CCC A.I CyberSecurity Scoring
26/01/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for C2C - Close to Consumer in 2026.
No incidents recorded for C2C - Close to Consumer in 2026.
No incidents recorded for C2C - Close to Consumer in 2026.
We established our back office here in Pakistan back in 2016 after which we have been providing complete support to our registered office in Florida. Our main aim has been to function as an effective thirdparty service provider in order to maintain beneficial relationships with multiple US based clients.Our sole focus has always been to deliver our best in an efficient and timely manner. We make sure that we develop a relationship of trust with our clients so that they can highly improve their business performance and shareholder value, at the same time reducing their costs to a greater extent. We function to cater businesses unique needs for multiple industries such as accounting, e‐commerce, pharmaceuticals, telecommunications and more. A highly committed, multi‐talented and energetic team is the sole reason we have been able to offer solutions to complex problems within a specified timeframe so that our clients’ needs and requirements are completely fulfilled with complete satisfaction.
TaskUs delivers outsourced digital services that power the companies shaping the future. By combining specialized human talent and intelligent technology, we solve complex operational challenges for global category leaders within AI, autonomous vehicles (AV), robotics, social media, financial services, healthcare, and beyond. We enable our clients to elevate their customer experience, protect their platforms, and grow their brands.
As the global leader in trusted technology services, empowering secure mobility for governments and citizens, VFS Global embraces technological innovation including Generative AI to support governments and diplomatic missions worldwide. VFS Global continuously transforms its business model with secure and efficient processes, market offerings and advanced technologies including AI/Analytics. With a responsible approach to technology development, adoption and integration, the company prioritizes ethical practices and sustainability while serving as a trusted partner to 69 client governments. VFS Global enhances cross border mobility for global citizens through highly secure, reliable, efficient, and innovative technology solutions. With an extensive global network and reach of over 3,900 Application Centres in 165 countries, VFS Global has efficiently processed more than 514 million transactions since 2001. We are an employee-centric organisation, creating meaningful work opportunities and fostering successful careers. Headquartered in Zurich and Dubai and majority owned through investment funds managed by Blackstone Inc, along with minority stakeholders including Swiss-based Kuoni and Hugentobler Foundation, we have been recognised for our commitment to nurturing a diverse and inclusive workplace, empowering women in our workforce and promoting gender equality at all levels of the organisation. We’re proud to be Great Place to Work-certified in Nigeria, China, India, and UAE, and hold multiple international certifications in data privacy, anti-bribery systems, and customer satisfaction. *Comprised of 325.54 million transactions by VFS Global and 189.12 million transactions by CiX Citizen Experience
iQor CXBPO™ is a trusted partner in intelligent customer experience solutions for global brands and a portfolio company of Mill Point Capital. With 47,000+ employees across 11 countries, iQor combines three decades of expertise with AI-driven innovation to optimize performance across the entire customer lifecycle. Through its three delivery pillars—CXBPO, Growth as a Service, and infinityAiQ—iQor delivers scalable solutions that drive acquisition, engagement, and retention. Powered by data intelligence and a people-first culture, iQor transforms customer interactions into measurable growth. Recognized as a Great Place to Work® and a leader in CX excellence, iQor empowers brands to grow smarter. Recent acquisitions of JumpCrew and OP360 further expand iQor’s global capabilities across sales, marketing, and customer experience delivery. Learn more at iQor.com.
Majorel has been acquired by TP allowing us to deliver even more exceptional services in more locations worldwide and on a greater scale than ever before. We deliver the most advanced, digitally-powered business services to help the world’s best brands streamline their business in meaningful and sustainable ways. The combination of our leading business services companies makes TP the industry leader, more capable than ever of delivering critical solutions and the support you need. Let’s master change together!
Intelcia is a global player in outsourcing, which has supported its clients for 20 years combining talents, technologies, and processes to offer a tailor-made service and skills that meet international standards. In order to allow its customers to focus on their challenges and core business, Intelcia offers a global offer on shore, near shore and offshore around a cluster of 4 main solutions: Multichannel CX Solutions, Business Processes, IT Solutions, and Innovative & Consulting Solutions. Present in Europe (France, Portugal, Spain, United Kingdom), in North Africa (Morocco, Egypt) in Sub-Saharan Africa (Cameroon, Senegal, Ivory Coast), in the Indian Ocean (Mauritius, Madagascar), in North America (United States United) in Latin America (Colombia, Chile) and the Caribbean (Jamaica, Dominican Republic), the group currently has more than 35,000 employees, spread across 85 operational centers. Intelcia has announced its ambition to be in the top 10 global outsourcing players and to reach 1.5 billion euros in turnover by 2025.
Transcom provides digitally enhanced customer experience (CX) services to some of the world's most ambitious brands. More than 300 clients globally, including disruptive e-commerce players, category redefining fintechs, and technology legends rely on us for on-, off-, and nearshoring services. Transcom’s over 33,000 employees work in 90 contact centers and work-at-home networks across 28 countries, creating brilliant experiences in customer care, sales, content moderation, and backoffice services. We help our clients drive their brands forward, customer satisfaction up, and operating costs down.
O Grupo Brasanitas é composto por quatro empresas, Brasanitas Limpeza e Conservação, Brasanitas Hospitalar, Praxxis Controle de Pragas e Infralink Facilities Services, o Grupo Brasanitas atua em indústrias em geral, hospitais, shopping centers, instituições de ensino, mineradoras, entre outros segmentos. Com mais de 26 mil colaboradores, a companhia está presente nas regiões Sul, Sudeste, Nordeste e Centro-Oeste do país. Limpeza e Conservação Ambiental - Manutenção Predial - Logística Interna - Gerenciamento de Facilities -Higienização Hospitalar - Gerenciamento de Leitos - Serviços de Apoio - Controle Integrado de Pragas - Jardinagem.
We’re passionate about creating customers for life by designing experiences that elevate your brand. As your full-service CX partner from strategy to execution, we blend proven performance, industry-leading expertise and the right technology that delivers real results and limitless possibilities. What makes us different: We don't just deliver customer experiences—we pioneer them. Bold enough to challenge convention, relentless in delivering results, connected through deep client relationships, and true to our values of integrity and authenticity. Our global reach includes 100,000 professionals across 17 countries, serving 250+ brands in 75+ languages. Ready to be part of a team that's curious, creative, connected, and committed? Check out our careers page: alorica.com/careers
Latest updates, reports, and threat intel affecting the global network.
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.