Comparison Overview
KPMG Bulgaria

KPMG Bulgaria
45/A Bulgaria Boulevard, Sofia, undefined, 1404, BG
Last Update: 09/03/2026
KPMG is a global organization of independent professional services firms providing Audit, Tax and Advisory services. We operate in 143 countries and territories and in FY20 had close to 227,000 people working in member firms around the world. Each KPMG firm is a legally...

TMF Group
Luna ArenA, Herikerbergweg 238, , Amsterdam , North Holland, NL, 1101 CM
Last Update: 13/09/2026
We provide employee, financial and legal administration so that firms can invest and operate safely around the world. TMF Group is a single global team with over 11,000 colleagues in more than 125 offices across 87 jurisdictions, covering 92% of world GDP and 95% of F...
Compliance Ranges Comparison

KPMG Bulgaria







TMF Group






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for KPMG Bulgaria in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for TMF Group in 2026.
Incident History - KPMG Bulgaria (X = Date, Y = Severity)
KPMG Bulgaria cyber incidents detection timeline including parent company and subsidiaries.
Incident History - TMF Group (X = Date, Y = Severity)
TMF Group cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

KPMG Bulgaria

TMF Group
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.