Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Lexfo

Lexfo Vendor Cyber Rating & Cyber Score

lexfo.fr

LEXFO is an offensive security firm that assesses and strengthens your systems with an expert, pragmatic, results-driven approach. We cover the full attack chain to better defend you: environment discovery and mapping, security audits and penetration testing, organizational audits, Red Team, code review, reverse engineering, incident response, data-leak monitoring, training and awareness, and analysis of embedded devices and set-top boxes. We provide CTEM (Continuous Threat Exposure Management) programs to continuously measure and reduce threat exposure, and we offer Pentest-as-a-Service through a dedicated platform : AMBIONICS. LEXFO holds PASSI qualification, is CESTI-approved, PRIS , referenced by ANJ and accredited to ISO/IEC 17025.


Lexfo A.I CyberSecurity Scoring

Lexfo
Company Information
Website:https://www.lexfo.fr
Employees number:59
Number of followers:4,734
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:lexfo.fr
Lexfo Risk Score (AI oriented)
Between 700 and 749
logo
LexfoIT Services and IT Consulting
Updated:
13/07/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Lexfo Global Score (TPRM)
xxxx
logo
LexfoIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Lexfo
LexfoModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
750Before Incident
Vulnerability
13 Jul 2026Lexfo
Lexfo: One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers

Exposed Python Server Reveals Three Active AiTM Phishing Campaigns

749After Incident
LOW-1
LEX1783931044
Exposed Python Server Reveals Three Active AiTM Phishing Campaigns Security researchers at Lexfo uncovered a misconfigured Python HTTP server left exposed on a virtual private server (VPS), inadvertently revealing the inner workings of multiple adversary-in-the-middle (AiTM) phishing operations. The incident highlights how simple operational errors such as unsecured, forgotten infrastructure can provide defenders with rare insights into attacker tactics. The exposed server contained a full toolkit used to build, host, and maintain credential-theft lures, including phishing pages, login-relay components, and configuration files. Lexfo linked the materials to three distinct AiTM campaigns, a technique where attackers intercept authentication flows to steal credentials and session cookies, potentially bypassing multifactor authentication (MFA). While the campaigns shared infrastructure, researchers noted that this did not necessarily prove a single group was responsible. Instead, the overlap could indicate shared tools, rented services, or a single operator managing multiple efforts. The exposure also revealed testing assets and revisions, offering defenders a chance to identify related activity though such intelligence is time-sensitive, as attackers may remove or replace files once detected. The incident underscores the risks of overlooked web services, even temporary ones. A lightweight server used for file-sharing or testing can persist beyond its intended lifespan, creating unintended exposure. Organizations are advised to maintain accurate inventories of internet-facing assets, enforce strict access controls, and regularly review configurations to prevent similar leaks. AiTM phishing remains a persistent threat, as stolen session tokens can grant attackers access even when MFA is enabled. Defenders are encouraged to monitor for unusual sign-in patterns, unexpected session changes, and rapid post-authentication activity. While phishing-resistant MFA and session controls improve security, user vigilance such as verifying URLs before entering credentials remains critical. The case serves as a reminder that attackers’ own mistakes can expose their operations, and even minor, short-lived services can become significant security risks if left unchecked.
INCIDENT DETAILS -
TYPE
Phishing (AiTM)
MOTIVATION
Credential theft, session hijacking
IMPACT
Data Compromised: Credentials, session cookies, phishing toolkitSystems Affected: Exposed Python HTTP server (VPS)Operational Impact: Potential unauthorized access to victim accountsIdentity Theft Risk: High (stolen credentials/session tokens)
DATA BREACH
Type Of Data Compromised: Credentials, session cookies, phishing toolkit (configuration files, phishing pages)Sensitivity Of Data: High (credentials, session tokens)Phishing pagesLogin-relay componentsConfiguration filesPersonally Identifiable Information: Credentials, session cookies
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Lexfo ?
?
What was Lexfo's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Lexfo's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Lexfo's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Lexfo ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Lexfo's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?