CSS A.I CyberSecurity Scoring
12/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Caffitaly System S.p.A. in 2026.
No incidents recorded for Caffitaly System S.p.A. in 2026.
No incidents recorded for Caffitaly System S.p.A. in 2026.
Food and Beverage Services
Compass Group is a global leader in food services operating in over 25 countries with around 590,000 employees worldwide and generating underlying revenues of over $46 billion for the 2025 fiscal year. Our vision is to be a world-class provider of contract food services and support services, renowned for our great people, our great service, and our great results.
HMSHost is recognized by the industry as the leader in travel dining with awards such as Restaurateur with the Highest Regard for Customer Service and Best Brand Restaurateur for Shake Shack by Airport Experience News. USA Today 10Best Readers’ Choice Travel Awards gave first place honors to both of HMSHost’s Whisky River locations at Charlotte Douglas International Airport and Raleigh-Durham International Airport. ACI-NA, the trade association representing commercial service airports in the United States and Canada, recognized HMSHost with the 2020 Inclusion Champion Award, for leadership and achievement in the ongoing inclusion of business and workforce diversity, outreach, and advocacy. The company also creates original award-winning events and campaigns including Airport Restaurant Month, Channel Your Inner Chef live culinary contest, 1,000 Acts of Kindness, and Eat Well. Travel Further. For careers, text HMSHost to 97211 or visit us at careers.hmshost.com
Compass Group is redefining the food and facility services landscape with innovation and passion through the lens of what’s next. Serving premier healthcare systems, respected educational institutions, world-renowned cultural centers, popular sporting and entertainment venues, and Fortune 500 organizations, Compass Group always finds a way to deliver excellence in nearly any vertical. Ranked No. 1 by industry peers on Fortune’s 2023 list of World’s Most Admired Companies, Compass has also earned a spot on Newsweek’s 2023 lists of America’s Greatest Workplaces for Diversity and America’s Most Trustworthy Companies and is among the Top 50 Companies Changing the World according to Fortune. Compass Careers Site - JOIN US! www.compassgroupcareers.com Compass USA Facebook: @compassgroupusa Compass USA Instagram: @compassgroupusa
Americana Restaurants is the largest restaurant operator in the MENA region and Kazakhstan in terms of number of restaurants in its countries of operations. Americana Restaurants operates iconic global brands such as KFC, Pizza Hut, Hardee’s, Krispy Kreme and TGI Fridays, along with proprietary brands such as Wimpy and Chicken Tikka across the MENA region and Kazakhstan for almost fifty years. The strength of Americana Restaurants is in the diversity of its portfolio which covers some of the most popular food categories including QSR, casual dining, indulgence, and coffee. Americana leverages the worldwide appeal and recall of its iconic brands, sustained focus on customer satisfaction, implementation of digital measures to increase efficiency in operations and enhance the customer experience. It replicates, improves and adapts to local tastes the tried-and-tested dining solutions from some of the world’s most popular brands with multi-decade global brand equity and high embedded customer trust, appeal and preference.
Keurig Dr Pepper (KDP) is a leading beverage company in North America, with annual revenue in excess of $14.1 billion and nearly 28,000 employees. KDP holds leadership positions in soft drinks, specialty coffee and tea, water, juice and juice drinks and mixers, and markets the #1 single serve coffee brewing system in the U.S. and Canada. The Company’s portfolio of more than 125 owned, licensed and partner brands is designed to satisfy virtually any consumer need, any time, and includes Keurig®, Dr Pepper®, Green Mountain Coffee Roasters®, Canada Dry®, Snapple®, Bai®, Mott's®, CORE® and The Original Donut Shop®. Through its powerful sales and distribution network, KDP can deliver its portfolio of hot and cold beverages to nearly every point of purchase for consumers. The Company is committed to sourcing, producing and distributing its beverages responsibly through its Drink Well. Do Good. corporate responsibility platform, including efforts around circular packaging, efficient natural resource use and supply chain sustainability. For more information, visit, www.keurigdrpepper.com.
Founded in 1977, Almarai Company is the world’s largest vertically integrated dairy company and the largest food and beverage manufacturing and distribution company in MENA. Headquartered in Riyadh, Almarai Company is ranked as the number one FMCG Brand in the MENA region and the market leader in all its categories across GCC, Egypt, and Jordan. Over five decades of sustainable growth, Almarai has consistently provided nutritious and healthy products to consumers of all ages, driven by its core principle: “Quality you can trust.” Almarai has expanded its product range to include, in addition to dairy products, juices and beverages, baked goods, poultry, infant formula, dates, fish and seafood, and bottled water, under more than 20 brands such as Almarai, L’usine, 7DAYS, ALYOUM, Nuralac, Farm’s Select, Ice Leaf, Almira, Seama, Oska, IVAL, Almarai Pro, Premier Chef, Bakemart, and others. In 2024, Almarai reported net income of SAR 2.31 billion on sales of SAR 20.98 billion. For more information, please visit our website.
Perfetti Van Melle is a privately owned company, producing and distributing candies and chewing gums in more than 150 countries worldwide. Employing over 17.000 people and operating 37 companies throughout the world, Perfetti Van Melle has a true global reach: it is present in the Asia Pacific Region, Europe, Middle East, Africa and the Americas The industrial adventure of Perfetti Van Melle began many years ago, but it was in March 2001 that the current Group was set up through the merger of Perfetti Spa and Van Melle N.V. In July 2006 the Group acquired the Spanish company Chupa Chups S.A., famous all over the world for its lollypops. Our brands convey the passion we have for our products. We continuously explore new ways of doing things and innovative ideas that will inspire and delight our consumers worldwide. Our global brands Mentos, Chupa Chups, Alpenliebe gratify, refresh, inspire consumers of all ages around the globe. Other brands are extremely popular in regional markets with innovative tastes that match local preferences.
Every day, millions of people throughout the world consume foods and beverages containing Kerry’s taste and nutrition solutions. We are committed to making the world of food and beverage better for everyone, and dedicated to our Purpose, Inspiring Food, Nourishing Life. At Kerry, we are proud to provide our customers – some of the world’s best-known food, beverage and pharma brands – with the expertise, insights and know-how they need to deliver products that people enjoy and feel better about consuming. Kerry is a company rich in heritage and resources. Over the past five decades, our focus on changing lifestyles, the globalisation of food tastes and ever-evolving consumer needs has brought us to a market-leading global position. Today, we are firmly established as a world leader in the food, beverage and pharma industries, with 22,000+ staff and 150+ innovation and manufacturing centres across 30+ countries. Learn more about Kerry: www.kerry.com
Atlanta-based platform company GoTo Foods (formerly known as Focus Brands) is a leading developer of global multi-channel foodservice brands. As of December 28 , 2025, GoTo Foods, through its affiliate brands, is the franchisor and operator of over 7,300 restaurants, cafes, ice cream shoppes and bakeries in all 50 states and in 71 countries and territories under the Auntie Anne’s®, Carvel®, Cinnabon®, Jamba®, Moe’s Southwest Grill®, McAlister’s Deli® and Schlotzsky’s® brand names, as well as the Seattle’s Best Coffee® brand on certain military bases and in certain international markets. The iconic GoTo Foods brands benefit from strong enterprise growth engines, including marketing, digital, technology and franchise sales & development to propel growth and brand performance. Please visit www.gotofoods.com to learn more. GoTo Foods is proud to be Certified™ by Great Place To Work®, the most definitive “employer-of-choice” recognition, and the only recognition based entirely on what employees report about their workplace experience for the second consecutive year.
Latest updates, reports, and threat intel affecting the global network.
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1, outlen - 1) and then scanned the result with strchr(out_buf, '"'). Because strncpy does not NUL-terminate the destination when the source is at least outlen - 1 (127) bytes long, the subsequent strchr reads past the 128-byte destination buffer into adjacent stack memory; if a " byte is found beyond the buffer, a one-byte out-of-bounds NUL write also occurs. A related defect in extract_payload() runs strchr/strrchr over the receive buffer, which may not be NUL-terminated when a maximal-length frame fills it. The parsed bytes come directly from the OCPP central-system server over a websocket: the reader thread fills recv_buf via websocket_recv_msg() and calls parse_rpc_msg() on each inbound DATA frame (subsys/net/lib/ocpp/ocpp.c). A malicious or compromised central server, or an on-path attacker (OCPP is commonly deployed over plain ws://), can send an RPC frame whose uid or action field is 127+ bytes with no closing quote, triggering the out-of-bounds access. The primary impact is a remotely triggerable denial of service: the unbounded scan can fault on an unmapped page, and the stray NUL write can corrupt adjacent stack state. The over-read data is not reflected to the peer, so disclosure is limited. The feature is EXPERIMENTAL and must be explicitly enabled (CONFIG_OCPP). The fix replaces the manual parser with the bounds-respecting json_mixed_arr_parse() and copies the extracted uid with an explicitly NUL-terminated buffer, eliminating both over-reads.
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.
Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import is never balanced by a destroy. The imbalanced teardown is reached every time subnet keys are destroyed: deleting a subnet (Config Server NetKey Delete), completing a Key Refresh Procedure (which retires the old key set), and resetting/re-provisioning the node. The over-the-air triggers are processed only under the node's device key, so they are exercisable by the provisioner or network administrator that owns the node, reachable over the Bluetooth Mesh network. With the default CONFIG_MBEDTLS_PSA_KEY_SLOT_COUNT of 16, repeated add/delete or key-refresh cycles exhaust the shared PSA key-slot pool after roughly a dozen rounds. Once exhausted, bt_mesh_private_beacon_key() and thus subnet creation fail: the node can no longer add subnets or complete key refresh, and other PSA crypto consumers on the device may be starved, until the device is rebooted. The fix aligns the destroy guard with the import guard (CONFIG_BT_MESH_PRIV_BEACONS) so each slot is freed.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.