CRU A.I CyberSecurity Scoring
12/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Colas Rail UK in 2026.
No incidents recorded for Colas Rail UK in 2026.
No incidents recorded for Colas Rail UK in 2026.
Latest updates, reports, and threat intel affecting the global network.
Colas Rail UK, working on behalf of Coventry City Council, has announced the completion of the on-road test track for the Coventry Very...
Colas Rail UK delivers Coventry's 220-metre CVLR track on time, showcasing rapid, sustainable light rail construction for future urban mobility.
The South Rail Systems Alliance made history by renewing the Severn Tunnel's track in a single 16-day possession, a rail industry first.
Colas Rail UK has added two new advanced Tampers to its fleet, highlighting its commitment to modern technology.
Rail infrastructure and freight company Colas Rail UK has added two new tampers from Plasser & Theurer (P&T) to its fleet to assist its work with Network Rail.
London's Waterloo station is one of the busiest railway stations in the UK, which provides more than half a million passenger journeys a day...
Operating and maintaining six rail grinding machines, Colas Rail will deliver almost 1400 operational shifts a year, in a 24/7 operation.
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.