LPDBSF A.I CyberSecurity Scoring
30/12/2025
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for La Plateforme du Bâtiment - SGDB France in 2026.
No incidents recorded for La Plateforme du Bâtiment - SGDB France in 2026.
No incidents recorded for La Plateforme du Bâtiment - SGDB France in 2026.
Travis Perkins plc is the UK’s largest distributor of building materials to trade customers. The breadth, reach and scale of our business means we are in a unique position to provide customers with the building materials and tools they need for their projects, when and where they need it. We have over 17,000 colleagues and 1400 branches and stores across the country, and are proud to have helped our customers to build Britain for over 200 years. That includes building new, as well as transforming our existing homes into places that people love, and helping to create the infrastructure, schools, hospitals and offices that everyone deserves. Within Travis Perkins Group, there are six leading businesses. These include the Travis Perkins builders merchant, Toolstation and a number of specialist businesses, including BSS, Keyline, CCF and TF Solutions. To find out more about working for Travis Perkins plc and to see our latest opportunities visit, please visit www.tpplccareers.co.uk
Everyone sees opportunity differently. Knauf sees opportunity in everyone. Similar to other global businesses, our 41,500 team members in 90 countries across 300 sites provide a huge opportunity for anyone with ambition and energy. Unlike other global businesses, you may be surprised that Knauf is still a family-owned and run company and that means that our values and people-first culture are at the forefront of how the business operates. This means that career with us can offer you something a bit special; family values at the heart combined with global success and influence. Founded in 1932, we are one of the world’s leading manufacturers of construction materials for interior design, building insulation, and design ceilings. We are made up of 4 core divisions and our plants across the globe produce state-of-the-art drywall systems, plasters, and insulating materials as well as external thermal insulation composite systems.
Masco Corporation is a global leader in the design, manufacture and distribution of branded home improvement and building products. Our products enhance the way consumers all over the world experience and enjoy their living spaces. Our portfolio of industry-leading brands includes Behr® paint; Delta® and Hansgrohe® faucets, bath and shower fixtures; and HotSpring® spas, to name a few. At Masco, we believe in better living possibilities—for our homes, our environment and our community. Across our businesses and geographies, we seek out these possibilities to grow ourselves, enhance our consumers’ lives, create returns for our shareholders and improve the world around us. We believe a strong, supportive presence in the communities where we live, work and do business is vital. We partner with organizations that are as driven as we are to support the growth of our communities, encourage and enable equity and provide safe, affordable housing for all families. Plumbing: Axor, BrassCraft®, Bristan®, Brizo®, Caldera®Spas, Delta®, Endless Pools®, Hansgrohe®, HotSpring®, Newport Brass®, Peerless®, Mercury Plastics LLC Decorative Architectural: Behr® , KILZ®, Liberty® Hardware For more information about Masco Corporation, visit masco.com.
Owens Corning is a building products leader committed to building a sustainable future through material innovation. Our products provide durable, sustainable, energy-efficient solutions that leverage our unique capabilities and market-leading positions to help our customers win and grow. We are global in scope, human in scale with more than 25,000 employees in 31 countries dedicated to generating value for our customers and shareholders and making a difference in the communities where we work and live. Founded in 1938 and based in Toledo, Ohio, USA, Owens Corning posted 2024 sales of $11.0 billion. For more information, visit www.owenscorning.com.
Let’s create a safer and more open world – together! ASSA ABLOY is the global leader in access solutions with sales of SEK 150 billion and 63,000 employees. The Group has operations in over 70 countries and sales worldwide. ASSA ABLOY’s innovations enable safe, secure and convenient access to physical and digital places. Every day, we help billions of people experience a more open world. We have a feeling of discovery and urge to innovate by working together and telling it like it is, enabling us to be always growing, never boring and leading right. Do you want to be encouraged to act, have responsibilities to grow with and opportunities to explore? Join us!
Ambuja Cements Ltd. is among the leading cement companies in India. It is a member of the Adani Group - the largest and fastest-growing portfolio of diversified sustainable businesses. Ambuja Cement is known for its hassle-free, home-building solutions. Its unique products tailor-made for Indian climatic conditions, sustainable operations and initiatives that advance the company's philosophy of contributing to the larger good of the society have made it the most trusted brand in the Indian cement industry.
Builders FirstSource is the nation’s largest supplier of structural building products, value-added components and services to the professional market for new residential construction and repair and remodeling. Our focus is on providing unparalleled service to both large and small customers. Through investments in innovation and an unmatched portfolio of value-added products and manufacturing capabilities, we’re revolutionizing the homebuilding industry – outperforming today and transforming tomorrow. Builders FirstSource and the Builders FirstSource logo are trademarks of Builders FirstSource, Inc. and/or its subsidiaries. © 2022 Builders FirstSource, Inc. All rights reserved. JOB SEEKERS: Beware of job scams and fake employment offers. It has come to our attention that fraudulent employment offers have been sent to job seekers by people who claim to be employees of Builders FirstSource (BFS). These scammers use a variety of tactics to engage with job seekers to commit identity theft, financial fraud, and other crimes. They can be very convincing, going as far as to steal the profile pictures of our actual recruiters from their LinkedIn profiles and using email addresses that contain words such as ‘@BuildersFirstSource’ or '@BFS.' The scammers will typically ask you to send money at some point (for equipment, training, or a uniform, etc.). A LEGITIMATE BFS RECRUITER OR HIRING MANAGER WILL NEVER ASK YOU TO SEND US MONEY. Also, you will never receive a job offer from us if we have not verbally interviewed you. If you ever receive an unsolicited or suspicious communication that demands any form of payment in connection with employment at BFS, you should consider it to be fraudulent and cease all contact with the sender. You can report US job scams to the FTC (www.ReportFraud.ftc.gov), your state attorney general, or econsumer.gov for international scams. You can also report any fraudulent activity to LinkedIn.
UltraTech Cement Ltd. is the largest manufacturer of grey cement, Ready Mix Concrete (RMC) and white cement in India. It is also one of the leading cement producers globally. UltraTech as a brand embodies 'strength', 'reliability' and 'innovation'. Together, these attributes inspire engineers to stretch the limits of their imagination to create homes, buildings and structures that define the new India. UltraTech is India’s No. 1 Cement’ - visit www.ultratechcement.com for claim details. Disclaimer We understand that certain individuals have been luring the public by offering company’s Distributorships and Retail Outlet dealerships and sale of bulk cement / products at a highly discounted rate and demanding advance money in the process. They illegally use the name and logo of UltraTech Cement Limited (UTCL) and claim to be UTCL's authorized representatives. Please note that UTCL does not offer to sell its goods through SMS, Whatsapp Message, Calls, Emails or through any social media and never asks customers to make any advance payment for the same, via net banking or otherwise. Please do not trust these individuals and if you are approached by anyone offering UltraTech products through any of the mediums, seeking advance money in their bank account, please report the incident to the nearest Dealer or Authorized Retail Stockist or at the company’s Toll Free No. 1800 210 3311. For any query or assistance, please dial our Toll Free No. 1800 210 3311 or visit our official website at www.ultratechcement.com
Carrier is a global leader in intelligent climate and energy solutions, pioneering sustainable innovations in climate technologies. Founded by Willis Carrier, the inventor of modern air conditioning, we have been shaping industries and enhancing lives for more than a century. With approximately 48,000 employees across 160 countries and more than 35 trusted brands, Carrier serves customers through four business segments: Climate Solutions Americas, Climate Solutions Europe, Climate Solutions Asia Pacific, Middle East & Africa and Climate Solutions Transportation. Our solutions enable healthier, more efficient and more sustainable environments in homes and buildings, and help ensure the safe transportation of food, medicine and vaccines. Grounded in our purpose—we continue to lead through relentless innovation and a deep commitment to customer success, delivering cutting-edge solutions that bring comfort, safety and sustainability to life. Carrier. For the World We Share.
Latest updates, reports, and threat intel affecting the global network.
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any application with low cache memory that causes premature eviction to free up memory and applications running macropay-solutions/maravel-framework that utilize tymon/jwt-auth for API token authentication and blacklist management or any other package that does the same may be affected. This architectural risk might also impact native Laravel applications utilizing cache tags under specific volatile or eviction-capped environments. tymon/jwt-auth automatically probes for cache tag support. If found, it forcefully wraps 14-day token blacklist entries (jti) inside a relational tymon.jwt tag. In environments where the O(1) Atomic Lazy Eviction model is active — either natively inside Maravel-Framework v20.x or manually backported into v10.x via the explicit DI container singletons provided in PR #104 (App\Cache\TaggedCache and App\Cache\TagSet) — a strict global tracking ceiling (Container::TAGGED_CACHE_TTL_CAP_SECONDS) of 7,200 seconds (2 hours) is enforced to secure the system against memory index bloat. This ceiling forcefully truncates the 14-day blacklist lifespan down to a maximum of 2 hours, after which individual tracking keys naturally expire and disappear from the active cache window. Furthermore, because the optimized engine implements a generational version matrix to achieve O(1) flush speeds, any programmatic or manual invocation of a tag flush or reset (e.g., Cache::tags([...])->flush()) instantly bumps the internal atomic master version pointer. This shifts the computed cryptographic composite hash (sha1($this->tags->getNamespace())) for all overlapping components, rendering the entire existing index immediately unreachable. Consequently, through either natural 2-hour expiration or an intervening tag flush execution (like the cache naturally cleaning old values to free up memory), the invalidation state records are entirely wiped out. Because the tokens' physical cryptographic signatures remain structurally valid for up to 14 days, stolen, hijacked, or legitimately logged-out tokens are instantly and silently resurrected across the entire API gateway, leaving the application critically vulnerable to widespread Token Replay Attacks. Because this issue is caused by an upstream architectural assumption within the tymon/jwt-auth package rather than a core defect inside the framework, there is no direct framework version upgrade that can safely bypass this lifecycle collision without breaking business cache recycling bounds. Maravel version 10.74.0 introduced a way to backport the new fixed tagged cache from 20.x into 10.x by resolving TagSet and TaggedCache from DI, which is how this latent architectural lifecycle vulnerability was discovered. Users must apply the decoupled configuration workaround outlined below. As a workaround, make sure that cache memory size does not generate early natural evictions from cache to free up space, deleting blacklisted jwt ids before they expire. Applications must decouple flat authentication vectors from the relational tagging subsystem. This forces token identifiers to write directly to the primary cache keyspace as flat, un-tagged key-value pairs where they securely retain their unclipped 14-day lifecycle.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.