Badge
11,371 badges added since 01 January 2025
ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Durant is a city in Bryan County, Oklahoma, United States and serves as the capital of the Choctaw Nation of Oklahoma. The population was 18,589 at the 2020 census. Durant is the principal city of the Durant Micropolitan Statistical Area, which had a population of 42,416 in 2010. Durant ranks as the second largest city within the Choctaw Nation, following McAlester, and ahead of Poteau. Durant is also part of the Dallas-Fort Worth Combined Statistical Area, anchoring the northern edge. The city was founded by Dixon Durant, a Choctaw who lived in the area,after the MK&T railroad came through the Indian Territory in the early 1870s. It became the county seat of Bryan County in 1907 after Oklahoma statehood. Durant is home to Southeastern Oklahoma State University and the headquarters of the Choctaw Nation. The city is officially known as the Magnolia Capital of Oklahoma. The city and its micropolitan are a major part of the Texoma region.

City of Durant A.I CyberSecurity Scoring

CD

Company Details

Linkedin ID:

city-of-durant-oklahoma

Employees number:

97

Number of followers:

268

NAICS:

92

Industry Type:

Government Administration

Homepage:

durant.org

IP Addresses:

0

Company ID:

CIT_9475623

Scan Status:

In-progress

AI scoreCD Risk Score (AI oriented)

Between 550 and 599

https://images.rankiteo.com/companyimages/city-of-durant-oklahoma.jpeg
CD Government Administration
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreCD Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/city-of-durant-oklahoma.jpeg
CD Government Administration
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

CD Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsSupply Chain SourceIncident DetailsView
City of Durant: Thousands impacted by cyberattacks on governments in Ohio, Oklahoma, Puerto RicoRansomware10051/2026NA
Rankiteo Explanation :
Attack threatening the organization's existence

Description: **Ransomware Attacks Disrupt Government Services in Ohio, Oklahoma, and Puerto Rico** Over the past week, cybercriminals launched ransomware attacks targeting government systems in Ohio, Oklahoma, and Puerto Rico, disrupting critical services for thousands of residents. In **Durant, Oklahoma**, a city of over 20,000 and the largest settlement on the Choctaw Nation reservation, officials confirmed a ransomware attack on Sunday. The city’s website remains offline, and digital payment systems are affected. While emergency services remain operational via 911, the police department reported network outages, leading to longer wait times. The incident follows a pattern of ransomware attacks on Native American governments this year, with the **RansomHub** gang claiming responsibility for previous strikes in Minnesota and Michigan. Meanwhile, **Lorain County, Ohio**, home to over 315,000 residents, disclosed a network security incident that forced multiple government systems offline. Courts were temporarily shut down, though emergency services remained available. The county has engaged cybersecurity experts to investigate the breach, which follows recent ransomware attacks on Cleveland Municipal Court and Columbus, Ohio, the latter exposing data of over 500,000 residents. In **Puerto Rico**, the Department of Justice and the Puerto Rico Innovation and Technology Service reported a cyberattack targeting the **Criminal Justice Information Office**. As a precaution, services—including criminal record certificate issuance—were suspended while authorities work to contain the breach. The FBI and CISA have not commented on their involvement, though both agencies previously assisted Puerto Rico in responding to a cyberattack on its water supply agency. The attacks highlight the ongoing vulnerability of municipal systems, with recovery efforts often spanning weeks or months. In **Abilene, Texas**, officials are still rebuilding infrastructure after an April ransomware attack, despite refusing to pay the ransom. The city faces potential data leaks of 477 GB of resident information.

City of Durant: Thousands impacted by cyberattacks on governments in Ohio, Oklahoma, Puerto Rico
Ransomware
Severity: 100
Impact: 5
Seen: 1/2026
Blog:
Supply Chain Source: NA
Rankiteo Explanation
Attack threatening the organization's existence

Description: **Ransomware Attacks Disrupt Government Services in Ohio, Oklahoma, and Puerto Rico** Over the past week, cybercriminals launched ransomware attacks targeting government systems in Ohio, Oklahoma, and Puerto Rico, disrupting critical services for thousands of residents. In **Durant, Oklahoma**, a city of over 20,000 and the largest settlement on the Choctaw Nation reservation, officials confirmed a ransomware attack on Sunday. The city’s website remains offline, and digital payment systems are affected. While emergency services remain operational via 911, the police department reported network outages, leading to longer wait times. The incident follows a pattern of ransomware attacks on Native American governments this year, with the **RansomHub** gang claiming responsibility for previous strikes in Minnesota and Michigan. Meanwhile, **Lorain County, Ohio**, home to over 315,000 residents, disclosed a network security incident that forced multiple government systems offline. Courts were temporarily shut down, though emergency services remained available. The county has engaged cybersecurity experts to investigate the breach, which follows recent ransomware attacks on Cleveland Municipal Court and Columbus, Ohio, the latter exposing data of over 500,000 residents. In **Puerto Rico**, the Department of Justice and the Puerto Rico Innovation and Technology Service reported a cyberattack targeting the **Criminal Justice Information Office**. As a precaution, services—including criminal record certificate issuance—were suspended while authorities work to contain the breach. The FBI and CISA have not commented on their involvement, though both agencies previously assisted Puerto Rico in responding to a cyberattack on its water supply agency. The attacks highlight the ongoing vulnerability of municipal systems, with recovery efforts often spanning weeks or months. In **Abilene, Texas**, officials are still rebuilding infrastructure after an April ransomware attack, despite refusing to pay the ransom. The city faces potential data leaks of 477 GB of resident information.

Ailogo

CD Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for CD

Incidents vs Government Administration Industry Average (This Year)

City of Durant has 50.0% fewer incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

City of Durant has 27.01% fewer incidents than the average of all companies with at least one recorded incident.

Incident Types CD vs Government Administration Industry Avg (This Year)

City of Durant reported 1 incidents this year: 0 cyber attacks, 1 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — CD (X = Date, Y = Severity)

CD cyber incidents detection timeline including parent company and subsidiaries

CD Company Subsidiaries

SubsidiaryImage

Durant is a city in Bryan County, Oklahoma, United States and serves as the capital of the Choctaw Nation of Oklahoma. The population was 18,589 at the 2020 census. Durant is the principal city of the Durant Micropolitan Statistical Area, which had a population of 42,416 in 2010. Durant ranks as the second largest city within the Choctaw Nation, following McAlester, and ahead of Poteau. Durant is also part of the Dallas-Fort Worth Combined Statistical Area, anchoring the northern edge. The city was founded by Dixon Durant, a Choctaw who lived in the area,after the MK&T railroad came through the Indian Territory in the early 1870s. It became the county seat of Bryan County in 1907 after Oklahoma statehood. Durant is home to Southeastern Oklahoma State University and the headquarters of the Choctaw Nation. The city is officially known as the Magnolia Capital of Oklahoma. The city and its micropolitan are a major part of the Texoma region.

Loading...
similarCompanies

CD Similar Companies

National Park Service

Most people know that the National Park Service cares for national parks, a network of over 420 natural, cultural and recreational sites across the nation. The treasures in this system – the first of its kind in the world – have been set aside by the American people to preserve, protect, and share t

Swiss Federal Administration

Working for Switzerland Seven departments, the Federal Chancellery and around 70 administrative units make up the Federal Administration. With around 38,000 employees, it is one of the largest employers in Switzerland. People from all regions of the country work in the Federal Administration un

State of Michigan

Every day the contributions and achievements of State of Michigan employees have a direct impact on over 10 million Michiganders across the state. If you're looking for a fulfilling career in state government that can make a real difference in the lives of others, you can find your place working wit

Council Careers Victoria

Victorian local government jobs offer opportunities for people with diverse skills. The sector delivers more than 100 services and employs staff in the areas of health and community care, corporate and business support, engineering, planning and community development, and environment and emergency m

Comunidad de Madrid

Si necesitas información general y especializada sobre los servicios públicos madrileños puedes llamar al teléfono de Atención al Ciudadano 012. En la Comunidad de Madrid estamos encantados de recibir comentarios y favorecer el diálogo, por eso te proponemos unas normas básicas de participación:

UK Home Office

At the Home Office, we help to ensure that the country is safe and secure. We’ve been looking after UK citizens since 1782. We are responsible for: - working on the problems caused by illegal drug use - shaping the alcohol strategy, policy and licensing conditions - keeping the United Kingdom safe

Queensland Government

We are the largest and most diverse organisation in our state. We have more than 90 government departments and organisations providing essential services across 4000+ locations—from the Torres Strait to the Gold Coast; Mount Isa to Brisbane. We are passionate about making Queensland better through

State of Oregon

Official LinkedIn page for the state of Oregon. Oregon is a state in the Pacific Northwest region of the United States. It is located on the Pacific coast, with Washington to the north, California to the south, Nevada on the southeast and Idaho to the east. The Columbia and Snake rivers delineate mu

City of Los Angeles

The City of Los Angeles employs more than 45,000 people in a wide range of careers. Visit our website for information on current openings, including regular civil service positions, exempt and emergency appointment opportunities, in addition to internships! The City of Los Angeles is a Mayor-Counci

newsone

CD CyberSecurity News

November 21, 2025 08:00 AM
Local law enforcement agencies in Oklahoma, Massachusetts responding to cyber incidents

A county sheriff's office in Oklahoma and a police department in Massachusetts said their networks were recently disrupted by cybersecurity...

November 03, 2025 08:00 AM
Healey wants mandatory reporting of municipal cyberattacks. 2 Cape towns hit in January.

Cities and towns would be required under a plan from Gov. Maura Healey to let the state know of any cybersecurity incidents like hacks and...

July 15, 2025 07:00 AM
Durant updates residents on June ransomware attack

The city is encouraging residents to watch their accounts, report suspicious activity and consider putting a fraud alert on their credit...

June 09, 2025 07:00 AM
9th June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 9th June, please download our Threat Intelligence Bulletin.

June 04, 2025 07:00 AM
Separate cyberattacks impact Ohio, Oklahoma, Puerto Rico

Ohio, Oklahoma, and Puerto Rico had government systems disrupted by cyberattacks during the past week, reports The Record, a news site by...

June 03, 2025 07:00 AM
Thousands impacted by cyberattacks on governments in Ohio, Oklahoma, Puerto Rico

Cybercriminals targeted government systems in Ohio, Oklahoma and Puerto Rico over the past week, limiting critical services for thousands.

June 02, 2025 07:00 AM
Durant targeted by ransomware attack, some services impacted

The city said that some services, including digital and credit card payments, are still impacted by the attack.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

CD CyberSecurity History Information

Official Website of City of Durant

The official website of City of Durant is http://www.durant.org.

City of Durant’s AI-Generated Cybersecurity Score

According to Rankiteo, City of Durant’s AI-generated cybersecurity score is 584, reflecting their Very Poor security posture.

How many security badges does City of Durant’ have ?

According to Rankiteo, City of Durant currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Has City of Durant been affected by any supply chain cyber incidents ?

According to Rankiteo, City of Durant has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.

Does City of Durant have SOC 2 Type 1 certification ?

According to Rankiteo, City of Durant is not certified under SOC 2 Type 1.

Does City of Durant have SOC 2 Type 2 certification ?

According to Rankiteo, City of Durant does not hold a SOC 2 Type 2 certification.

Does City of Durant comply with GDPR ?

According to Rankiteo, City of Durant is not listed as GDPR compliant.

Does City of Durant have PCI DSS certification ?

According to Rankiteo, City of Durant does not currently maintain PCI DSS compliance.

Does City of Durant comply with HIPAA ?

According to Rankiteo, City of Durant is not compliant with HIPAA regulations.

Does City of Durant have ISO 27001 certification ?

According to Rankiteo,City of Durant is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of City of Durant

City of Durant operates primarily in the Government Administration industry.

Number of Employees at City of Durant

City of Durant employs approximately 97 people worldwide.

Subsidiaries Owned by City of Durant

City of Durant presently has no subsidiaries across any sectors.

City of Durant’s LinkedIn Followers

City of Durant’s official LinkedIn profile has approximately 268 followers.

NAICS Classification of City of Durant

City of Durant is classified under the NAICS code 92, which corresponds to Public Administration.

City of Durant’s Presence on Crunchbase

No, City of Durant does not have a profile on Crunchbase.

City of Durant’s Presence on LinkedIn

Yes, City of Durant maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/city-of-durant-oklahoma.

Cybersecurity Incidents Involving City of Durant

As of January 06, 2026, Rankiteo reports that City of Durant has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

City of Durant has an estimated 11,806 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at City of Durant ?

Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.

How does City of Durant detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with cybersecurity experts (lorain county), and law enforcement notified with yes (durant), and containment measures with systems taken offline, containment measures with protocols initiated to contain the attack, and remediation measures with replacing network infrastructure (abilene), and communication strategy with social media updates, communication strategy with public advisories..

Incident Details

Can you provide details on each incident ?

Incident : Ransomware

Title: Ransomware Attacks on Government Systems in Ohio, Oklahoma, and Puerto Rico

Description: Cybercriminals targeted government systems in Ohio, Oklahoma, and Puerto Rico over the past week, limiting critical services for thousands. The city of Durant, Oklahoma, was hit with ransomware, causing its website to go down and impacting digital and credit card payments. Lorain County, Ohio, experienced a network security incident knocking dozens of government systems offline, while Puerto Rico's Justice Department reported a cyberattack affecting the Criminal Justice Information Office.

Type: Ransomware

Threat Actor: RansomHub ransomware gang

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Impact of the Incidents

What was the impact of each incident ?

Incident : Ransomware CIT1767304505

Data Compromised: 477 GB of data (Abilene, TX)

Systems Affected: websitesdigital and credit card paymentscourt systemscriminal record certificate issuance

Operational Impact: Extended wait times for emergency services, court closures, temporary suspension of services

Identity Theft Risk: Exposure of information of over 500,000 residents (Columbus, OH)

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information, Criminal Records and .

Which entities were affected by each incident ?

Incident : Ransomware CIT1767304505

Entity Name: City of Durant

Entity Type: Municipal Government

Industry: Government

Location: Durant, Oklahoma, USA

Size: 20,000+ residents

Customers Affected: 20,000+ residents

Incident : Ransomware CIT1767304505

Entity Name: Lorain County

Entity Type: County Government

Industry: Government

Location: Lorain County, Ohio, USA

Size: 315,000+ residents

Customers Affected: 315,000+ residents

Incident : Ransomware CIT1767304505

Entity Name: Puerto Rico Department of Justice

Entity Type: State Government

Industry: Government

Location: Puerto Rico

Incident : Ransomware CIT1767304505

Entity Name: City of Abilene

Entity Type: Municipal Government

Industry: Government

Location: Abilene, Texas, USA

Size: 130,000 residents

Customers Affected: 130,000 residents

Incident : Ransomware CIT1767304505

Entity Name: Cleveland Municipal Court

Entity Type: Municipal Government

Industry: Government

Location: Cleveland, Ohio, USA

Incident : Ransomware CIT1767304505

Entity Name: City of Columbus

Entity Type: Municipal Government

Industry: Government

Location: Columbus, Ohio, USA

Size: 500,000+ current and former residents

Customers Affected: 500,000+ current and former residents

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Ransomware CIT1767304505

Third Party Assistance: Cybersecurity experts (Lorain County)

Law Enforcement Notified: Yes (Durant)

Containment Measures: Systems taken offlineProtocols initiated to contain the attack

Remediation Measures: Replacing network infrastructure (Abilene)

Communication Strategy: Social media updatesPublic advisories

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through Cybersecurity experts (Lorain County).

Data Breach Information

What type of data was compromised in each breach ?

Incident : Ransomware CIT1767304505

Type of Data Compromised: Personally identifiable information, Criminal records

Number of Records Exposed: 500,000+ (Columbus, OH)

Sensitivity of Data: High

Data Exfiltration: 477 GB (Abilene, TX)

Data Encryption: Yes (Ransomware)

Personally Identifiable Information: Yes

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Replacing network infrastructure (Abilene), .

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by systems taken offline, protocols initiated to contain the attack and .

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Ransomware CIT1767304505

Ransom Paid: No (Abilene)

Ransomware Strain: RansomHub

Data Encryption: Yes

Data Exfiltration: Yes (477 GB, Abilene)

References

Where can I find more information about each incident ?

Incident : Ransomware CIT1767304505

Source: City of Durant Facebook

Incident : Ransomware CIT1767304505

Source: Lorain County Social Media Warnings

Incident : Ransomware CIT1767304505

Source: Puerto Rico Justice Department Statement

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: City of Durant Facebook, and Source: Lorain County Social Media Warnings, and Source: Puerto Rico Justice Department Statement.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Ransomware CIT1767304505

Investigation Status: Ongoing

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Social Media Updates and Public Advisories.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Ransomware CIT1767304505

Customer Advisories: Social media updatesPublic notices

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Social Media Updates, Public Notices and .

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Ransomware CIT1767304505

Corrective Actions: Replacing Network Infrastructure (Abilene),

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Cybersecurity experts (Lorain County).

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Replacing Network Infrastructure (Abilene), .

Additional Questions

General Information

Has the company ever paid ransoms ?

Ransom Payment History: The company has Paid ransoms in the past.

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an RansomHub ransomware gang.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were 477 GB of data (Abilene and TX).

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was websitesdigital and credit card paymentscourt systemscriminal record certificate issuance.

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Cybersecurity experts (Lorain County).

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Systems taken offlineProtocols initiated to contain the attack.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 477 GB of data (Abilene and TX).

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 500.0K.

Ransomware Information

What was the highest ransom paid in a ransomware incident ?

Highest Ransom Paid: The highest ransom paid in a ransomware incident was No (Abilene).

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Puerto Rico Justice Department Statement, City of Durant Facebook and Lorain County Social Media Warnings.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

Stakeholder and Customer Advisories

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an Social media updatesPublic notices.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Albums.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. This issue is fixed in version 3.13.3.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Multiple D-Link DSL gateway devices contain a command injection vulnerability in the dnscfg.cgi endpoint due to improper sanitization of user-supplied DNS configuration parameters. An unauthenticated remote attacker can inject and execute arbitrary shell commands, resulting in remote code execution. The affected endpoint is also associated with unauthenticated DNS modification (“DNSChanger”) behavior documented by D-Link, which reported active exploitation campaigns targeting firmware variants of the DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B models from 2016 through 2019. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC). Affected devices were declared end-of-life/end-of-service in early 2020.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=city-of-durant-oklahoma' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge