Found 48 repositories(showing 30)
python
Decisions by the Python Typing Council
consiglionazionaledellericerche
Online application system for recruitment of staff and other types of employment and training of the National Research Council of Italy.
Mario-Kart-Felix
2020 was a roller coaster of major, world-shaking events. We all couldn't wait for the year to end. But just as 2020 was about to close, it pulled another fast one on us: the SolarWinds hack, one of the biggest cybersecurity breaches of the 21st century. The SolarWinds hack was a major event not because a single company was breached, but because it triggered a much larger supply chain incident that affected thousands of organizations, including the U.S. government. What is SolarWinds? SolarWinds is a major software company based in Tulsa, Okla., which provides system management tools for network and infrastructure monitoring, and other technical services to hundreds of thousands of organizations around the world. Among the company's products is an IT performance monitoring system called Orion. As an IT monitoring system, SolarWinds Orion has privileged access to IT systems to obtain log and system performance data. It is that privileged position and its wide deployment that made SolarWinds a lucrative and attractive target. What is the SolarWinds hack? The SolarWinds hack is the commonly used term to refer to the supply chain breach that involved the SolarWinds Orion system. In this hack, suspected nation-state hackers that have been identified as a group known as Nobelium by Microsoft -- and often simply referred to as the SolarWinds Hackers by other researchers -- gained access to the networks, systems and data of thousands of SolarWinds customers. The breadth of the hack is unprecedented and one of the largest, if not the largest, of its kind ever recorded. More than 30,000 public and private organizations -- including local, state and federal agencies -- use the Orion network management system to manage their IT resources. As a result, the hack compromised the data, networks and systems of thousands when SolarWinds inadvertently delivered the backdoor malware as an update to the Orion software. SolarWinds customers weren't the only ones affected. Because the hack exposed the inner workings of Orion users, the hackers could potentially gain access to the data and networks of their customers and partners as well -- enabling affected victims to grow exponentially from there. Orion Platform hack compromised networks of thousands of SolarWinds customers Hackers compromised a digitally signed SolarWinds Orion network monitoring component, opening a backdoor into the networks of thousands of SolarWinds government and enterprise customers. How did the SolarWinds hack happen? The hackers used a method known as a supply chain attack to insert malicious code into the Orion system. A supply chain attack works by targeting a third party with access to an organization's systems rather than trying to hack the networks directly. The third-party software, in this case the SolarWinds Orion Platform, creates a backdoor through which hackers can access and impersonate users and accounts of victim organizations. The malware could also access system files and blend in with legitimate SolarWinds activity without detection, even by antivirus software. SolarWinds was a perfect target for this kind of supply chain attack. Because their Orion software is used by many multinational companies and government agencies, all the hackers had to do was install the malicious code into a new batch of software distributed by SolarWinds as an update or patch. The SolarWinds hack timeline Here is a timeline of the SolarWinds hack: September 2019. Threat actors gain unauthorized access to SolarWinds network October 2019. Threat actors test initial code injection into Orion Feb. 20, 2020. Malicious code known as Sunburst injected into Orion March 26, 2020. SolarWinds unknowingly starts sending out Orion software updates with hacked code According to a U.S. Department of Homeland Security advisory, the affected versions of SolarWinds Orion are versions are 2019.4 through 2020.2.1 HF1. More than 18,000 SolarWinds customers installed the malicious updates, with the malware spreading undetected. Through this code, hackers accessed SolarWinds's customer information technology systems, which they could then use to install even more malware to spy on other companies and organizations. Who was affected? According to reports, the malware affected many companies and organizations. Even government departments such as Homeland Security, State, Commerce and Treasury were affected, as there was evidence that emails were missing from their systems. Private companies such as FireEye, Microsoft, Intel, Cisco and Deloitte also suffered from this attack. The breach was first detected by cybersecurity company FireEye. The company confirmed they had been infected with the malware when they saw the infection in customer systems. FireEye labeled the SolarWinds hack "UNC2452" and identified the backdoor used to gain access to its systems through SolarWinds as "Sunburst." Microsoft also confirmed that it found signs of the malware in its systems, as the breach was affecting its customers as well. Reports indicated Microsoft's own systems were being used to further the hacking attack, but Microsoft denied this claim to news agencies. Later, the company worked with FireEye and GoDaddy to block and isolate versions of Orion known to contain the malware to cut off hackers from customers' systems. They did so by turning the domain used by the backdoor malware used in Orion as part of the SolarWinds hack into a kill switch. The kill switch here served as a mechanism to prevent Sunburst from operating further. Nonetheless, even with the kill switch in place, the hack is still ongoing. Investigators have a lot of data to look through, as many companies using the Orion software aren't yet sure if they are free from the backdoor malware. It will take a long time before the full impact of the hack is known. Why did it take so long to detect the SolarWinds attack? With attackers having first gained access to the SolarWinds systems in September 2019 and the attack not being publicly discovered or reported until December 2020, attackers may well have had 14 or more months of unfettered access. The time it takes between when an attacker is able to gain access and the time an attack is actually discovered is often referred to as dwell time. According to a report released in January 2020 by security firm CrowdStrike, the average dwell time in 2019 was 95 days. Given that it took well over a year from the time the attackers first entered the SolarWinds network until the breach was discovered, the dwell time in the attack exceeded the average. The question of why it took so long to detect the SolarWinds attack has a lot to do with the sophistication of the Sunburst code and the hackers that executed the attack. "Analysis suggests that by managing the intrusion through multiple servers based in the United States and mimicking legitimate network traffic, the attackers were able to circumvent threat detection techniques employed by both SolarWinds, other private companies, and the federal government," SolarWinds said in its analysis of the attack. FireEye, which was the first firm to publicly report the attack, conducted its own analysis of the SolarWinds attack. In its report, FireEye described in detail the complex series of action that the attackers took to mask their tracks. Even before Sunburst attempts to connect out to its command-and-control server, the malware executes a number of checks to make sure no antimalware or forensic analysis tools are running. What was the purpose of the hack? The purpose of the hack remains largely unknown. Still, there are many reasons hackers would want to get into an organization's system, including having access to future product plans or employee and customer information held for ransom. It is also not yet clear what information, if any, hackers stole from government agencies. But the level of access appears to be deep and broad. There are speculations that many enterprises might be collateral damage, as the main focus of the attack was government agencies that make use of the SolarWinds IT management systems. Who was responsible for the hack? Federal investigators and cybersecurity agents believe a Russian espionage operation -- mostly likely Russia's Foreign Intelligence Service -- is behind the SolarWinds attack. The Russian government has denied any involvement in the attack, releasing a statement that said, "Malicious activities in the information space contradicts the principles of the Russian foreign policy, national interests and understanding of interstate relations." They also added that "Russia does not conduct offensive operations in the cyber domain." Contrary to experts in his administration, then-President Donald Trump hinted at around the time of the discovery of the SolarWinds hack that Chinese hackers might be behind the cybersecurity attack. However, he did not present any evidence to back up his claim. Shortly after his inauguration, President Joe Biden vowed that his administration intended to hold Russia accountable, through the launch of a full-scale intelligence assessment and review of the SolarWinds attack and those behind it. The president also created the position of deputy national security adviser for cybersecurity as part of the National Security Council. The role, held by veteran intelligence operative Anne Neuberger, is part of an overall bid by the Biden administration to refresh the federal government's approach to cybersecurity and better respond to nation-state actors. Naming the attack: What is Solorigate, Sunburst and Nobelium? The SolarWinds attack has a number of different names associated with it. While the attack is often referred to simply as the SolarWinds attack, that isn't the only name to know. Sunburst. This is the name of the actual malicious code injection that was planted by hackers into the SolarWinds Orion IT monitoring system code. Both SolarWinds and CrowdStrike generally refer to the attack as Sunburst. Solorigate. Microsoft initially dubbed the actual threat actor group behind the SolarWinds attack as Solorigate. It's a name that stuck and was adopted by other researchers as well as media. Nobelium. In March 2021, Microsoft decided that the primary designation for the threat actor behind the SolarWinds attack should actually be Nobelium -- the idea being that the group is active against multiple victims -- not just SolarWinds -- and uses more malware than just Sunburst. The China connection to the SolarWinds attack While it is suspected that the initial Sunburst code and the attack against SolarWinds and its users came from a threat actor based in Russia, other nation-state threat actors have also used SolarWinds in attacks. According to a Reuters report, suspected nation-state hackers based in China exploited SolarWinds during the same period of time the Sunburst attack occurred. The suspected China-based threat actors targeted the National Finance Center, which is a payroll agency within the U.S. Department of Agriculture. It is suspected that the China-based attackers did not use Sunburst, but rather a different malware that SolarWinds identifies as Supernova. Why is the SolarWinds hack important? The SolarWinds supply chain attack is a global hack, as threat actors turned the Orion software into a weapon gaining access to several government systems and thousands of private systems around the world. Due to the nature of the software -- and by extension the Sunburst malware -- having access to entire networks, many government and enterprise networks and systems face the risk of significant breaches. The hack could also be the catalyst for rapid, broad change in the cybersecurity industry. Many companies and government agencies are now in the process of devising new methods to react to these types of attacks before they happen. Governments and organizations are learning that it is not enough to build a firewall and hope it protects them. They have to actively seek out vulnerabilities in their systems, and either shore them up or turn them into traps against these types of attacks. Since the hack was discovered, SolarWinds has recommended customers update their existing Orion platform. The company has released patches for the malware and other potential vulnerabilities discovered since the initial Orion attack. SolarWinds also recommended customers not able to update Orion isolate SolarWinds servers and/or change passwords for accounts that have access to those servers. The greater White House cybersecurity focus will be crucial, some industry experts have said. But organizations should consider adopting modern software-as-a-service tools for monitoring and collaboration. While the cybersecurity industry has significantly advanced in the last decade, these kinds of attacks show that there is still a long way to go to get really secure systems. The Nobelium group continues to attack targets The suspected threat actor group behind the SolarWinds attack has remained active in 2021 and hasn't stopped at just targeting SolarWinds. On May 27, 2021, Microsoft reported that Nobelium, the group allegedly behind the SolarWinds attack, infiltrated software from email marketing service Constant Contact. According to Microsoft, Nobelium targeted approximately 3,000 email accounts at more than 150 different organizations. The initial attack vector appears to be an account used by USAID. From that initial foothold, Nobelium was able to send out phishing emails in an attempt to get victims to click on a link that would deploy a backdoor Trojan designed to steal user information.
Types of cyber operations and other data from the Council on Foreign Relations
joemcc-90
Welcome to Leeds waste collection Home asistant integration! This is an integration to get data from Leeds City Council in the UK and create sensors for each bin type.
Code-Tap
Node Script to scrape bin collection types and dates for Walsall City Council
UnpaidAttention
Agentic SDLC framework for Google Antigravity IDE — 4 councils, 166 workflows, 236 skills, 13 quality gates, 5 cycle types. "Do it right, or do it twice."
EdinburghCityScope
Number of council house sales in Edinburgh to sitting tenants by housing type.
ulrikaandersson
NodeMCU checks council website for next bin day date and type. Displays using NeoPixel
ryanluuwas
Neural Network and Multinomial Logistic Regression in predicting the type of service requests likely to occur given the specified parameters (i.e. GPS coordinates, Council District, Season, etc.) onto San Diego’s Get it Done! dataset.
PipTea-cpu
Analysis of Blue Badge data from Leicester City Council using Python. This notebook imports, cleans, and visualizes the data to explore badge types and eligibility criteria, providing a brief overview of the Blue Badge scheme's data in Leicester.
Developed a Python-based application for a local council to analyze real-world traffic flow data collected at two major junctions. The tool processes CSV datasets to extract key traffic insights such as vehicle counts, speed violations, peak hours, and vehicle types.
melissaschenk
Using historical and current API data pulled from https://data.sandiego.gov/datasets/get-it-done-311/ this dashboard dynamically displays service request count by year and council district, service request type, and interactive mapbox cluster map of service request locations. Target audience city of San Diego leadership.
mapcolabora
This is a proof of concept and a pet project for learning python while preparing data for importing it to OpenStreetMap. Although I will start small (importing trees from Barcelona city council), I aim to set the foundations for adding other types of imports that may (or may not) be added in the future.
Taranjeet0874
The Chicago Crime dataset contains a summary of the reported crimes occurred in the City of Chicago from 2001 to 2017. Dataset has been obtained from the Chicago Police Department's CLEAR (Citizen Law Enforcement Analysis and Reporting) system. Dataset contains the following columns: ID: Unique identifier for the record. Case Number: The Chicago Police Department RD Number (Records Division Number), which is unique to the incident. Date: Date when the incident occurred. Block: address where the incident occurred IUCR: The Illinois Uniform Crime Reporting code. Primary Type: The primary description of the IUCR code. Description: The secondary description of the IUCR code, a subcategory of the primary description. Location Description: Description of the location where the incident occurred. Arrest: Indicates whether an arrest was made. Domestic: Indicates whether the incident was domestic-related as defined by the Illinois Domestic Violence Act. Beat: Indicates the beat where the incident occurred. A beat is the smallest police geographic area – each beat has a dedicated police beat car. District: Indicates police district where the incident occurred. Ward: The ward (City Council district) where incident occurred. Community Area: Indicates the community area where the incident occurred. Chicago has 77 community areas. FBI Code: Indicates the crime classification as outlined in the FBI's National Incident-Based Reporting System (NIBRS). X Coordinate: The x coordinate of the location where the incident occurred in State of Illinois. Y Coordinate: The y coordinate of the location where the incident occurred in State of Illinois. Year: Year the incident occurred. Updated On: Date and time the record was last updated. Latitude: The latitude of the location where the incident occurred. This location is shifted from the actual location for partial redaction but falls on the same block. Longitude: The longitude of the location where the incident occurred. This location is shifted from the actual location for partial redaction but falls on the same block. Location: The location where the incident occurred. predicting what crimes could take place in future by studying the crime rates in different regions ,with the help of fbprophet time series analysis .The visualization is made with the help of seaborn and matplotlib library ,by plotting several countplots,histograms etc
Narenderbeniwal
# - The Chicago Crime dataset contains a summary of the reported crimes occurred in the City of Chicago from 2001 to 2017. - Dataset has been obtained from the Chicago Police Department's CLEAR (Citizen Law Enforcement Analysis and Reporting) system. - Dataset contains the following columns: - ID: Unique identifier for the record. - Case Number: The Chicago Police Department RD Number (Records Division Number), which is unique to the incident. - Date: Date when the incident occurred. - Block: address where the incident occurred - IUCR: The Illinois Unifrom Crime Reporting code. - Primary Type: The primary description of the IUCR code. - Description: The secondary description of the IUCR code, a subcategory of the primary description. - Location Description: Description of the location where the incident occurred. - Arrest: Indicates whether an arrest was made. - Domestic: Indicates whether the incident was domestic-related as defined by the Illinois Domestic Violence Act. - Beat: Indicates the beat where the incident occurred. A beat is the smallest police geographic area – each beat has a dedicated police beat car. - District: Indicates the police district where the incident occurred. - Ward: The ward (City Council district) where the incident occurred. - Community Area: Indicates the community area where the incident occurred. Chicago has 77 community areas. - FBI Code: Indicates the crime classification as outlined in the FBI's National Incident-Based Reporting System (NIBRS). - X Coordinate: The x coordinate of the location where the incident occurred in State Plane Illinois East NAD 1983 projection. - Y Coordinate: The y coordinate of the location where the incident occurred in State Plane Illinois East NAD 1983 projection. - Year: Year the incident occurred. - Updated On: Date and time the record was last updated. - Latitude: The latitude of the location where the incident occurred. This location is shifted from the actual location for partial redaction but falls on the same block. - Longitude: The longitude of the location where the incident occurred. This location is shifted from the actual location for partial redaction but falls on the same block. - Location: The location where the incident occurred in a format that allows for creation of maps and other geographic operations on this data portal. This location is shifted from the actual location for partial redaction but falls on the same block. - Datasource: https://www.kaggle.com/currie32/crimes-in-chicago
Amravati is also known as Ambangari is a city in the Maharashtra State, India. It is the 5th most crowded urban area in the state. It is the governmental head office if the Amravati District. It is also head office of Amravati separation or division. Which is one of the six separations of the state? Among the chronological or historical landmarks in the town are the temples of Shri Venkateshwara, Shri Krishna and Amba. Engineering is the submission of scientific, economic, social machines, devices, system, materials and processes. The regulation of engineering is enormously board and encompasses a range of more specific fields of engineering, each with a more specific prominence on meticulous areas of applied science, technology and types of application. The original function of scientific principles to plan or develop structures, machines equipment, or developing procedure or works operate them individually or in amalgamation; or to build or function the same with full cognizance of their design; or to estimate their behavior under precise in service situation; all as greetings an future function, finances of operation or security of life and possessions. One who performs engineering is called an engineer and those licensed to do so may have more recognized designations such as Professional Engineer, Designated Engineering, Representative, Chartered Engineer, Incorporated Engineer, Ingenieur or Eurpoean Engineer. Engineering has existed since ancient times as human’s devised elementary development such as the hold, lever, wheel and pulley. Each of these creations is fundamentally steady with the modern explanation of engineering. The phrase engineering itself has a much more fresh etymology, obtain from the word engineer, which itself appointment back to 1300, when an engineer (accurately, one who function an engine) initially referred to “a constructor of services engines.” In this context, now out of date, an “engine” referred to a military appliance, i.e. a mechanical device used in disagreement for example a project. Notable examples of the outdated usage which have stayed alive to the in attendance day are military engineering group, e.g. the US Army group of Engineers. The word “engine” itself is of still big source; eventually get hold of from the Latin ingenium, and sense “normal advantage, particularly academic authority, for this cause a brilliant conception.” afterward, as the propose of inhabitant arrangement such as suspension bridge and building developed as a strictly regulation, the term civil engineering go into the vocabulary as a method to discriminate connecting those concentrate in the building of such non- military venture and those concerned in the elder restraint of armed engineering. Sipna is the Top Engineering College in Amravati, Maharashtra. Sipna’s College of Engineering & Technology has a wonderful history of 10 years through which it has grown and urbanized in to illustrious institute of technical education and research. All component of the institution have conventional, promote and uphold its high average and impressive civilization over the years. I feel hugely satisfied about the development of the institution and positive that the institution will achieve superiority in education and research. These all courses or programs are agreed by All India Council for Technical Education, New Delhi, and Government of Maharashtra and associated to Sant Gadge Baba Amravati University, Amravati. The policy of the Sipna college of Engineering and Technology is terminate to be at the vanguard of the technical education by generating a hub of custom and to be rated and conventional as a imitation institute in the district by the stakeholders in order to team to the obligation of the society. Vision of Sipna College of Engineering and Technology is providing the excellence, specialized education and conductive atmosphere to come out as a representation capable institute. Sipna rating for the top Engineering College in Maharashtra Amravati 2015 bring you a comprehensive list of reputed engineering institutes in the state.
Comtrag8
A typing practice tool for Pharmacy Technician Educator Council members
youhyun-ai
MBTI Council — pick 3 types, ask anything, watch them debate
priyakalyan
Finding correlation between crime and 311 request types in LA city neighborhood councils
Alyshira
Join flow prototype for AI Ops Council - demonstrates segmented onboarding for different user types.
honisoit
Vote Compass type canidate similarity quiz for the University of Sydney's 2017 Student Representative Council election
localgovdrupal
Creates a content type and list for the weekly planning notices that all Irish councils must publish.
prajwalheybobo
A screening agent that analyses the users distress type and suggests cure helps build on a councilling agentic ai.
nirmalghimire
Analysis of theses and dissertations by year, report type, and academic program from 2020 to 2024, with visualizations for Graduate Council review.
jgcrunden
An Alexa skill which informs residents of Stroud District Council when the next bin day is and what waste collection type it is.
AbrishamLocalPathways
A comparison between the council types of NSW, Australia for crime and mental health using publicly available datasets from NSW Bureau of Crime Statistics and Research (BOSCAR) and the Australian Bureau of Statistics (ABS) census data.
peres84
SpecTalk is an open-source, voice-first, spec-driven development system. You have a conversation with your AI — it understands your project, assembles a design council of specialist agents, generates a full specification, and autonomously builds your project using parallel Claude Code agents. No typing. No manual scaffolding. Just talk.
NnekaAsuzu
House Price Prediction project using a dataset containing information such as number of rooms, price, property type, seller, date sold, distance from CBD, region name, property count, bedrooms, bathrooms, carspots, land size, building size, year built, council area, latitude, and longitude.
Excel-based analysis of housing affordability across London boroughs. Combined income, rent, council tax, and commuting data to build an affordability index. Explored differences by household type and gender, highlighting structural cost-of-living pressures and affordability–commute trade-offs.