Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

CARB-XCARB-X
VS
Thermo Fisher ScientificThermo Fisher Scientific
CARB-X

CARB-X

undefined, Boston, MA, undefined, undefined

Last Update: 18/02/2026

View Profile
Between 700 and 749
http://www.carb-x.org
749/1000Moderate

CARB-X (Combating Antibiotic Resistant Bacteria Biopharmaceutical Accelerator) is a global non-profit partnership dedicated to accelerating early development antibacterial R&D to address the rising global threat of drug-resistant bacteria. CARB-X is led by Boston Univer...

NAICS:541714
NAICS Definition:Research and Development in Biotechnology (except Nanobiotechnology)
Employees:33
Subsidiaries:31
12-month incidents
0
Known data breaches
0
Attack type number
0
Thermo Fisher Scientific

Thermo Fisher Scientific

168 Third Avenue, Waltham, MA, US

Last Update: 01/04/2026

View Profile
Between 800 and 849
https://www.thermofisher.com
825/1000Good

About Thermo Fisher Scientific Thermo Fisher Scientific Inc. is the world leader in serving science, with annual revenue of approximately $40 billion. Our Mission is to enable our customers to make the world healthier, cleaner and safer. Whether our customers are accele...

NAICS:541714
NAICS Definition:Research and Development in Biotechnology (except Nanobiotechnology)
Employees:99,125
Subsidiaries:18
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Ranges Comparison

Based On Specific Ai Models Category
CARB-X

CARB-X

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Thermo Fisher Scientific

Thermo Fisher Scientific

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Biotechnology Research Industry Avg (This Year)

No incidents recorded for CARB-X in 2026.

Incidents

Incidents vs Biotechnology Research Industry Avg (This Year)

No incidents recorded for Thermo Fisher Scientific in 2026.

Incidents

Incident History - CARB-X (X = Date, Y = Severity)

CARB-X cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Thermo Fisher Scientific (X = Date, Y = Severity)

Thermo Fisher Scientific cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
CARB-X

CARB-X

Incidents
No explicit notable incidents reported.
Thermo Fisher Scientific

Thermo Fisher Scientific

Incidents
🔒 Incident : Breach
THE206072925

FAQ

Between CARB-X company and Thermo Fisher Scientific company, which one has the best AI Cybersecurity Score ?
Between CARB-X company and Thermo Fisher Scientific company, which one has experienced more cyber incidents in the past ?
Between CARB-X company and Thermo Fisher Scientific company, which one has experienced more cyber incidents this year ?
Between CARB-X company and Thermo Fisher Scientific company, which one has experienced at least one ransomware attack ?
Between CARB-X company and Thermo Fisher Scientific company, which one has experienced at least one data breach ?
Between CARB-X company and Thermo Fisher Scientific company, which one has experienced at least one targeted cyberattack ?
Between CARB-X company and Thermo Fisher Scientific company, which one has experienced at least one vulnerability ?
Between CARB-X company and Thermo Fisher Scientific company, which one holds the most compliance certifications ?
Between CARB-X company and Thermo Fisher Scientific company, which one holds the fewest compliance certifications ?
Between CARB-X company and Thermo Fisher Scientific company, which one has the most subsidiaries ?
Between CARB-X company and Thermo Fisher Scientific company, which one has the largest number of employees ?
Between CARB-X and Thermo Fisher Scientific, which company holds both SOC 2 Type 1 certifications ?
Between CARB-X and Thermo Fisher Scientific, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - CARB-X or Thermo Fisher Scientific ?
Which company is PCI DSS compliant - CARB-X or Thermo Fisher Scientific ?
Between CARB-X and Thermo Fisher Scientific, which company complies with HIPAA regulations for healthcare data ?
Between CARB-X and Thermo Fisher Scientific, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-66339
SUMMARY

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.

PUBLISHED
Date2026-07-24
UPDATED
Date2026-07-24
RISK INFORMATION (Score: 6.5)
CVSS3
Base Score: 6.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
IMPACT SCORE
3.6
EXPLOITABILITY
2.8
CVE-2026-66338
SUMMARY

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.

PUBLISHED
Date2026-07-24
UPDATED
Date2026-07-24
RISK INFORMATION (Score: 5.4)
CVSS3
Base Score: 5.4
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
IMPACT SCORE
2.7
EXPLOITABILITY
2.2
CVE-2026-66337
SUMMARY

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.

PUBLISHED
Date2026-07-24
UPDATED
Date2026-07-24
RISK INFORMATION (Score: 6.5)
CVSS3
Base Score: 6.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
IMPACT SCORE
2.5
EXPLOITABILITY
3.9
CVE-2026-61892
SUMMARY

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

PUBLISHED
Date2026-07-24
UPDATED
Date2026-07-24
RISK INFORMATION (Score: 8.8)
CVSS3
Base Score: 8.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS4
Base Score: 8.7
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
2.8
CVE-2026-61886
SUMMARY

Weintek cMT3092X HMI stores user account passwords in plaintext.

PUBLISHED
Date2026-07-24
UPDATED
Date2026-07-24
RISK INFORMATION (Score: 6.5)
CVSS3
Base Score: 6.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS4
Base Score: 7.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.6
EXPLOITABILITY
2.8