FSSS A.I CyberSecurity Scoring
01/02/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Flexaseal Seal Support Systems in 2026.
No incidents recorded for Flexaseal Seal Support Systems in 2026.
No incidents recorded for Flexaseal Seal Support Systems in 2026.
Pioneering positive impact! Our pioneering 140-year-old start-up culture is built on the idea that partnership is the key to solving complex problems and unlocking the full potential of resources. So we collaborate closely with our partners, customers, and thought leaders to create game-changing solutions that challenge conventional thinking on quality, efficiency, and innovation. United by a shared commitment to creating positive impact we’re reshaping vital industries, like energy, food, water, and shipping, to optimize efficiency, reduce emissions, and increase yields. Together, we’re building business success, elevating the quality of life across society, and driving progress towards a more sustainable world. Alfa Laval is a leading global provider of first-rate products in the areas of heat transfer, separation and fluid handling. With these as its base, Alfa Laval aims to help enhance the productivity and competitiveness of its customers in various industries throughout the world. We define their challenges and deliver sustainable products and solutions that meet their requirements. Alfa Laval today has customers in some 100 countries, employs more than 21,300 people, and annual sales were SEK 63.6 billion (5.5 BEUR) in 2023. The company is listed on Nasdaq Stockholm. Alfa Laval contributes to 15 of the 17 UN Sustainable Development Goals. Our solutions make a difference in daily life. You can learn more on our website about how our products work, and how they are used in industries worldwide. We welcome your engagement, comments and questions - our guidelines and moderation policy for Alfa Laval channels on social media can be found here: https://www.alfalaval.com/legal/community-guidelines/ Personal data will be handled in accordance with the Alfa Laval Privacy Policy. https://www.alfalaval.com/privacy
FLSmidth is a full flowsheet technology and service supplier to the global mining industry. We enable our customers to improve performance, lower operating costs and reduce environmental impact. MissionZero is our sustainability ambition towards zero emissions in mining by 2030. We work within fully validated Science-Based Targets, have a clear commitment to improving the sustainability performance of the global mining industry and aim to become carbon neutral in our own operations by 2030. FLSmidth is listed on NASDAQ OMX Exchange Copenhagen. #mining #FLS #MissionZero #EmpoweringTheFutureOfMining Privacy policy - https://fls.com/en/legal/privacy-policy
Established in 1949, the Liebherr Group today is not only one of the biggest construction equipment manufacturers in the world, but also offers high-quality, user-oriented products and services in many other areas. The family-run technology company employs nearly 50,000 people in over 150 companies worldwide. Liebherr’s product range includes the segments Earthmoving, Deep Foundation Machines, Mobile and Crawler Cranes, Tower Cranes, Concrete Technology, Material Handling Technology, Mining, Maritime Cranes, Aerospace and Transportation Systems, Gear Technology and Automation Systems, Refrigeration and Freezing, Components as well as Hotels in Ireland, Austria and Germany. The Group’s parent company is Liebherr-International AG located in Bulle, Switzerland, which is entirely owned by members of the Liebherr family. Career possibilities can be found online: https://www.liebherr.com/en/deu/career/career.html Imprint:https://www.liebherr.com/en-de/group/disclaimer/imprint-3705178
We are a global leader in innovative technologies and services shaping the decarbonisation of marine and energy. With approximately 6.9 billion euros in sales and 18,000 employees across 78 countries, the Wärtsilä strategy focuses on helping customers to continuously improve their environmental and economic performance. Wärtsilä is listed on Nasdaq Helsinki.
𝗪𝗲𝗹𝗰𝗼𝗺𝗲 𝘁𝗼 𝗧𝗞 𝗘𝗹𝗲𝘃𝗮𝘁𝗼𝗿 – 𝗪𝗵𝗲𝗿𝗲 𝗜𝗻𝗴𝗲𝗻𝘂𝗶𝘁𝘆 𝗘𝗹𝗲𝘃𝗮𝘁𝗲𝘀 𝗨𝗿𝗯𝗮𝗻 𝗟𝗶𝘃𝗶𝗻𝗴 Engineering pioneer. Global industry leader. TK Elevator draws on a legacy of firsts – from a groundbreaking vertical conveyor in 1890 – to evolve modern mobility. TKE blends safety, reliability, and innovation to create cutting-edge solutions that redefine how we move. Our dedicated teams engineer, manufacture, install, modernize, and service elevators, escalators, walkways, passenger boarding bridges, and residential lifts. Our German engineering heritage inspires our commitment to precision and fresh thinking, leading to a breakthrough elevator system incorporating two, independent passenger cars in the same shaft (TWIN), the first-ever cableless car design (MULTI), a forward-thinking eco-efficient and digitally native elevator system (EOX), and a novel suite of IoT-driven digital solutions that provide real-time insights, virtual repairs, and personalized control (MAX and AGILE). Our tailored products meet diverse needs – from commercial spaces to residential complexes – and include iconic projects like One World Trade Center in New York City, Madrid's new subway lines, and the BMW Tower and Google's German headquarters in Munich. With a global footprint spanning 1,000 locations and customers in over 100 countries, TKE delivers top-level, 24/7 service through 25,000 specialists expertly trained at our state-of-the-art International Technical Services SEED campus to provide Universal Service for any brand, any place, any time. Above all, we embrace responsibility to our planet. With sustainability at the heart of our business model, TKE is focused on improving accessibility and quality of life for a growing and aging population and doing so with lower emissions in our operations and solutions. Join us in shaping the future of sustainable urban mobility. TK Elevator – Move Beyond
Carrier is a global leader in intelligent climate and energy solutions, pioneering sustainable innovations in climate technologies. Founded by Willis Carrier, the inventor of modern air conditioning, we have been shaping industries and enhancing lives for more than a century. With approximately 48,000 employees across 160 countries and more than 35 trusted brands, Carrier serves customers through four business segments: Climate Solutions Americas, Climate Solutions Europe, Climate Solutions Asia Pacific, Middle East & Africa and Climate Solutions Transportation. Our solutions enable healthier, more efficient and more sustainable environments in homes and buildings, and help ensure the safe transportation of food, medicine and vaccines. Grounded in our purpose—we continue to lead through relentless innovation and a deep commitment to customer success, delivering cutting-edge solutions that bring comfort, safety and sustainability to life. Carrier. For the World We Share.
The Schindler Group is a leading manufacturer and provider of related services for elevators, escalators, and moving walkways. Founded in 1874 in Switzerland, our company is at the forefront of industry innovation, working on pushing the boundaries of technological engineering, while having a strong focus on safety, comfort, efficiency and reliability. Moving more than two billion people each day, our products can be found in many well-known buildings throughout the globe, including office and residential buildings, airports, shopping centers/retail establishments and specialty buildings. We’re a leading employer in the industry, with over 69’000 engaged employees enabling mobility within the urban world. We have a network of over 1000 branch offices in over 100 countries, as well as production sites and research and development facilities in the US, Brazil, Europe, China and India. At Schindler, our mission is to keep the world moving. We Elevate… Our World
Bilfinger is an international industrial services provider with a vision to be the No. 1 for its customers in enhancing efficiency and sustainability within the process industry. Bilfinger’s comprehensive portfolio spans the entire value chain, from consulting & engineering to prefabrication & installation, access & insulation, and services that improve the asset performance of industrial plants. The company operates in three geography-based segments: Western Europe, Central Europe, and International, with primary activities in Europe, North America, and the Middle East. Its process industry customers come from markets such as chemicals & petrochemicals, energy, oil & gas, and pharma & biopharma. With over 32,000 employees, Bilfinger upholds the highest standards of safety and quality, generating revenue of more than €5 billion in the financial year 2024. To achieve its goals, Bilfinger has identified two strategic levers: enhancing Operational Excellence to boost internal efficiency, and Market Expansion to strengthen customer focus and establish Bilfinger as the preferred partner. Imprint: https://www.bilfinger.com/en/imprint/ Data privacy: https://www.bilfinger.com/en/data-privacy/
GEA is one of the largest technology suppliers for food processing and a wide range of other industries. The global group specializes in machinery, plants, as well as process technology and components. GEA provides resource-efficient solutions for sophisticated production processes in diverse end-user markets and offers a comprehensive service portfolio.
Latest updates, reports, and threat intel affecting the global network.
A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling `__import__(module_path, ...)`. The module is imported — running its top-level code (import side effects) — before the framework checks that the resolved object is a `LiveView` subclass and before any per-view authentication. The `LIVEVIEW_ALLOWED_MODULES` allowlist that should contain this is fail-open (`if allowed_modules:` — skipped when the setting is unset, the framework default) and uses loose `startswith` matching. An unauthenticated WebSocket client (the WS handshake does not require auth; per-view auth runs only after import + instantiate) can therefore send a `mount` / `live_redirect_mount` / `url_change` frame (or an SSE mount) with `view = "<any.importable.module>.AnyName"` and cause the server to import — and execute the top-level code of — any importable Python module by name. Version 1.0.7 fixes the issue with a fail-closed resolution gate (`djust._view_resolution.is_view_import_allowed`): a client view path resolves only if (a) its module is already loaded (`sys.modules` — so resolving runs no new code; URL-routed views loaded by URLconf at startup keep working with zero config) or (b) it matches `LIVEVIEW_ALLOWED_MODULES` on a module-segment boundary (explicit opt-in for lazily-imported views). The gate runs before `__import__` at all three sinks (+ defense-in-depth inside `_instantiate_view`). As a workaround, set `LIVEVIEW_ALLOWED_MODULES` to the narrow list of modules that contain your mountable LiveView classes. (Note: pre-patch the allowlist is `startswith`-matched and the import still precedes the subclass check, so this is mitigation, not a complete fix.)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA `url_change` navigation, and (c) `{% live_render %}` embedded child views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views. This is fixed in djust 1.0.7. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns 403, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op). No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` on the live path while the HTTP path resolved correctly. With `STRICT_MODE=False` the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against `ALLOWED_HOSTS` (the same logic as the CSWSH Origin gate, parsed with Django's `split_domain_port` so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with `STRICT_MODE=False`.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Because exposing model objects to templates is a normal djust pattern, this could leak credentials/PII without the developer realizing the full object crossed the wire. This is fixed in djust 1.0.7. Model serialization applies a secure-by-default sensitive-field denylist (password/hash/token/secret-style fields and known privilege flags are withheld) with an identity-subset fallback. As a workaround, keep `Model` instances on `_private` attributes and expose only the specific fields needed, until patched.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.