LAFAM A.I CyberSecurity Scoring
25/04/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for LAFAM in 2026.
No incidents recorded for LAFAM in 2026.
No incidents recorded for LAFAM in 2026.
Retail
Founded in 1956, Williams-Sonoma, Inc. is the premier specialty retailer of high-quality products for the home. Our family of brands includes Williams Sonoma, Pottery Barn, Pottery Barn Kids, PBteen, West Elm, Williams-Sonoma Home, Rejuvenation, and Mark and Graham. These brands are among the best known and most respected in the industry. We offer beautifully-designed, stylish and functional products for every area of the home, including the kitchen, living room, bedroom, home office, closet, laundry room, and even outdoor spaces. We've seen some big changes since our first brick-and-mortar store opened more than half of a century ago. What hasn't changed is our passion for high-quality products, functional design, outstanding customer service, and enhancing the lives of our customers and the communities where we operate. Today, we're a multi-brand, multi-channel, global enterprise supported by state-of-the-art technology and some of the most talented teams in retailing - and we're always looking for new energy and ideas.
Bij Albert Heijn geloven we dat eten en drinken een essentiële rol speelt bij de grote uitdagingen in de maatschappij. Het levert een belangrijke bijdrage aan een gezonde levensstijl, het verbindt mensen en draagt bij aan een beter klimaat en daarmee een duurzame samenleving. Onze missie is dan ook: ‘Samen beter eten bereikbaar maken. Voor iedereen.’ Elke dag zit boordevol keuzes en met alle mogelijkheden van tegenwoordig is kiezen niet altijd makkelijk. Daarbij snapt Albert Heijn dat beter eten voor iedereen anders is, maar uiteindelijk willen we allemaal hetzelfde: ons goed voelen en lekker in ons vel zitten. Dit kunnen we realiseren door gezonder te eten. Door te weten waar ons voedsel vandaan komt en er samen van te genieten. Door een bijdrage te leveren aan het beter achterlaten van de wereld voor de generaties na ons. Dat gaat niet vanzelf. Daarom nemen we iedereen stap voor stap mee op weg naar beter eten. Albert Heijn Nederland is B Corp gecertificeerd. Deze certificering onderstreept onze missie waarmee we een bijdrage leveren aan een gezonde, sociale en duurzame samenleving. De B Corp certificering wordt toegekend aan bedrijven die voldoen aan hoge normen voor sociale- en milieuprestaties, transparantie en verantwoordelijkheid. Het behalen van de B Corp certificering is een aanmoediging om op de ingeslagen weg verder te gaan. Overal en op elk moment zijn wij de vertrouwde en inspirerende partner van onze klanten, al meer dan 135 jaar. Met meer dan 1.250 winkels, 9 home shop centers, 6 distributiecentra en 125.000 collega’s dragen we samen bij aan onze missie. Wil je weten wat de carrièremogelijkheden zijn? Ga naar werk.ah.nl. Meer weten over wat wij nog meer doen? Ga naar over.ah.nl.
AS Watson Group, the world’s largest international health and beauty retailer, is operating over 17,000 stores under 12 retail brands in 31 markets, with over 130,000 employees worldwide. For the fiscal year 2024, AS Watson Group recorded revenue of over US$24 billion. Every year, we are serving over 6 billion shoppers via our O+O (Offline plus Online) technology-enabled platforms. Together with our 12 retail brands including Watsons, Kruidvat, Trekpleister, Superdrug, Savers, Rossmann, Drogas, ICI PARIS XL, The Perfume Shop, PARKnSHOP, FORTRESS and Watson’s Wine, we set O+O (Offline Plus Online) as the new standard for retail. O+O is more about creating an integrated offline and online experience to better serve customers’ needs through digital transformation, that enables them to shop across any channel, anytime, anywhere. Every day, we work towards a clear purpose: To put a Smile on our customers’ faces today and tomorrow. Our success depends on our people staying ahead of the game. We believe that our attitude to teamwork and our encouragement for your personal growth comes shining through everything we do. We also know that our success as an employer isn’t just about influencing you on why you should join our business. It’s about asking you to imagine where it could take you.
Welcome to Zalando. Here’s some key info about us: Our position and vision: - We’re Europe’s leading online platform for fashion and lifestyle. - Founded in Berlin in 2008, we bring head-to-toe fashion to more than 50 million active customers in 25 markets; offering clothes, footwear, accessories, and beauty. - We're building the ecosystem for fashion and lifestyle ecommerce. Our offering: - Our assortment of international brands ranges from world-famous names to local labels - Our platform is a one-stop fashion destination for inspiration, innovation, and interaction - As Europe’s most fashionable tech company, we work hard to find digital solutions for every aspect of the fashion journey: for our customers, partners, and friends of our brand. - Our logistics network with 12 centrally located fulfillment centers allows us to efficiently serve our customers throughout Europe, supported by warehouses in Italy, France, Poland, and Sweden with a focus on local customer needs. Our beliefs: - Our ambition is to combine our passion for self-expression through fashion with our unwavering commitments to sustainability and D&I - We promote an inclusive corporate culture that welcomes different perspectives and brings together people from diverse backgrounds. We want to ensure a non-discriminatory and supportive working environment for each of our employees to thrive. It’s a journey that all teams are on together, centered around the values we uphold. - We believe that our integration of fashion, operations, and online technology gives us the capability to deliver a compelling value proposition to both our customers and fashion brand partners.
Genesco is a footwear focused specialty retailer and branded company with more than 1,400 stores in the U.S., Canada, the U.K. and Republic of Ireland. We also sell footwear at wholesale under the Johnston & Murphy brand, and through licensing agreements under the Levi’s, Dockers, Bass and other footwear brands. Today our portfolio of brands ranges from fashion footwear with an attitude to timeless brands.
Originated from the idea to facilitate the provision of employees’ basic daily needs, a store, known as Indomaret, was established in 1988. As the store developed, the Company were interested to further explore and understand the consumers’ various needs and shopping behaviors. Hence, several employees were assigned to observe and examine the community’s buying behavior. It was concluded that people would rather shop in modern stores due to more choices of quality products, fixed competitive prices, as well as comfortable atmosphere. With knowledge about consumers’ needs, store management skill, community’s shifting shopping behavior towards modern outlets, came forth the desire to further serve Indonesia nationwide. This was realized when Indomaret were registered as a legal entity, PT. Indomarco Prismatama, with a vision of “becoming an excellent retail network” and emphasizing on the “easy and economical” motto. Indomaret aims to grow rapidly by expanding its business and services to satisfy its customers. The business sectors has owned up to this point are Retail (Indomaret), Grocery (Indogrosir), Shopping Plaza (BSD Plaza), Food & Beverage (Yummy Choice), Bakery (Mr. Bread & Saybread & Mr. Donut), Japanese Restaurant (Osaka Food & Washoku Sato), and IT Consultant (AGCI). In the 20th century, Indomaret Group continuously evolve throughout all the capital city of the province and globally supported by up to 100.000 high competence human resources.
The Home Depot, the world’s largest home improvement specialty retailer, values and rewards dedicated, knowledgeable, and experienced professionals. We operate more than 2,300 retail stores in all 50 states, the District of Columbia, Puerto Rico, the U.S. Virgin Islands, Guam, Canada, and Mexico. All of our associates have one thing in mind — helping our customers build and improve their homes. Join The Home Depot team today and see for yourself why we are consistently ranked as a top Fortune 500 company.
Dollarama was founded by third-generation retailer and Canadian entrepreneur, Larry Rossy. It all started with one store, in Matane, Quebec, in 1992, and quickly grew over the next two decades to become a household name and shopping destination for Canadians from coast to coast. Dollarama today is a recognized Canadian value retailer with well over 1,300 locations, led by Neil Rossy, fourth-generation retailer and member of Dollarama’s founding management team. Dollarama aims to provide customers with a consistent shopping experience and compelling value, offering a broad assortment of general merchandise, consumables and seasonal items. All stores are corporately-owned and operated, and are conveniently located in metropolitan areas, mid-sized cities and small towns. Products are available in individual or multiple units at low, fixed price points.
We’re Team Kmart, on a mission to make everyday living brighter for our customers by improving the Kmart shopping experience – every time and everywhere they engage with us. For over fifty years now, we’ve been spreading the Kmart love to families of all shapes and sizes in Australia, then New Zealand, and now right across the world! We’re the place where families come first for the lowest prices on everyday items – it’s our vision and it’s what we do with passion. Today, Kmart has more than 300 stores across Australia and New Zealand and is recognised as one of the most profitable discount department stores in Australia. With over 40,000 Kmart superstars who are all focused on giving our customers the products that they love at the lowest prices, it truly is an exciting time to be a part of our Kmart family – and there’s never been a better time to join us then now! To find out more information, scroll through our LinkedIn page, or, we’d be happy to welcome you online at www.kmart.com.au Did you know we’re a part of something bigger? Owned by Wesfarmers Limited, the Kmart Group family comprises of Kmart Australia and New Zealand, Target Australia, Catch Australia and KAS Group Asia. The Group operates 520 stores across Australia and New Zealand, has offices in Australia and around the world, and employs more than 46,000 team members all focused on delivering products that our customers love. Together, the Kmart Group is creating an even more satisfying shopping experience for all of our customers, no matter where they are in the world.
Latest updates, reports, and threat intel affecting the global network.
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_SSL_CID_OUT_LEN_MAX) into that buffer without a destination-size parameter, so a caller-supplied optlen smaller than the CID causes a write of up to 31 bytes past the buffer end. In CONFIG_USERSPACE builds the getsockopt syscall verifier (z_vrfy_zsock_getsockopt) bounce-buffers the user's optval into a kernel allocation of exactly optlen bytes (k_usermode_alloc_from_copy -> z_thread_malloc), so an unprivileged user thread that passes a small optlen on a connected DTLS socket with Connection ID enabled induces a kernel-heap buffer overflow, with the overflowing content being the remote peer's CID. The defect requires CONFIG_MBEDTLS_SSL_DTLS_CONNECTION_ID, an established DTLS session with a negotiated peer CID, and (for the kernel-crossing case) CONFIG_USERSPACE. Introduced when the TLS_DTLS_CID option was added (v3.5.0). The fix rejects callers whose optlen is below MBEDTLS_SSL_CID_OUT_LEN_MAX with -EINVAL.
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-19 01:07:01 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity since 2026-05-19 01:07:01, and clean local clones.
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote ctx.fds[ctx.nfds] and incremented ctx.nfds with no bounds check. Two independent paths mutate ctx concurrently: the background autohandler running on the system workqueue, and user-triggered operations reached through the updatehub run shell command, direct API calls, or — since the operations are exposed as syscalls — userspace threads. When a second flow enters prepare_fds() while ctx.nfds is already 1, the write lands one element past the array; by struct layout it overlaps the adjacent ctx.sock/ctx.nfds members. More broadly, the unsynchronized sharing lets two flows interleave connection setup and teardown, double-closing a socket descriptor or scribbling the shared buffers. The result is corruption of the update subsystem's internal state and denial of service of the firmware-update path; the out-of-bounds write is contained within the ctx structure and there is no demonstrated path to memory outside it or to code execution. Triggering requires a local actor able to invoke update operations (or, with CONFIG_USERSPACE, an unprivileged userspace thread) and to win a timing race against the background handler; remote peers cannot control the race timing. The fix serializes the entry points with a mutex and adds a bounds check to prepare_fds().
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.