Comparison Overview
Cirium Japan (シリウム)

Cirium Japan (シリウム)
東麻布1-9-15, 東麻布1丁目ビル7階, 港区, 東京都, JP, 106-0044
Last Update: 12/01/2026
Ciriumは「航空業界・旅行業界は、知識と情報を効率的に共有することによってさらなる力をつけることができる」という考え方から出発しました。 現在、Ciriumは世界中の金融、 航空宇宙、旅行、政府機関、航空会社をはじめとした各業界のリーダーに、データと分析ソリューションを提供しています。スケジュールや飛行ルートはもちろん、機材仕様や乗客記録番号まで、300テラバイト以上ものすべてを網羅したデータを日々管理しているのです。 https://www.youtube.com/watch?v=_tR8VXlzWvo

Iberia
Calle Martínez Villergas 49, Madrid, 28027, ES
Last Update: 12/09/2026
Iberia is Spain’s number-one airline group and the leader in the Europe-Latin America market, with the single greatest array of destinations and flight frequencies. Together with British Airways, we’re part of the IAG Group, with the third-highest receipts in Europe and...
Compliance Ranges Comparison

Cirium Japan (シリウム)







Iberia






Benchmark & Cyber Underwriting Signals
Incidents vs Airlines and Aviation Industry Avg (This Year)
No incidents recorded for Cirium Japan (シリウム) in 2026.
Incidents vs Airlines and Aviation Industry Avg (This Year)
Iberia has 96.08% more incidents than the average of all companies with at least one recorded incident.
Incident History - Cirium Japan (シリウム) (X = Date, Y = Severity)
Cirium Japan (シリウム) cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Iberia (X = Date, Y = Severity)
Iberia cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Cirium Japan (シリウム)

Iberia
FAQ
Latest Global CVEs
A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. Fix suggestion's "streaming/size-limit" was never shipped - latest 2026.9.5 still buffers the whole file via readFile() (src/canvas/serve.runtime.ts:17,114), unlike the sibling WS path which caps at 64KB. The vendor was contacted early about this disclosure.
A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. In v2.9.0 the PyTorch tensor load path is hardened (weights_only=True), but that hardening was later reverted on master via PR #1913 "Hotfix: revert loading with weights_only=True" [blocked] to fix PyTorch 1.13 compat - so even the one "safe" path is inconsistent across versions. #2281 was closed as a duplicate of #1831 since both are unsafe pickle deserialization - but #1831's fix (PR #41) only gated the Hugging Face Hub loader in the separate huggingface_sb3 package. This finding covers the core stable_baselines3 load APIs (PPO.load, load_replay_buffer, VecNormalize.load), which have no safe mode or gate and remained exploitable in v2.9.0 until the outstanding hardening (PR #2264) ships.
A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Maintainer closed #3663 same-day with no comment, PR, or fix; repo's last push (2025-11-01) predates the report, so the unsafe pickle.load in SaveLoad.load remains unguarded at develop HEAD.
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue.