
Financial Crimes Enforcement Network, US Treasury
Official LinkedIn account of the Financial Crimes Enforcement Network, a U.S. Treasury bureau. Learn more at www.fincen.gov



Official LinkedIn account of the Financial Crimes Enforcement Network, a U.S. Treasury bureau. Learn more at www.fincen.gov

Home to a respected and energetic cultural arts scene, celebrated restaurants featuring flavors from 35 countries, world-renowned theater groups and the brains behind U.S. space exploration, Houston is a diverse metropolis brimming with personality. With nearly 21,000 concerts, plays, exhibitions and other arts programs presented in Houston annually, residents and visitors have access to a wide variety of cultural programs. On any given night, it's a safe bet that there's a show somewhere in Houston's Theater District. More than 2 million people visit the Downtown area each year to attend one of the city's world-class performances. Within the Museum District you will find eighteen world-class institutions, including the Menil Collection, Museum of Fine Arts, Houston and the Houston Museum of Natural Science are clustered in this area, drawing a reported seven million visitors to the district each year. Houston’s restaurant scene is as ethnically diverse as its 4 million residents. ForbesTraveler.com ranked Houston as one of the best restaurant cities in America. The city is jam-packed with more than 8,000 tempting eateries that feature culinary flavors from more than 35 countries. With 56,405 acres of total park space, Houston rates first among the nation's 10 most populous cities in total acreage of park land. The 165 public and private golf courses around the city and teams in nearly every major professional sport keep sports fever high year-round. The city also employs over 22,000 full-time staff to keep the city running. We are always looking for everyone from Engineers to IT Professionals, from entry level to executive level. Check back here for current postings, follow us on Facebook at www.facebook.com/cohcareers or on Twitter @COHCareers for all the up to date recruitment happenings!
Security & Compliance Standards Overview












Financial Crimes Enforcement Network, US Treasury has 53.85% more incidents than the average of same-industry companies with at least one recorded incident.
City of Houston has 53.85% more incidents than the average of same-industry companies with at least one recorded incident.
Financial Crimes Enforcement Network, US Treasury cyber incidents detection timeline including parent company and subsidiaries
City of Houston cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.