
Department of Government Efficiency
The people voted for major reform.



The people voted for major reform.

Home to a respected and energetic cultural arts scene, celebrated restaurants featuring flavors from 35 countries, world-renowned theater groups and the brains behind U.S. space exploration, Houston is a diverse metropolis brimming with personality. With nearly 21,000 concerts, plays, exhibitions and other arts programs presented in Houston annually, residents and visitors have access to a wide variety of cultural programs. On any given night, it's a safe bet that there's a show somewhere in Houston's Theater District. More than 2 million people visit the Downtown area each year to attend one of the city's world-class performances. Within the Museum District you will find eighteen world-class institutions, including the Menil Collection, Museum of Fine Arts, Houston and the Houston Museum of Natural Science are clustered in this area, drawing a reported seven million visitors to the district each year. Houston’s restaurant scene is as ethnically diverse as its 4 million residents. ForbesTraveler.com ranked Houston as one of the best restaurant cities in America. The city is jam-packed with more than 8,000 tempting eateries that feature culinary flavors from more than 35 countries. With 56,405 acres of total park space, Houston rates first among the nation's 10 most populous cities in total acreage of park land. The 165 public and private golf courses around the city and teams in nearly every major professional sport keep sports fever high year-round. The city also employs over 22,000 full-time staff to keep the city running. We are always looking for everyone from Engineers to IT Professionals, from entry level to executive level. Check back here for current postings, follow us on Facebook at www.facebook.com/cohcareers or on Twitter @COHCareers for all the up to date recruitment happenings!
Security & Compliance Standards Overview












No incidents recorded for Department of Government Efficiency in 2026.
No incidents recorded for City of Houston in 2026.
Department of Government Efficiency cyber incidents detection timeline including parent company and subsidiaries
City of Houston cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.