Krispy Kreme A.I CyberSecurity Scoring
27/05/2026
Access Monitoring Plan
Access Monitoring Plan
Krispy Kreme has 47.92% fewer incidents than the average of same-industry companies with at least one recorded incident.
Krispy Kreme has 2.91% fewer incidents than the average of all companies with at least one recorded incident.
Krispy Kreme reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
Food and Beverage Services
Sysco is the global leader in selling, marketing and distributing food and related products to customers who prepare meals away from home. This includes restaurants, healthcare and educational facilities, lodging establishments, entertainment venues, and more. Sysco operates almost 340 distribution centers, in over 10 countries, with 76,000 colleagues serving approximately 730,000 customer locations. The company generated sales of more than $81 billion in fiscal year 2025 that ended June 28, 2025. As the world’s largest food-away-from-home distributor, Sysco offers customized supply chain solutions, bespoke specialty product offerings, and culinary support to drive customers to innovate and optimize their operations. We act as a trusted business partner to our customers, helping them grow through our industry-leading portfolio that includes fresh produce, premium proteins, specialty products, sustainably focused items, equipment and supplies, and innovative culinary solutions. For more information, visit www.sysco.com. For important news and key information for Sysco investors, visit the Investor Relations section of the company’s website at investors.sysco.com.
Keurig Dr Pepper (KDP) is a leading beverage company in North America, with annual revenue in excess of $14.1 billion and nearly 28,000 employees. KDP holds leadership positions in soft drinks, specialty coffee and tea, water, juice and juice drinks and mixers, and markets the #1 single serve coffee brewing system in the U.S. and Canada. The Company’s portfolio of more than 125 owned, licensed and partner brands is designed to satisfy virtually any consumer need, any time, and includes Keurig®, Dr Pepper®, Green Mountain Coffee Roasters®, Canada Dry®, Snapple®, Bai®, Mott's®, CORE® and The Original Donut Shop®. Through its powerful sales and distribution network, KDP can deliver its portfolio of hot and cold beverages to nearly every point of purchase for consumers. The Company is committed to sourcing, producing and distributing its beverages responsibly through its Drink Well. Do Good. corporate responsibility platform, including efforts around circular packaging, efficient natural resource use and supply chain sustainability. For more information, visit, www.keurigdrpepper.com.
Coca-Cola Consolidated is the largest Coca-Cola bottler in the United States. Our Purpose is to honor God in all we do, serve others, pursue excellence, and grow profitably. For over 120 years, we have been deeply committed to the consumers, customers, and communities we serve and are passionate about the broad portfolio of beverages and services we offer. We make, sell, and distribute beverages of The Coca-Cola Company and other partner companies in more than 300 brands and flavors across 14 states and the District of Columbia to approximately 60 million consumers. Headquartered in Charlotte, N.C., Coca-Cola Consolidated is traded on the NASDAQ Global Select Market under the symbol “COKE.” More information about the Company is available at www.cokeconsolidated.com. Follow Coca-Cola Consolidated on Facebook, Twitter, Instagram and LinkedIn.
We bottle and sell the beverages of The Coca-Cola Company exclusively in our 29 markets and partner with other beverage businesses to also sell their brands. With over 100 brands covering eight categories – sparkling, water, juices, ready-to-drink tea, energy, plant-based, premium spirits and coffee, we help our customers delight consumers with the drink they want, when and where they want it, around the clock. These brands cater to a growing range of tastes with a wider choice of healthier options, premium products and increasingly sustainable packaging. Sustainability is integrated within every aspect of our business. It is fundamental to our business strategy, which aims to create and share value with all of our stakeholders. This defines how we run our business, carry out our activities and develop our relationships. In doing so, we foster an open and inclusive work environment with our 33,000+ employees who share a passion for serving our customers and communities and building a more positive environmental impact.
Greene King is the country’s leading pub company and brewer with c.2,600 pubs, restaurants and hotels across England, Wales and Scotland. At Greene King we are passionate about delivering our purpose to ‘pour happiness into lives’. That’s for our customers, our team, our pub partners, our suppliers and the communities in which we live, operate and serve. Founded in 1799 with offices in Bury St. Edmunds, Suffolk and Burton on Trent in Staffordshire we employ around 40,000 people across the group with three divisions: Greene King pubs, Destination Brands & Ventures, and Brewing & Brands. • Greene King pubs: Greene King pubs is our mainstream pub brand located where people and communities come together; pubs enjoyed in cities, towns and villages throughout the country with clear ambition to be “The Nation’s Most Loved Pub Brand”. Pub Partners runs our tenanted and leased pubs business and Hive Franchise pubs. • Destination Brands & Ventures: Destination Brands is a portfolio of distinct brands which includes Hungry Horse, Chef & Brewer, Farmhouse Inns and Flaming Grill that bring friends and family together, delivering great service, quality and value for money for a range of eating out and drinking occasions. Venture includes Hickory’s, Premium (Crafted Pubs & Metropolitan Pub Company) and Hotels which operate autonomously of Greene King’s managed pub brands. • Brewing & Brands covers the brewing sides of the business. Quality ales are brewed at the Westgate brewery in Bury St Edmunds and the Belhaven Brewery in Dunbar. Our industry-leading portfolio includes Greene King IPA, Old Speckled Hen, Abbot Ale, Ice Breaker and Belhaven Best and our premium beers, Level Head and Flint Eye, brewed for the modern-day drinker.
Varun Beverages Limited (VBL) is one of the top FMCG players in the Indian Market. We are on track towards strengthening our position in the global beverage industry with our presence in 14 countries in the Indian sub-continent and Africa - where we are responsible for producing popular brands like Pepsi, Mirinda, 7up, Mountain Dew, Slice, Aquafina, Sting, Tropicana, Gatorade, and many more and making them readily available at outlets near you. We are committed towards delivering a refreshing beverage experience to our consumers. VBL in India is the second-largest franchisee partner for PepsiCo (outside US) and is powered by #HungryForMore spirit of 10,000+ employees who contribute to making the VBL family stronger and bigger every-day. Life@VBL is about endless opportunities and maximizing learnings every-day. We take immense pride in our employees’ commitment, ownership, and spirit of #OneTeamOneDream. We are equally committed to ESG principles; focusing on environmental stewardship and actively participating in community initiatives demonstrate our dedication to giving back to the environment and society. Our robust governance framework ensures accountability and sustainability in everything we do. For more details, please visit our website.
We are a global food company dedicated to bringing local favorite foods to communities everywhere. Within 17 countries, we offer quality branded food at a range of price points and across diverse categories. We're a company dedicated to the production, distribution and sales of refrigerated and frozen products such as cold meats, dry meats, cheese, yogurt, prepared meals and beverages. We have a strong diversified portfolio of well-positioned brands that market in the countries where we participate. We operate in 64 production plants, serving more than 670,000 customers in North, Central, South America, the Caribbean and Europe. We strive for excellence in everything we do. We're passionate about innovation and our consumers; we're committed in bringing them the best quality and taste in every product. The passion and effort we invest in our work is the reason we're on the road to success.
Compass Group is a global leader in food services operating in over 25 countries with around 590,000 employees worldwide and generating underlying revenues of over $46 billion for the 2025 fiscal year. Our vision is to be a world-class provider of contract food services and support services, renowned for our great people, our great service, and our great results.
From Coors Light, Miller Lite, Molson Canadian, Carling and Staropramen to Coors Banquet, Blue Moon Belgian White, Leinenkugel’s Summer Shandy, Vizzy, Creemore Springs and more, our 16,000+ employees across the globe make and market many of the most beloved beverage brands in the world. While our history is rooted in beer, we offer a modern portfolio that expands beyond the beer aisle with energy drinks, non-alc beer and canned cocktails, ready-to-drink coffee and more. Molson Coors Beverage Company is a publicly traded company that operates through Molson Coors North America and Molson Coors Europe, and is traded on the New York and Canadian Stock Exchange (TAP). Our commitment to raising industry standards, promoting the responsible consumption of our products, and leaving a positive imprint on our employees, consumers and communities is reflected on our website, www.molsoncoors.com. Celebrate responsibly. Follow only if legal drinking age and do not share with those who are underage. TERMS: http://bit.ly/TnCs-MC
Latest updates, reports, and threat intel affecting the global network.
Panera confirmed its second data security incident in two years, while Krispy Kreme agreed to pay a $1.6 million settlement after a 2024...
Krispy Kreme Inc. will pay $1616760 to settle a proposed class action alleging it negligently failed to protect the personal information of...
Kash Patel invested up to $50000 in Krispy Kreme as the FBI investigates a breach affecting 160000 customers.
Everyone has a Krispy Kreme story, CISO and Senior Director, Infrastructure, Jerry Fowler says, adding that those stories are more than doughnut reviews.
The doughnut company already is dealing with lawsuits stemming from the abrupt end to a deal with McDonald's.
Krispy Kreme has released a detailed update on the ransomware attack that targeted its systems in November 2024, confirming that the breach...
We are investigating a data breach impacting the sensitive personal and health information of 161676 current and former employees of Krispy...
Krispy Kreme began sending out breach notification documents to thousands of victims this week after a cyberattack in November exposed troves of data.
A cautionary tale from the crypto world, but equally applicable to regular businesses and organizations. Security firm Huntress reports on a...
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and payload). The resulting unverified claims are forwarded directly to the configured token module's revoke callback and the implementation's on_revoke callback, a state-mutating sink. The sibling operations refresh/2 and exchange/4 both call decode_and_verify first, so the signature is checked before anything acts on the claims; revoke/3 is the only state-mutating path that acts on claims without verifying the signature. An attacker who knows or guesses a victim's identifying claim values (jti, sub) can forge a JWT carrying those claims, sign it with an arbitrary key, and submit it to any endpoint that funnels a caller-supplied token into Guardian.revoke/3 (the standard logout / session-revocation pattern). When the token module mutates state keyed by the claims (whitelist deletion or blacklist insertion, for example a GuardianDb-style store), the victim's legitimate session is evicted. This is an unauthenticated session-revocation denial of service; the attacker never needs the signing secret. This issue affects guardian: from 1.0.0 before 2.4.1.
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is associated with program file lib/guardian/permissions.ex and program routines 'Elixir.Guardian.Permissions':encode_permissions!/1, 'Elixir.Guardian.Permissions':encode_permissions_into_claims!/2, 'Elixir.Guardian.Permissions':do_encode_permissions!/2. The Guardian.Permissions mixin installs a public encode_permissions!/1 function on every module that does use Guardian.Permissions. For each key of the supplied map, encode_permissions!/1 calls String.to_atom(to_string(k)) before any validation runs. The integer-value clause of do_encode_permissions!/2 then short-circuits straight to encoding without validating the key against the configured permission set, so a key with an integer value is interned as a fresh atom with no exception raised. Atoms are never garbage collected and the BEAM atom table is a fixed-size resource (default roughly 1,048,576 entries), so each unique attacker-chosen key permanently consumes one slot. An attacker who can influence a permission map that reaches encode_permissions!/1 (for example a permissions map read from a request body and passed into token issuance via encode_permissions_into_claims!/2) can mint an unbounded number of atoms and exhaust the atom table, crashing the entire BEAM node and every service running on it. The sibling decode_permissions/1 is not affected because it skips keys absent from the configured permission set. This issue affects guardian: from 2.0.0 before 2.4.1.
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check. The perm_set argument (the application's small, finite set of legitimate permission names) is discarded, so any external string flows straight into atom creation. This encoder is selected with use Guardian.Permissions, encoding: Guardian.Permissions.AtomEncoding and reached through the imported encode/3 entry point. String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that funnels attacker-influenced permission scopes (from a request body, a JWT claim, or other external input) into encode/3 therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node with system_limit, taking down every application running on it. The default encoder is Guardian.Permissions.BitwiseEncoding, which is not affected. This issue affects guardian: from 2.0.0 before 2.4.1.
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. base_key/1 in lib/guardian/plug/keys.ex converts any binary into the atom :"guardian_<input>", and the derived helpers claims_key/1, resource_key/1, and token_key/1 create a second atom on top of that. key_from_other/1 likewise converts a regex-captured binary through String.to_atom/1. The public specs advertise String.t() as a valid argument, so passing a string is documented usage, and higher-level entry points such as Guardian.Plug.current_token(conn, key: key) thread the caller-supplied key straight into these functions. String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that routes attacker-influenced data (a tenant identifier, header, or other request input) into a Guardian key therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node, taking down every application running on it. This issue affects guardian: from 0.1.0 before 2.4.1.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.