Lenovo A.I CyberSecurity Scoring
Lenovo
Company Information
Website:http://www.lenovo.com
Employees number:46,066
Number of followers:1,250,702
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:lenovo.com
Lenovo Risk Score (AI oriented)
Between 750 and 799
LenovoIT Services and IT Consulting
Updated:
01/04/2026
01/04/2026
786/1000
Fair
Baa
Lenovo Global Score (TPRM)
xxxx
LenovoIT Services and IT Consulting
Score locked

LenovoFair
Current Score
786Baa (FAIR)
01000
4 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
792
MAY 2026
791
APRIL 2026
797
Cyber Attack
02 Apr 2026 • Lenovo
DigiCert: DigiCert Revokes Certificates After Support Portal Hack
DigiCert Revokes Fraudulently Obtained Certificates Following Cyberattack
781
CRITICAL-16
DIG1777919462
DigiCert Revokes Fraudulently Obtained Certificates Following Cyberattack
On April 2, digital certificate authority DigiCert fell victim to a cyberattack after a threat actor targeted its support team with malware disguised as a screenshot in a customer chat channel. The malicious payload infected two endpoints one detected on April 3 and another on April 14, with the delayed discovery of the second infection attributed to malfunctioning security tools.
The attackers exploited a limited-access function in DigiCert’s internal support portal, leveraging the ability of authenticated support analysts to proxy into customer accounts. This allowed them to obtain initialization codes for pending Extended Validation (EV) Code Signing certificate orders. With these codes and approved orders, the threat actor successfully issued fraudulent certificates across multiple customer accounts and certificate authorities (CAs).
By April 17, DigiCert identified and revoked 60 certificates tied to the incident, including 27 directly linked to the attacker. Of these, 11 were reported by the cybersecurity community and had been used to sign the Zhong Stealer malware. The company confirmed that no other internal systems were compromised beyond the unauthorized access to initialization codes.
In response, DigiCert revoked all potentially affected certificates, canceled pending orders to block further exploitation, and implemented stricter security measures. These include enforcing multi-factor authentication (MFA) for administrative workflows, restricting support users from accessing initialization codes, limiting file types in support chats and Salesforce case attachments, and enhancing logging capabilities.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
791
FEBRUARY 2026
790
JANUARY 2026
790
DECEMBER 2025
786
NOVEMBER 2025
790
OCTOBER 2025
790
SEPTEMBER 2025
789
AUGUST 2025
789
Vulnerability
20 Aug 2025 • Lenovo
Lenovo
Critical XSS Vulnerabilities in Lenovo’s AI-Powered Customer Support Chatbot 'Lena'
785
CRITICAL-4
LEN532082025
Critical vulnerabilities were discovered in Lenovo’s AI-powered customer support chatbot, Lena, which leverages OpenAI’s GPT-4. The flaw stemmed from improper input and output sanitization, exposing the system to cross-site scripting (XSS) attacks. Security researchers at Cybernews demonstrated that attackers could exploit this by injecting malicious code via a 400-character prompt, tricking the AI into generating harmful HTML content. This enabled threat actors to steal session cookies, potentially granting unauthorized access to Lenovo’s customer support systems.The vulnerability highlighted significant risks in poorly secured AI implementations, particularly as enterprises accelerate AI adoption. While no evidence of active exploitation was reported, the flaw posed a serious threat to customer data integrity and system security. Had attackers successfully leveraged this, they could have compromised user sessions, accessed sensitive support-related information, or escalated privileges within Lenovo’s infrastructure. The incident underscores the urgency for robust AI security frameworks to prevent such exposures in high-stakes enterprise environments.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2025
793
JUNE 2023
790
Vulnerability
16 Jun 2023 • Lenovo
Lenovo
Lenovo Devices Targeted by BootKitty Linux UEFI Bootkit
786
CRITICAL-4
LEN001120824
Lenovo devices running on vulnerable Insyde firmware were targeted by the BootKitty Linux UEFI bootkit exploiting the LogoFAIL flaws (CVE-2023-40238). BootKitty bypassed UEFI Secure Boot by injecting rogue certificates and exploiting vulnerabilities in UEFI image-parsing components through tampered BMP files. The bootkit was capable of disabling kernel signature verification, preloading malicious binaries, and targeting specific Ubuntu versions. Despite available security patches, many devices remained at risk. The incident served as a reminder of the dangers associated with unaddressed vulnerabilities and the importance of timely updates to safeguard devices in the field.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2019
787
Vulnerability
16 Jun 2019 • Lenovo
Lenovo
Lenovo Preloaded Windows Vulnerability
787
LOW0
LEN749070725
A significant security vulnerability has been discovered in Lenovo’s preloaded Windows operating systems, where a writable file in the Windows directory enables attackers to bypass Microsoft’s AppLocker security framework. The issue affects all variants of Lenovo machines running default Windows installations and poses serious implications for enterprise security environments. Key takeaways include the writable MFGSTAT.zip file bypassing AppLocker security due to incorrect permissions, the use of Alternate Data Streams to hide executables, and the persistence of the vulnerability from 2019 to 2025. Mitigation strategies involve removing the vulnerable file using PowerShell or other enterprise management tools.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Lenovo ??
What was Lenovo's A.I Rankiteo Cyber Score in May 2026 ??
What was Lenovo's A.I Rankiteo Cyber Score in April 2026 ??
What was Lenovo's A.I Rankiteo Cyber Score in March 2026 ??
What was Lenovo's A.I Rankiteo Cyber Score in February 2026 ??
What was Lenovo's A.I Rankiteo Cyber Score in January 2026 ??
What was Lenovo's A.I Rankiteo Cyber Score in December 2025 ??
What was Lenovo's A.I Rankiteo Cyber Score in November 2025 ??
What was Lenovo's A.I Rankiteo Cyber Score in October 2025 ??
What was Lenovo's A.I Rankiteo Cyber Score in September 2025 ??
What was Lenovo's A.I Rankiteo Cyber Score in August 2025 ??
What was Lenovo's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Lenovo's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Lenovo ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Lenovo's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?