ASG A.I CyberSecurity Scoring
04/12/2025
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Avia Solutions Group in 2026.
No incidents recorded for Avia Solutions Group in 2026.
No incidents recorded for Avia Solutions Group in 2026.
Delta Air Lines (NYSE: DAL) is the U.S. global airline leader in safety, innovation, reliability and customer experience. Powered by our employees around the world, Delta has for a decade led the airline industry in operational excellence while maintaining our reputation for award-winning customer service. With our mission of connecting the people and cultures of the globe, Delta strives to foster understanding across a diverse world and serve as a force for social good.
Red. Hot. Spicy. That’s not just our tagline, it’s how we fly. Red reflects the bold spirit we bring to every journey, energetic, passionate, and full of heart. Hot captures the warmth of our service and the vibrant destinations we connect. Spicy is our drive to keep travel exciting through innovation and industry-firsts. Since 2005, SpiceJet has been shaping India’s aviation journey, connecting people, places, and possibilities. We pioneered regional air connectivity under the UDAN scheme, making air travel more accessible across the country. We led several industry-firsts, including India’s first biofuel-powered flight, the first seaplane, and in-flight entertainment on personal devices. Our premium economy product, SpiceMax, brings added comfort, priority services, and hot meals, redefining low-cost travel. At SpiceJet, we fly with passion, powered by people, always Red. Hot. Spicy.
Welcome to AISATS! As India's leading gateway services company headquartered in Mumbai and operating in Delhi, Bengaluru, Hyderabad, Thiruvananthapuram, Mangaluru and Ranchi airports, we at AISATS, care for our client airlines and their passengers. Our customers know when they do business with us, they do business with our 15000+ value creators, because our people are passionate believers of the company’s vision, mission and core values. Our comprehensive gateway services that include ground handling and air cargo handling are managed by a team of experts that understand the importance of your business. That’s why, every time we serve a passenger, we partner with our customer airlines to create a new travel memory. Every piece of cargo held, is our promise to deliver it carefully and every ramp support offered is a commitment to safe and secure operations. At AISATS we place purpose at the core of everything we do. Every day, everyone comes together to pursue our promise of service excellence. No matter what the ask, we always deliver. We are AISATS. People First - Customer Focused - Purpose Driven
Grupo Aeromexico, S.A.B. de C.V. is a holding company whose subsidiaries are engaged in commercial aviation and the promotion of passenger loyalty programs in Mexico. Aeromexico, Mexico’s global airline, operates more than 600 daily flights and has its main hub in Terminal 2 of the Mexico City International Airport. Its destinations network features 89 cities on three continents; including 43 destinations in Mexico, 18 in the United States, 17 in Latin America, 4 in Europe, 3 in Canada, and 3 in Asia. The Group's operating fleet of 133 aircraft is comprised of Boeing 787 and 737 jet airliners and next generation Embraer 170 and 190 models. In 2012, the airline announced its most significant investment strategy in Mexican aviation history, purchasing 100 Boeing aircraft including 90 MAX B737 jet airliners and 10 B787-9 Dreamliners. As a founding member of the SkyTeam airline alliance, Aeromexico offers customers more than 1,000 destinations in 177 countries served by the 20 SkyTeam airline partners rewarding passengers with benefits. Our vision Be the #1 choice for delivering the best personalized flying experience with a spirit of warmth and service. Our Values Deliver sustained growth by providing consistent service from the heart and creating unique experiences with safety and discipline. Our Behaviors Put safety first- Fully comply with norms, policies and procedures guaranteeing the safety and well-being of our customers and employees. Serve with excellence- Provide best- in-class quality service, taking care of the details that are important for your customers, and offer a personalized experience every step of the way. Collaborate as one- Work as a team, creating synergies and integrating different perspectives to be more efficient and unleash Aeromexico’s potential. Live with unshakable integrity- Be an ambassador for Aeromexico, acting with discipline and responsibility at all moments according to our values and Code of Conduct.
Based in Dubai, the Emirates Group employs over 120,000 staff from more than 170 nationalities. The Emirates Group’s extensive and diverse international portfolio includes the world’s largest international airline, Emirates, and one of the largest combined air services provider in the world, dnata. Within the Group there are a diverse range of businesses which offer a wide spectrum of career opportunities, all of which can be explored through the Group's dedicated careers website, emirates.com/careers Essential to the Group’s ongoing success is the employment of high-quality people who benefit from living and working in Dubai, a modern cosmopolitan city offering one of the most desirable lifestyles in the world. The Emirates Group employees come from over 170 nationalities, receive tax-free salary and benefits package, and are offered professional development opportunities to further their careers with the organisation. If you are a high-performer, seeking a career challenge, personal and professional development, and reward and recognition for your contribution, then the Emirates Group is the perfect opportunity for you. To find out more about the career opportunities the Emirates Groups offers and how to become part of our future growth and rapid success, visit emirates.com/careers
Welcome to the official Cathay Pacific LinkedIn page. We have over 200 destinations in our global network, but want to do more than just move you from A to B. We want to take you further in your journey, and ultimately, to move beyond. And we’re here to do what we can to help you discover what’s next. For flight and related enquiries, please contact us via WhatsApp (+852 2747 2747). For other feedback or a formal response, please fill out the form at https://bit.ly/3N7e3BM.
JetBlue — New York's Hometown Airline — was born at JFK in 1999 with the mission of bringing humanity back to air travel, and is now a leading carrier in NYC, Boston, Fort Lauderdale, Orlando, and San Juan. JetBlue serves 40M+ customers annually, with low fares and award-winning service to 100+ destinations on both sides of the Atlantic. Questions? We’ve got you. Visit jetblue.com
gategourmet has been serving the airline industry for more than 70 years and has become the world’s largest independent provider of airline catering and logistics. We prepare tens of thousands of tasty, nutritious passenger meals and snacks daily and reliably service more than 2 million flights a year in “last mile” operations worldwide. gategourmet is the core business behind gategroup, the leading independent global provider of products, services and solutions related to an airline passenger’s onboard experience. Our 27,000 employees work to serve people on the move with their expertise in catering and hospitality, provisioning and logistics, and onboard solutions. We serve over 250 carriers in more than 30 countries and provide our customers with expertise and solutions tailored to their guests, service offerings, and geographic regions.
Canada's largest airline, the country’s flag carrier and a founding member of Star Alliance, the world's most comprehensive air transportation network celebrating its 25thanniversary in 2022, Air Canada provides scheduled passenger service directly to 51 airports in Canada, 51 in the United States and 86 internationally. It is the only international network carrier in North America to receive a Four-Star ranking from Skytrax, which in 2021 gave Air Canada awards for the Best Airline Staff in North America, Best Airline Staff in Canada, Best Business Class Lounge in North America, and an excellence award for its management of the COVID-19 pandemic. ** Air Canada est la plus importante société aérienne du Canada, le transporteur national du pays et un membre cofondateur du réseau Star Alliance — le plus vaste regroupement mondial de sociétés aériennes, qui célèbre son 25e anniversaire en 2022. Les lignes passagers régulières d’Air Canada relient sans escale 51 aéroports au Canada, 51 aux États-Unis et 86 sur le reste du globe. En Amérique du Nord, Air Canada constitue le seul transporteur aérien d’envergure internationale offrant une gamme complète de services à détenir la cote quatre étoiles de Skytrax qui, en 2021, lui a décerné les prix Meilleur personnel au sol et à bord en Amérique du Nord, Meilleur personnel au sol et à bord au Canada, Meilleur salon de classe affaires en Amérique du Nord ainsi qu’un Prix d’excellence pour sa gestion de la pandémie de la COVID-19.
Latest updates, reports, and threat intel affecting the global network.
Avia Solutions Group selects Dubai South for its regional HQ with an AI innovation hub, reinforcing Dubai's aviation leadership.
The world's largest ACMI provider has chosen Mohammed Bin Rashid Aerospace Hub as its Middle East base, complete with an AI-driven...
Avia Solutions Group, the world's largest ACMI services provider, is opening a state-of-the-art new regional HQ in Dubai South.
Mohammed Bin Rashid Aerospace Hub (MBRAH), the aerospace platform of Dubai South dedicated to advancing the aviation industry,...
Dublin-based Avia Solutions Group, the world's largest ACMI provider, plans to consolidate its European Air Operators Certificates.
Vietnam's business aviation sector is in its early stages but showing signs of significant potential, according to Quang Le,...
Australian passenger airline Skytrans, part of the world's largest ACMI (Aircraft, Crew, Maintenance, and Insurance) provider Avia Solutions...
SmartLynx, a Latvia-based provider of aircraft and crews for airlines, is abandoning freighter operations and its fleet of Airbus A321 converted cargo jets to...
On November 12, 2024, Avia Solutions Group, known as the world's largest ACMI (Aircraft, Crew, Maintenance, and Insurance) provider,...
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that returns the poisoned issue, the payload executes in the admin’s control panel session. No control panel account or elevated privileges are required on the attacker’s side. This issue has been fixed in versions 4.17.16 and 5.9.23.
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the target folder. It never enforces deletePeerAssets:<volume-uid>, even though Assets::deleteFoldersByIds() cascades deletion to every descendant folder and every asset inside, regardless of the uploader's assigned privileges. A low-privilege user who has been granted folder-management rights on a shared volume can therefore destroy assets uploaded by other users (peer assets), bypassing the per-asset peer-permission check that the sibling actionDeleteAsset endpoint correctly applies. This issue has been fixed in versions 4.17.15 and 5.9.22.
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete permission by supplying both assetId and sourceAssetId. AssetsController::actionReplaceFile() supports replacing a target asset file using another existing asset as the source. The action loads: assetId -> $assetToReplace and sourceAssetId -> $sourceAsset, then enforces replace permissions using ($assetToReplace ?: $sourceAsset). When both IDs are provided, this expression resolves to the target asset so no permission check is performed against the source asset volume. When both assets are present, Craft copies the source file into the target and then deletes the source asset. There is no deletion check for for the source asset. An authenticated user who can replace files in one volume can delete assets in another volume where they do not have delete permission, as long as they can obtain a sourceAssetId, leading to broken content references and data loss. This issue has been fixed in versions 4.17.14 and 5.9.21.
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "letsencrypt.org"' without parameters). On Universal SSL zones, Cloudflare's authoritative DNS serves this auto-managed RRset at query time, superseding any customer-configured CAA records on the zone. When a customer publishes a stricter CAA record using the RFC 8657 accounturi or validationmethods parameters, the Certificate Authority does not observe those parameters when evaluating the served RRset under RFC 8659. As a result, the RFC 8657 account-binding and validation-method-binding protections are not enforced end-to-end on Universal SSL zones. Successful exploitation could result in issuance of a browser-trusted TLS certificate to an attacker, enabling MITM against the affected domain. Exploitation is non-trivial in practice: an attacker would need to hold an ACME account at one of the Certificate Authorities in the served CAA RRset and to simultaneously satisfy domain control validation across the multiple geographically distinct Network Perspectives the CA relies on for Multi-Perspective Issuance Corroboration. Cloudflare prefixes are anycast-announced from hundreds of locations globally, raising the bar against single-vantage-point BGP hijacks. Any resulting misissuance of a browser-trusted certificate is subject to Certificate Transparency logging required by major browsers, and would be visible to CT monitoring. Mitigation: Customers requiring strict RFC 8657 enforcement need to disable Universal SSL on the affected zone. Universal SSL's automatic CAA management and customer-set RFC 8657 accounturi and validationmethods enforcement are mutually exclusive by the nature of the issue, so there is no in-product workaround that preserves both. Certificate Transparency monitoring is recommended for all customers as a general detection control. Credits: David Osipov (ORCID: https://orcid.org/0009-0005-2713-9242), independent researcher
Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.