
Altoona Area School District
None



None

The Clark County School District is the 5th largest school district in the nation with over 300,000 students in 357 schools and over 40,000 employees. Our focus is on people – the educators, staff, students and parents who make our community one of the most diverse and dynamic places in the country. Our vision is for all students to graduate from high school having the knowledge, skills, attitudes, and values necessary to achieve academically, prosper economically, and contribute in a global society. In recent years, CCSD has been the fastest growing district in the country, building more than 110 new schools since 2000, including six new Career & Technical Academies and some of the top magnet schools in the nation. Here are some highlights of our achievements: Ranked among the top 10 school districts in the nation for its use of blended learning programs by Edgenuity, an online provider of education solutions. Council of Chief State School Offices (CCSSO) announced that L. Juliana Urtubey is among 4 exemplary educators from across the country who are finalists for 2021 National Teacher of the Year. Named 2015 Advance Placement District of the year by the College Board for expanding access to Advanced Placement courses while improving AP Exam performance. U.S. Department of Education selected 2 CCSD schools as 2015 National Blue Ribbon Schools for their overall excellence among only 335 public and private schools recognized nationwide. Newsweek ranked 5 CCSD high schools among the best in the nation. Magnet Schools of America recognized 17 CCSD magnet schools for their outstanding programs and overall excellence. 13 of the 17 CCSD schools received the highest designation possible from MSA -"Magnet School of Excellence!" Las Vegas Academy of the Arts has 12 Grammy awards under its belt- more than any other school in the nation!
Security & Compliance Standards Overview












No incidents recorded for Altoona Area School District in 2025.
No incidents recorded for Clark County School District in 2025.
Altoona Area School District cyber incidents detection timeline including parent company and subsidiaries
Clark County School District cyber incidents detection timeline including parent company and subsidiaries
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.