Grifols A.I CyberSecurity Scoring
07/09/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Grifols in 2026.
No incidents recorded for Grifols in 2026.
No incidents recorded for Grifols in 2026.
Sandoz is the global leader in generic and biosimilar medicines. Our Purpose is to pioneer access to medicines for patients globally. We are on a mission to drive innovation in the healthcare industry by freeing up resources sustainably and responsibly while continuing to address global health challenges such as antimicrobial resistance. We are present in more than 100 countries and our medicines serve some 500 million people every year. We have two main global businesses: Generics - divided between standard generics and complex generics - and Biosimilars. Read our community engagement guidelines: http://bit.ly/4ofoggc
Lonza is a pioneer and world leader in the CDMO industry, setting the pace with cutting-edge science, smart technology, and lean manufacturing. United by a common purpose, we turn our customers’ breakthrough innovations into viable therapies and manufacture the medicines of tomorrow. Founded in Switzerland in 1897, our company is the first and original CDMO, and today we are more dynamic, agile and forward-focused than ever before. As one of the largest Western CDMOs, we bring together a global team of around 18,500 colleagues across five continents to deliver comprehensive, integrated solutions for our customers' complex needs. For our customers and their patients, we bring quality, safety and reliability to bring life-enhancing and life-saving treatments to market at speed and at scale. For our colleagues, we strive to create a sense of belonging and inclusion where every person can thrive and bring their best.
At Merck, known as MSD outside of the United States and Canada, we are unified around our purpose: We use the power of leading-edge science to save and improve lives around the world. For more than 130 years, we have brought hope to humanity through the development of important medicines and vaccines. We aspire to be the premier research-intensive biopharmaceutical company in the world – and today, we are at the forefront of research to deliver innovative health solutions that advance the prevention and treatment of diseases in people and animals. We foster a diverse and inclusive global workforce and operate responsibly every day to enable a safe, sustainable and healthy future for all people and communities. For more information, visit www.merck.com. This site is intended for residents of the United States and Canada and their territories only. FLS: http://merck.us/3TKXNuZ
We're a medicine company turning science into healing to make life better for people around the world. It all started nearly 150 years ago with a clear vision from founder Colonel Eli Lilly: "Take what you find here and make it better and better." Harnessing the power of biotechnology, chemistry and genetic medicine, our scientists are urgently advancing science to solve some of the world's most significant health challenges. General Information and Guidelines: When you engage with us on LinkedIn, you're agreeing to these Community Guidelines: https://e.lilly/guidelines. If you have questions about a Lilly medicine, contact The Lilly Answers Center at 1-800-Lilly-Rx (1-800-545-5979) Monday through Friday, excluding company holidays.
Lupin Limited is a global pharmaceutical leader headquartered in Mumbai, India, with products distributed in over 100 markets. Lupin specializes in pharmaceutical products, including branded and generic formulations, complex generics, biotechnology products, and active pharmaceutical ingredients. Trusted by healthcare professionals and consumers globally, the company enjoys a strong position in India and the U.S. across multiple therapy areas, including respiratory, cardiovascular, anti-diabetic, anti-infective, gastrointestinal, central nervous system, and women’s health. Lupin has 15 state-of-the-art manufacturing sites and 7 research centers globally, along with a dedicated workforce of over 23,000 professionals. Lupin is committed to improving patient health outcomes through its subsidiaries – Lupin Diagnostics, Lupin Digital Health, and Lupin Manufacturing Solutions.
Sun Pharma is the world's fourth-largest speciality generic pharmaceutical company and No. 1 in India. We provide high-quality, affordable medicines trusted by customers and patients in over 100 countries. Sun Pharma's global presence is supported by more than 40 manufacturing facilities spread across 5 continents, R&D centres across the globe, and a multicultural workforce comprising over 50 nationalities. Sun Pharma fosters excellence through innovation supported by strong R&D capabilities comprising around 3,000 scientists and R&D investments of over 6-8% of annual revenues. At Sun, our people are our greatest asset. Ours has never been a story of individual brilliance but of cultivating a culture of realising collective potential. In our journey, everyone is enabled to take charge in an environment that offers limitless growth opportunities. We are with you every step of the way, so you can shine for years to come. With the launch of our Employee Value Proposition (EVP), we define our promise to ‘Create Your Own Sunshine'—driven by the three pillars of Better Every Day, Take Charge, and Thrive Together. These pillars drive progress at Sun so that people can achieve what they would have thought impossible. Learn more about our EVP here: https://sunpharma.com/careers/
Founded to serve health 70 years ago, Servier is a global pharmaceutical group governed by a non-profit Foundation that aspires to make a meaningful social impact for patients and for a sustainable world. The Group’s unique governance model preserves its independence and means it can fully serve its vocation of being committed to therapeutic progress to serve patient needs while adopting a long-term vision. Its employees are fully committed to this shared vocation, which serves as a source of inspiration every day. A world leader in cardiometabolism and venous diseases, Servier has made a major shift into oncology, which represents a new pillar of strategic growth. The Group devotes close to 70% of its R&D budget to this field, with the ambition of becoming a focused and innovative player in the development of treatments targeting rare cancers. Neurology will constitute a future growth driver. Servier is focusing on a limited number of diseases in this area where accurate patient profiling makes it possible to offer a targeted therapeutic response through precision medicine. To promote widespread access to quality care at a lower cost, the Group also offers a range of quality generic drugs covering most pathologies, leveraging well-known brands in France, and Eastern Europe. In all these areas, the Group takes patient considerations into account at every stage of the medicine life cycle. Headquartered in France, Servier relies on committed teams and strong geographical footprint; its medicines are available in close to 140 countries. In 2023/2024, the Group achieved sales revenue of €5.9 billion and EBITDA of €1.3 billion in 2024 (22.2%). Today, the Group employs over 22,000 people worldwide. -- To report a suspected adverse event with a Servier drug, please visit servier.com
At UCB, we believe everyone deserves to live the best life they can - as free as possible from the challenges and uncertainty of disease. Our purpose is to support people living with severe central nervous system and immunological conditions by delivering meaningful solutions that go beyond medicine. We are driven by the experiences of patients and caregivers, and inspired to pursue innovations that create real value - not just in clinical outcomes, but in everyday moments, dreams pursued, and simple pleasures enjoyed. Our ambition is to unlock transformative science and technologies that respond to unmet needs and elevate lives. From our headquarters in Belgium to nearly 40 countries around the world, we nurture a culture of respect and care. By listening deeply and collaborating across borders and disciplines, we enable cutting-edge research shaped by patients’ needs. Through strong connections with healthcare professionals, partners, and communities, we strive to make a lasting impact - today and into the future. We're inspired by patients, driven by science.
AbbVie is a global biopharmaceutical company focused on creating medicines and solutions that put impact first — for patients, communities, and our world. We aim to address complex health issues and enhance people's lives through our core therapeutic areas: immunology, oncology, neuroscience, aesthetics and other areas of unmet need. Learn more about us at www.abbvie.com and review our community guidelines at https://www.abbvie.com/social-media-community-guidelines.html.
Latest updates, reports, and threat intel affecting the global network.
The Cencora breach affected some of the most prominent Big Pharma firms, including Novartis, Bayer, AbbVie, Regeneron, Genentech and Incyte.
A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling `__import__(module_path, ...)`. The module is imported — running its top-level code (import side effects) — before the framework checks that the resolved object is a `LiveView` subclass and before any per-view authentication. The `LIVEVIEW_ALLOWED_MODULES` allowlist that should contain this is fail-open (`if allowed_modules:` — skipped when the setting is unset, the framework default) and uses loose `startswith` matching. An unauthenticated WebSocket client (the WS handshake does not require auth; per-view auth runs only after import + instantiate) can therefore send a `mount` / `live_redirect_mount` / `url_change` frame (or an SSE mount) with `view = "<any.importable.module>.AnyName"` and cause the server to import — and execute the top-level code of — any importable Python module by name. Version 1.0.7 fixes the issue with a fail-closed resolution gate (`djust._view_resolution.is_view_import_allowed`): a client view path resolves only if (a) its module is already loaded (`sys.modules` — so resolving runs no new code; URL-routed views loaded by URLconf at startup keep working with zero config) or (b) it matches `LIVEVIEW_ALLOWED_MODULES` on a module-segment boundary (explicit opt-in for lazily-imported views). The gate runs before `__import__` at all three sinks (+ defense-in-depth inside `_instantiate_view`). As a workaround, set `LIVEVIEW_ALLOWED_MODULES` to the narrow list of modules that contain your mountable LiveView classes. (Note: pre-patch the allowlist is `startswith`-matched and the import still precedes the subclass check, so this is mitigation, not a complete fix.)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA `url_change` navigation, and (c) `{% live_render %}` embedded child views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views. This is fixed in djust 1.0.7. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns 403, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op). No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` on the live path while the HTTP path resolved correctly. With `STRICT_MODE=False` the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against `ALLOWED_HOSTS` (the same logic as the CSWSH Origin gate, parsed with Django's `split_domain_port` so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with `STRICT_MODE=False`.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Because exposing model objects to templates is a normal djust pattern, this could leak credentials/PII without the developer realizing the full object crossed the wire. This is fixed in djust 1.0.7. Model serialization applies a secure-by-default sensitive-field denylist (password/hash/token/secret-style fields and known privilege flags are withheld) with an identity-subset fallback. As a workaround, keep `Model` instances on `_private` attributes and expose only the specific fields needed, until patched.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.