful, and exceptional team players.&nbsp; H2O.ai plans to continue to partner with NESP through our compliance journey of HIPAA, GDPR,&nbsp; ISO, and FedRamp.&#8221; &#8211; <em>David Epperson, CISO, H2O.ai</em></p>



<p><strong>About New England Safety Partners</strong></p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong><em>For more information contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com<br></a><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sense receives SOC2 attestation</title>
		<link>https://www.newenglandsp.com/2023/02/sense-receives-soc2-attestation/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=sense-receives-soc2-attestation</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Fri, 24 Feb 2023 14:08:59 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=17882</guid>

					<description><![CDATA[For Immediate Release 24 February 2023 Sense receives a SOC 2 Type 2 Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped Sense Labs, Inc. (Sense) successfully complete the Service Organization Control (SOC) [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p>24 February 2023</p>



<p><em>Sense receives a SOC 2 Type 2</em></p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped Sense Labs, Inc. (Sense) successfully complete the Service Organization Control (SOC) 2 Type 2 audit for 2023.</p>



<p>Sense Labs, Inc.’s (Sense) mission is to make all homes intelligent through its “fitness tracker for the home”, helping consumers save money and live more safely with more energy-efficient households. Founded in 2013 by pioneers in speech recognition, Sense uses machine learning technology to provide real-time insights on device behavior, even for those devices that are not “smart”. Consumers and Partners (Customers) rely on Sense for a wide range of uses including monitoring their home appliances, determining whether they left appliances running, and identifying major energy drains in their homes so they can substantially reduce their energy costs. Sense is headquartered in Cambridge, Massachusetts.</p>



<p>The audit affirms that Sense’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security, availability, and confidentiality. These audits are key to demonstrating the design and operation of critical controls crucial for Sense&#8217;s customers.</p>



<p>“NESP was a tremendous help in our SOC 2 journey. They are deeply knowledgeable in the security domain and were able to provide extensive guidance and advice. They were incredibly responsive, proactive in pushing us forward in critical areas, and really acted as an extension of our team. They were hands-on in helping us craft policies and set up systems that strike the appropriate balance of rigor and overhead. On top of it all, they&#8217;re a joy to work with: pleasant, good-humored, and professional. I would wholeheartedly recommend them to anyone embarking on a compliance process.” &#8211; <em>Ryan Houlette, Vice President Engineering, Sense.</em></p>



<p><strong>About New England Safety Partners</strong></p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong><em>For more information contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com<br></a><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>



<p></p>



<p><br><br></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Silverbills receives SOC2 Type 2 attestation</title>
		<link>https://www.newenglandsp.com/2023/02/silverbills-receives-soc2-type-2-attestation/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=silverbills-receives-soc2-type-2-attestation</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Thu, 23 Feb 2023 18:29:35 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=17884</guid>

					<description><![CDATA[For Immediate Release 23 February 2023 Silverbills receives a SOC 2 Type 2 Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped Silverbills successfully complete the Service Organization Control (SOC) 2 Type 2 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p><strong>23  February 2023</strong></p>



<p><em>Silverbills receives a SOC 2 Type </em>2</p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security, and business process analysis and implementation today announced that it has helped Silverbills successfully complete the Service Organization Control (SOC) 2 Type 2 audit for 2022.</p>



<p>The Silverbills platform is an online platform that helps its clients age with dignity by managing bills securely. SilverBills is revolutionizing household bills using proprietary software and personal support. Instead of being inundated by bills, having to remember deadlines and writing checks, clients are enjoying life without these stressors.</p>



<p>The audit affirms that Silverbill’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security, availability, confidentially, and HIPAA. These audits are vital to demonstrating the design and operation of critical controls crucial for Silverbill’s customers in healthcare. Additionally, a Type 2 attestation demonstrates that these controls are operating effectively, giving additional assurance that security is paramount to management.</p>



<p>“The NESP team&#8217;s expertise and guidance were invaluable in helping us navigate the complex requirements and ensure that we were compliant with all the necessary regulations. From the initial assessment to the implementation of necessary controls and policies, the team provided exceptional support every step of the way. Their thorough approach and attention to detail gave us the confidence we needed to pass the audits with flying colors.” &#8211; <em>Vlad Mangeym, CTO, Silverbills.</em></p>



<p><strong>About New England Safety Partners</strong></p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong><em>For more information contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com<br></a><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Device to Turn Traffic Lights Green</title>
		<link>https://www.newenglandsp.com/2023/02/a-device-to-turn-traffic-lights-green/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=a-device-to-turn-traffic-lights-green</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Wed, 22 Feb 2023 12:30:20 +0000</pubDate>
				<category><![CDATA[Welcome]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=66958</guid>

					<description><![CDATA[<p>Here’s a <a href="https://www.thedrive.com/news/hacker-uncovers-how-to-turn-traffic-lights-green-with-flipper-zero">story</a> about a hacker who reprogrammed a device called “Flipper Zero” to mimic Opticom transmitters—to turn traffic lights in his path green.</p>
<blockquote><p>As mentioned earlier, the Flipper Zero has a built-in sub-GHz radio that lets the device receive data (or transmit it, with the right firmware in approved regions) on the <a href="https://www.thedrive.com/tech/i-tried-the-honda-keyfob-hack-on-my-own-car-it-totally-worked">same wireless frequencies as keyfobs and other devices</a>. Most traffic preemption devices intended for emergency traffic redirection don’t actually transmit signals over RF. Instead, they use optical technology to beam infrared light from vehicles to static receivers mounted on traffic light poles...</p></blockquote>]]></description>
										<content:encoded><![CDATA[<p>Here&#8217;s a <a href="https://www.thedrive.com/news/hacker-uncovers-how-to-turn-traffic-lights-green-with-flipper-zero">story</a> about a hacker who reprogrammed a device called &#8220;Flipper Zero&#8221; to mimic Opticom transmitters&#8212;to turn traffic lights in his path green.</p>
<blockquote>
<p>As mentioned earlier, the Flipper Zero has a built-in sub-GHz radio that lets the device receive data (or transmit it, with the right firmware in approved regions) on the <a href="https://www.thedrive.com/tech/i-tried-the-honda-keyfob-hack-on-my-own-car-it-totally-worked">same wireless frequencies as keyfobs and other devices</a>. Most traffic preemption devices intended for emergency traffic redirection don&#8217;t actually transmit signals over RF. Instead, they use optical technology to beam infrared light from vehicles to static receivers mounted on traffic light poles.</p>
<p>Perhaps the most well-known branding for these types of devices is called <a href="https://www.gtt.com/">Opticom</a>. Essentially, the tech works by detecting a specific pattern of infrared light emitted by the Mobile Infrared Transmitter (MIRT) installed in a police car, fire truck, or ambulance when the MIRT is switched on. When the receiver detects the light, the traffic system then initiates a signal change as the emergency vehicle approaches an intersection, safely redirecting the traffic flow so that the emergency vehicle can pass through the intersection as if it were regular traffic and potentially avoid a collision.
</p>
</blockquote>
<p>This seems easy to do, but it&#8217;s also very illegal. It&#8217;s called &#8220;impersonating an emergency vehicle,&#8221; and it comes with hefty penalties if you&#8217;re caught.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
		<link>https://www.newenglandsp.com/2023/02/cisa-adds-three-known-exploited-vulnerabilities-to-catalog-6/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisa-adds-three-known-exploited-vulnerabilities-to-catalog-6</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 21 Feb 2023 18:34:00 +0000</pubDate>
				<guid isPermaLink="false">http://www.newenglandsp.com/?guid=6779a930b5e3b770ab722ab8880f8c0c</guid>

					<description><![CDATA[Original release date: February 21, 2023CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.


	CVE-2022-47986 IBM Aspera Faspex Code Execution Vulnerability
	CVE-2022-41223 ...]]></description>
										<content:encoded><![CDATA[<p>Original release date: February 21, 2023</p>
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities Catalog</a>, based on evidence of active exploitation.</p>
<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47986">CVE-2022-47986</a> IBM Aspera Faspex Code Execution Vulnerability</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41223">CVE-2022-41223</a> Mitel MiVoice Connect Code Injection Vulnerability</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40765">CVE-2022-40765</a> Mitel MiVoice Connect Command Injection Vulnerability</li>
</ul>
<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. <strong>Note:</strong> To view other newly added vulnerabilities in the catalog, click on the arrow in the &#8220;Date Added to Catalog&#8221; column, which will sort by descending dates.</p>
<p><a href="https://www.cisa.gov/binding-operational-directive-22-01">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href="https://cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf">BOD 22-01 Fact Sheet</a> for more information.</p>
<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href="https://www.cisa.gov/known-exploited-vulnerabilities">specified criteria</a>.</p>
<div class="field field--name-body field--type-text-with-summary field--label-hidden field--item">
<p class="privacy-and-terms">This product is provided subject to this <a href="https://us-cert.cisa.gov/privacy/notification">Notification</a> and this <a href="https://www.dhs.gov/privacy-policy">Privacy &amp; Use</a> policy.</p>
</div>
]]></content:encoded>
					
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
		<link>https://www.newenglandsp.com/2023/02/cisa-adds-three-known-exploited-vulnerabilities-to-catalog-6/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisa-adds-three-known-exploited-vulnerabilities-to-catalog-6</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 21 Feb 2023 18:34:00 +0000</pubDate>
				<guid isPermaLink="false">http://www.newenglandsp.com/?guid=6779a930b5e3b770ab722ab8880f8c0c</guid>

					<description><![CDATA[Original release date: February 21, 2023CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.


	CVE-2022-47986 IBM Aspera Faspex Code Execution Vulnerability
	CVE-2022-41223 ...]]></description>
										<content:encoded><![CDATA[<p>Original release date: February 21, 2023</p>
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities Catalog</a>, based on evidence of active exploitation.</p>
<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47986">CVE-2022-47986</a> IBM Aspera Faspex Code Execution Vulnerability</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41223">CVE-2022-41223</a> Mitel MiVoice Connect Code Injection Vulnerability</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40765">CVE-2022-40765</a> Mitel MiVoice Connect Command Injection Vulnerability</li>
</ul>
<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. <strong>Note:</strong> To view other newly added vulnerabilities in the catalog, click on the arrow in the &#8220;Date Added to Catalog&#8221; column, which will sort by descending dates.</p>
<p><a href="https://www.cisa.gov/binding-operational-directive-22-01">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href="https://cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf">BOD 22-01 Fact Sheet</a> for more information.</p>
<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href="https://www.cisa.gov/known-exploited-vulnerabilities">specified criteria</a>.</p>
<div class="field field--name-body field--type-text-with-summary field--label-hidden field--item">
<p class="privacy-and-terms">This product is provided subject to this <a href="https://us-cert.cisa.gov/privacy/notification">Notification</a> and this <a href="https://www.dhs.gov/privacy-policy">Privacy &amp; Use</a> policy.</p>
</div>
]]></content:encoded>
					
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>
