Comparison Overview
BMW Group Italia

BMW Group Italia
Via dell'Unione Europea 1, San Donato Milanese, Milano, IT, 20097
Last Update: 17/02/2026
BMW Italia appartiene ad un Gruppo internazionale sorto nel 1916 a Monaco di Baviera che aveva inizialmente come oggetto sociale la costruzione di motori per aerei (da cui deriva il logo di BMW che rappresenta un’elica stilizzata). BMW è presente in Italia dal 1965, in...

BYD
No.3009, BYD Road, Pingshan, Shenzhen, 518118, CN
Last Update: 11/09/2026
Established in 1995, BYD is a top high-tech enterprise in China specializing in IT, automobile, and new energy.BYD is the largest supplier of rechargeable batteries in the globe, and has the largest market share for Nickel-cadmium batteries, handset Li-ion batteries, ce...
Compliance Ranges Comparison

BMW Group Italia







BYD






Benchmark & Cyber Underwriting Signals
Incidents vs Motor Vehicle Manufacturing Industry Avg (This Year)
No incidents recorded for BMW Group Italia in 2026.
Incidents vs Motor Vehicle Manufacturing Industry Avg (This Year)
No incidents recorded for BYD in 2026.
Incident History - BMW Group Italia (X = Date, Y = Severity)
BMW Group Italia cyber incidents detection timeline including parent company and subsidiaries.
Incident History - BYD (X = Date, Y = Severity)
BYD cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

BMW Group Italia

BYD
FAQ
Latest Global CVEs
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
- https://github.com/vllm-project/vllm
- https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/nixl/push_worker.py#L162-L181
- https://github.com/vllm-project/vllm/pull/55677
- https://www.vulncheck.com/advisories/vllm-through-0.29.0-memory-exhaustion-via-rejected-requests
redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.
- https://github.com/NodeRedis/node-redis-parser
- https://github.com/NodeRedis/node-redis-parser/blob/701655430f5f7d9ca00892a02f7eefcbc1193a98/lib/parser.js#L204-L213
- https://github.com/NodeRedis/node-redis-parser/blob/701655430f5f7d9ca00892a02f7eefcbc1193a98/lib/parser.js#L291-L306
- https://github.com/redis/ioredis/issues/2108
- https://www.vulncheck.com/advisories/redis-parser-through-3.0.0-denial-of-service-via-unbounded-recursion
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.