Cinnabon A.I CyberSecurity Scoring
05/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Cinnabon in 2026.
No incidents recorded for Cinnabon in 2026.
No incidents recorded for Cinnabon in 2026.
Food and Beverage Services
Every day, millions of people throughout the world consume foods and beverages containing Kerry’s taste and nutrition solutions. We are committed to making the world of food and beverage better for everyone, and dedicated to our Purpose, Inspiring Food, Nourishing Life. At Kerry, we are proud to provide our customers – some of the world’s best-known food, beverage and pharma brands – with the expertise, insights and know-how they need to deliver products that people enjoy and feel better about consuming. Kerry is a company rich in heritage and resources. Over the past five decades, our focus on changing lifestyles, the globalisation of food tastes and ever-evolving consumer needs has brought us to a market-leading global position. Today, we are firmly established as a world leader in the food, beverage and pharma industries, with 22,000+ staff and 150+ innovation and manufacturing centres across 30+ countries. Learn more about Kerry: www.kerry.com
Atlanta-based platform company GoTo Foods (formerly known as Focus Brands) is a leading developer of global multi-channel foodservice brands. As of December 28 , 2025, GoTo Foods, through its affiliate brands, is the franchisor and operator of over 7,300 restaurants, cafes, ice cream shoppes and bakeries in all 50 states and in 71 countries and territories under the Auntie Anne’s®, Carvel®, Cinnabon®, Jamba®, Moe’s Southwest Grill®, McAlister’s Deli® and Schlotzsky’s® brand names, as well as the Seattle’s Best Coffee® brand on certain military bases and in certain international markets. The iconic GoTo Foods brands benefit from strong enterprise growth engines, including marketing, digital, technology and franchise sales & development to propel growth and brand performance. Please visit www.gotofoods.com to learn more. GoTo Foods is proud to be Certified™ by Great Place To Work®, the most definitive “employer-of-choice” recognition, and the only recognition based entirely on what employees report about their workplace experience for the second consecutive year.
We are a global food company dedicated to bringing local favorite foods to communities everywhere. Within 17 countries, we offer quality branded food at a range of price points and across diverse categories. We're a company dedicated to the production, distribution and sales of refrigerated and frozen products such as cold meats, dry meats, cheese, yogurt, prepared meals and beverages. We have a strong diversified portfolio of well-positioned brands that market in the countries where we participate. We operate in 64 production plants, serving more than 670,000 customers in North, Central, South America, the Caribbean and Europe. We strive for excellence in everything we do. We're passionate about innovation and our consumers; we're committed in bringing them the best quality and taste in every product. The passion and effort we invest in our work is the reason we're on the road to success.
Founded in 1977, Almarai Company is the world’s largest vertically integrated dairy company and the largest food and beverage manufacturing and distribution company in MENA. Headquartered in Riyadh, Almarai Company is ranked as the number one FMCG Brand in the MENA region and the market leader in all its categories across GCC, Egypt, and Jordan. Over five decades of sustainable growth, Almarai has consistently provided nutritious and healthy products to consumers of all ages, driven by its core principle: “Quality you can trust.” Almarai has expanded its product range to include, in addition to dairy products, juices and beverages, baked goods, poultry, infant formula, dates, fish and seafood, and bottled water, under more than 20 brands such as Almarai, L’usine, 7DAYS, ALYOUM, Nuralac, Farm’s Select, Ice Leaf, Almira, Seama, Oska, IVAL, Almarai Pro, Premier Chef, Bakemart, and others. In 2024, Almarai reported net income of SAR 2.31 billion on sales of SAR 20.98 billion. For more information, please visit our website.
HMSHost is recognized by the industry as the leader in travel dining with awards such as Restaurateur with the Highest Regard for Customer Service and Best Brand Restaurateur for Shake Shack by Airport Experience News. USA Today 10Best Readers’ Choice Travel Awards gave first place honors to both of HMSHost’s Whisky River locations at Charlotte Douglas International Airport and Raleigh-Durham International Airport. ACI-NA, the trade association representing commercial service airports in the United States and Canada, recognized HMSHost with the 2020 Inclusion Champion Award, for leadership and achievement in the ongoing inclusion of business and workforce diversity, outreach, and advocacy. The company also creates original award-winning events and campaigns including Airport Restaurant Month, Channel Your Inner Chef live culinary contest, 1,000 Acts of Kindness, and Eat Well. Travel Further. For careers, text HMSHost to 97211 or visit us at careers.hmshost.com
PRAN RFL Group, one of the most reputed conglomerates in Bangladesh, is in market since 1981. It started mainly with Foundry business and gradually diversified to Light Engineering, PVC Fittings, Plastics, Food and Beverage and Agro-Processing. It has it's marketing and selling network in 145 countries as of date.Group directly employs over 1,25,000 people and another 15,00,000 over people subsists on PRAN-RFL Group.
Keurig Dr Pepper (KDP) is a leading beverage company in North America, with annual revenue in excess of $14.1 billion and nearly 28,000 employees. KDP holds leadership positions in soft drinks, specialty coffee and tea, water, juice and juice drinks and mixers, and markets the #1 single serve coffee brewing system in the U.S. and Canada. The Company’s portfolio of more than 125 owned, licensed and partner brands is designed to satisfy virtually any consumer need, any time, and includes Keurig®, Dr Pepper®, Green Mountain Coffee Roasters®, Canada Dry®, Snapple®, Bai®, Mott's®, CORE® and The Original Donut Shop®. Through its powerful sales and distribution network, KDP can deliver its portfolio of hot and cold beverages to nearly every point of purchase for consumers. The Company is committed to sourcing, producing and distributing its beverages responsibly through its Drink Well. Do Good. corporate responsibility platform, including efforts around circular packaging, efficient natural resource use and supply chain sustainability. For more information, visit, www.keurigdrpepper.com.
HEINEKEN - the world's most international brewer. It is the leading developer and marketer of premium beer and cider brands. Led by the Heineken® brand, the Group has a portfolio of more than 500 international, regional, local, and speciality beers and ciders. We are committed to innovation, long-term brand investment, disciplined sales execution and focused cost management. Through our "Brew a Better World" strategy, sustainability is embedded in the business and delivers value for all stakeholders. HEINEKEN has a well-balanced geographic footprint with leadership positions in both developed and developing markets. We employ over 85,000 employees and operate breweries, malteries, cider plants and other production facilities in more than 70 countries. Stay informed: https://www.theheinekencompany.com/newsroom Please enjoy our brands responsibly and only share our posts with those who are of legal drinking age.
We believe every consumer should have access to their favorite snack, everywhere. We own the manufacturing process from seed to shelf and actively invest in technology to automate key steps of the process. This helps us be more agile in what we need to make, who we need to make it for, and how we can best deliver it to snack lovers from coast to coast.
Latest updates, reports, and threat intel affecting the global network.
Cinnabon has unveiled its first online gifting ecommerce platform. The platform allows customers to order a range of gift packs, which will be delivered with...
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_SSL_CID_OUT_LEN_MAX) into that buffer without a destination-size parameter, so a caller-supplied optlen smaller than the CID causes a write of up to 31 bytes past the buffer end. In CONFIG_USERSPACE builds the getsockopt syscall verifier (z_vrfy_zsock_getsockopt) bounce-buffers the user's optval into a kernel allocation of exactly optlen bytes (k_usermode_alloc_from_copy -> z_thread_malloc), so an unprivileged user thread that passes a small optlen on a connected DTLS socket with Connection ID enabled induces a kernel-heap buffer overflow, with the overflowing content being the remote peer's CID. The defect requires CONFIG_MBEDTLS_SSL_DTLS_CONNECTION_ID, an established DTLS session with a negotiated peer CID, and (for the kernel-crossing case) CONFIG_USERSPACE. Introduced when the TLS_DTLS_CID option was added (v3.5.0). The fix rejects callers whose optlen is below MBEDTLS_SSL_CID_OUT_LEN_MAX with -EINVAL.
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-19 01:07:01 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity since 2026-05-19 01:07:01, and clean local clones.
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote ctx.fds[ctx.nfds] and incremented ctx.nfds with no bounds check. Two independent paths mutate ctx concurrently: the background autohandler running on the system workqueue, and user-triggered operations reached through the updatehub run shell command, direct API calls, or — since the operations are exposed as syscalls — userspace threads. When a second flow enters prepare_fds() while ctx.nfds is already 1, the write lands one element past the array; by struct layout it overlaps the adjacent ctx.sock/ctx.nfds members. More broadly, the unsynchronized sharing lets two flows interleave connection setup and teardown, double-closing a socket descriptor or scribbling the shared buffers. The result is corruption of the update subsystem's internal state and denial of service of the firmware-update path; the out-of-bounds write is contained within the ctx structure and there is no demonstrated path to memory outside it or to code execution. Triggering requires a local actor able to invoke update operations (or, with CONFIG_USERSPACE, an unprivileged userspace thread) and to win a timing race against the background handler; remote peers cannot control the race timing. The fix serializes the entry points with a mutex and adds a bounds check to prepare_fds().
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.