GCO A.I CyberSecurity Scoring
GCO
Company Information
Website:http://www.satyamsolutions.com
Employees number:9
Number of followers:348
NAICS:484
Industry Type:Truck Transportation
Homepage:satyamsolutions.com
GCO Risk Score (AI oriented)
Between 700 and 749
GCOTruck Transportation
Updated:
03/08/2026
03/08/2026
744/1000
Moderate
Ba
GCO Global Score (TPRM)
xxxx
GCOTruck Transportation
Score locked

GCOModerate
Current Score
744Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
749
Vulnerability
03 Aug 2026 • GCO
eBay and Google: Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint
Google Passkey Security Flaws Expose Accounts to Silent Hijacking
744
HIGH-5
GOOEBA1785781429
Google Passkey Security Flaws Expose Accounts to Silent Hijacking
New research from Unit 42 reveals critical vulnerabilities in Google’s Cloud Authenticator, allowing malware on compromised Windows devices to hijack synced passkeys and bypass multi-factor authentication (MFA) without user interaction. The findings, part of a three-part series on passkey security, highlight flaws in device trust, onboarding, and recovery mechanisms that undermine the protections passkeys were designed to provide.
Passkeys, which replace passwords with public-key cryptography, are vulnerable due to Chrome’s handling of the "identity key" a hardware-backed credential meant to verify device possession. Instead of being permanently secured in the Trusted Platform Module (TPM), the key is generated as an exportable blob, enabling malware to extract and use it via Windows cryptography APIs to authenticate as the victim. This "Pass-ta-key" attack allows silent logins without triggering biometric or PIN prompts.
A more severe variant, the "Silver Pass-ta-key" attack, exploits Chrome’s re-onboarding process. By corrupting local passkey state files, attackers force the browser to accept a new, attacker-controlled verification key, granting persistent access even to MFA-protected accounts. The most damaging technique, the "Golden Pass-ta-key" attack, targets the security domain secret (SDS), a 32-byte master key encrypting all synced passkeys. Researchers found this key exposed in Chrome’s logs and memory during recovery, allowing attackers to decrypt past and future passkeys creating undetectable, long-term access since Google lacks a mechanism to rotate the SDS.
The vulnerabilities stem from implementation gaps rather than flaws in passkey cryptography itself, particularly over-reliance on client device trust and inconsistent validation by service providers. Some platforms, including eBay, have patched verification gaps following responsible disclosure. Mitigation strategies include enforcing user verification checks, validating device key attestation, restricting local access to credential stores, and monitoring for unusual onboarding or recovery triggers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
749
JUNE 2026
749
MAY 2026
749
APRIL 2026
749
MARCH 2026
749
FEBRUARY 2026
748
JANUARY 2026
748
DECEMBER 2025
747
Vulnerability
05 Dec 2025 • GCO
Resilient AI-enabled Cybersecurity and Trustworthiness (ReACT) Lab: Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
Exploitation of React Server Components (RSC) Vulnerability (CVE-2025-55182) by China-Linked Threat Actors
748
CRITICAL-1
REA1764950234
Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public knowledge.
The vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), aka React2Shell, which allows unauthenticated remote code execution. It has been addressed in React versions 19.0.1, 19.1.2, and 19.2.1.
According to a new report shared by Amazon Web Services (AWS), two China-linked threat actors known as Earth Lamia and Jackpot Panda have been observed attempting to exploit the maximum-severity security flaw.
"Our analysis of exploitation attempts in AWS MadPot honeypot infrastructure has identified exploitation activity from IP addresses and infrastructure historically linked to known China state-nexus threat actors," CJ Moses, CISO of Amazon Integrated Security, said in a report shared with The Hacker News.
Specifically, the tech giant said it identified infrastructure associated with Earth Lamia, a China-nexus group that was attributed to attacks exploiting a critical SAP NetWeaver flaw (CVE-2025-31324) earlier this year.
The hacking crew has targeted sectors across financial services, logistics, retail, IT companies, universities, and government organizations across Latin America, the Middle East, and Southeast Asia.
The attack efforts have also originated from infrastructure related to another China-nexus cyber threat actor known as Jackpot Panda, which has primarily singled out entit
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2025
747
OCTOBER 2025
747
SEPTEMBER 2025
747
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for GCO ??
What was GCO's A.I Rankiteo Cyber Score in July 2026 ??
What was GCO's A.I Rankiteo Cyber Score in June 2026 ??
What was GCO's A.I Rankiteo Cyber Score in May 2026 ??
What was GCO's A.I Rankiteo Cyber Score in April 2026 ??
What was GCO's A.I Rankiteo Cyber Score in March 2026 ??
What was GCO's A.I Rankiteo Cyber Score in February 2026 ??
What was GCO's A.I Rankiteo Cyber Score in January 2026 ??
What was GCO's A.I Rankiteo Cyber Score in December 2025 ??
What was GCO's A.I Rankiteo Cyber Score in November 2025 ??
What was GCO's A.I Rankiteo Cyber Score in October 2025 ??
What was GCO's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on GCO's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with GCO ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view GCO's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?