Comparison Overview
CSN - Companhia Siderúrgica Nacional

CSN - Companhia Siderúrgica Nacional
Av. Brig. Faria Lima, 3400 - 20º andar - Itaim Bibi, São Paulo, 04538-132, BR
Last Update: 03/04/2026
Fundada em 1941, a CSN representa um marco no processo de industrialização do Brasil. O seu aço viabilizou a implantação das primeiras indústrias nacionais, núcleo do atual parque fabril brasileiro. Ao longo de mais de oito décadas, a CSN segue fazendo história, sendo h...

ArcelorMittal Nippon Steel India
27 km, Surat-Hazira Road , Surat, 394270, IN
Last Update: 03/04/2026
AM/NS India is a joint venture between the world's leading steel companies, ArcelorMittal and Nippon Steel. Established in December 2019, post-acquisition of Essar Steel, we are an integrated flat steel manufacturer - from iron ore to ready-to-market products. With over...
Compliance Ranges Comparison

CSN - Companhia Siderúrgica Nacional







ArcelorMittal Nippon Steel India






Benchmark & Cyber Underwriting Signals
Incidents vs Mining Industry Avg (This Year)
No incidents recorded for CSN - Companhia Siderúrgica Nacional in 2026.
Incidents vs Mining Industry Avg (This Year)
No incidents recorded for ArcelorMittal Nippon Steel India in 2026.
Incident History - CSN - Companhia Siderúrgica Nacional (X = Date, Y = Severity)
CSN - Companhia Siderúrgica Nacional cyber incidents detection timeline including parent company and subsidiaries.
Incident History - ArcelorMittal Nippon Steel India (X = Date, Y = Severity)
ArcelorMittal Nippon Steel India cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

CSN - Companhia Siderúrgica Nacional

ArcelorMittal Nippon Steel India
FAQ
Latest Global CVEs
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the owner has reused across multiple agents. The deletion removes the file globally — not just from the shared agent — breaking the owner's other private agents that reference the same `file_id`. The private agent retains a stale `file_id` reference that no longer resolves. A shared-agent editor can destroy files that the owner uses across multiple agents. The owner's private agents — which the attacker has no access to — break silently with stale `file_id` references. This is a cross-agent integrity violation: editing access to one agent should not affect another. Version 0.8.4 contains a patch.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` and `GET /api/mcp/servers/:serverName`. The returned config includes plaintext values for `apiKey.key` and `oauth.client_secret`. This allows viewers of a shared MCP server to exfiltrate the underlying provider credentials. Version 0.8..4 contains a patch. Other remediations include: never returning decrypted admin-managed secrets to non-owners; redacting apiKey.key and oauth.client_secret from all API responses consider returning only boolean presence indicators for secrets, similar to the auth-values route pattern; and, if owners need to edit configs without re-entering secrets, preserving secrets server-side and returning placeholders instead of plaintext.
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP client (`simpleHttpClient`) into every extension script's scope. The `postFileAndSaveResponse()` method accepts an arbitrary filesystem path as its `file` parameter and reads the file contents using `new FileInputStream(file)` with no path validation, directory restriction, or allowlist. A malicious extension script can read any file accessible to the JVM process user and exfiltrate it to an attacker-controlled server via HTTP POST. Version 2.0-M5-2606 patches the issue.