Comparison Overview
Labour Program

Labour Program
Gatineau, CA
Last Update: 02/04/2026
Welcome to the Labour Program page. The Labour Program is part of the Employment and Social Development Canada portfolio and is responsible for protecting the rights and well-being of both workers and employers in federally regulated workplaces. We work closely with pr...

State of California
Sacramento, Sacramento, 95814, US
Last Update: 31/03/2026
Californians deserve a government that works for them and with them. One that will work to ensure opportunity and justice. We are building a California not for the few, but for all — including those who have historically been left out. We are doing the work to make ou...
Compliance Ranges Comparison

Labour Program







State of California






Benchmark & Cyber Underwriting Signals
Incidents vs Government Administration Industry Avg (This Year)
No incidents recorded for Labour Program in 2026.
Incidents vs Government Administration Industry Avg (This Year)
No incidents recorded for State of California in 2026.
Incident History - Labour Program (X = Date, Y = Severity)
Labour Program cyber incidents detection timeline including parent company and subsidiaries.
Incident History - State of California (X = Date, Y = Severity)
State of California cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Labour Program

State of California
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.