
Chess Electrics
Strong
Electrical Contractor
Strong
Electrical Contractor
Strong
Aperam is a world-leading stainless steel company with sustainability at its heart. Since its launch in 2011, Aperam has become an undisputable global player in stainless, electrical, and specialty steel. With a flat stainless and electrical steel production capacity of 2.5 million tonnes in Brazil and Europe, Aperam has customers in over 40 countries. This success is the result of a community of 12,000 employees who are working hard to make Aperam consistently better. Together, the company and its people are embracing sustainable development, a factor that is at the very heart of Aperamโรรดs strategy of providing steel and alloy solutions that are affordable, and long-lasting, and that offers the strength, versatility, and endless recyclability needed to build a sustainable society. With its new Recycling and Renewables segment (BioEnergia, ELG, Recyco), Aperam has put itself at the forefront of the circular economy. In Europe, its production processes use about 90% scrap metal. Aperam is also unique as it is producing charcoal from its own FSCยฌร-certified forestry in Brazil, which is then used in the steel-making process as a natural and renewable substitute for fossil fuels. Today, around 30% of Aperamโรรดs workforce create value from working in Recycling and Renewables upstream. Aperam is also committed to making its products both sustainably and safely. Thanks to efforts like these, which go above and beyond what is required, Aperamโรรดs CO2 footprint ranks as sector leading, and its overall sustainability performance consistently receives top ratings from external analysts. If you want to learn more about our business, products or how we operate, please visit www.aperam.com.
Security & Compliance Standards Overview
No incidents recorded for Chess Electrics in 2025.
No incidents recorded for Aperam in 2025.
Chess Electrics cyber incidents detection timeline including parent company and subsidiaries
Aperam cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platform resulting in a loss of confidentiality.
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. Users can view all hints for free, undermining the business logic of the platform and reducing the integrity of the challenge system. This issue has been patched in version 2.3.0.
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privilege escalation and impersonation of administrative roles. This issue has been patched in version 2.2.0.
parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.