Comparison Overview
맥킨지앤드컴퍼니 (McKinsey Korea)

맥킨지앤드컴퍼니 (McKinsey Korea)
54F Three IFC, 10 Gukjegeumyung-ro, Yeongdeungpo-gu, Seoul, Seoul, 07326, KR
Last Update: 31/01/2026
맥킨지앤드컴퍼니(McKinsey & Company)는 세계 유수의 기업, 정부, 공공기관의 신뢰받는 자문 파트너로 활동하는 글로벌 경영 컨설팅 기업입니다. 민간, 공공, 사회 전반에 걸친 다양한 조직들과 협업하며, 깊이 있는 전문성과 폭넓은 글로벌 네트워크를 바탕으로 복잡하고 중요한 과제를 해결합니다. 우리는 고객과 함께 역량과 리더십을 강화하며, 실질적인 해법 도출과 지속 가능한 변화에 기여하는 것을 목표로 합니다. 해당 페이지에서는 맥킨지 한국 오피스의 미디어 활동,...

SGS
Zugerstrasse 57, Baar, Zug, CH, 6340
Last Update: 31/03/2026
SGS is the world’s leading Testing, Inspection and Certification company. We operate a network of over 2,500 laboratories and business facilities across 115 countries, supported by a team of 99,500 dedicated professionals. With over 145 years of service excellence, we c...
Compliance Ranges Comparison

맥킨지앤드컴퍼니 (McKinsey Korea)







SGS






Benchmark & Cyber Underwriting Signals
Incidents vs Professional Services Industry Avg (This Year)
No incidents recorded for 맥킨지앤드컴퍼니 (McKinsey Korea) in 2026.
Incidents vs Professional Services Industry Avg (This Year)
No incidents recorded for SGS in 2026.
Incident History - 맥킨지앤드컴퍼니 (McKinsey Korea) (X = Date, Y = Severity)
맥킨지앤드컴퍼니 (McKinsey Korea) cyber incidents detection timeline including parent company and subsidiaries.
Incident History - SGS (X = Date, Y = Severity)
SGS cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

맥킨지앤드컴퍼니 (McKinsey Korea)

SGS
FAQ
Latest Global CVEs
A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2.
- https://github.com/openchoreo/openchoreo/commit/047d80ddc63b4b4b9dd67044d5cffcdbd77685ce
- https://github.com/openchoreo/openchoreo/commit/0aa0ffe1623bd8eb4235cb2a5854336695953c3a
- https://github.com/openchoreo/openchoreo/commit/b42eeb0f5dce95195a9781d7c5a1fe9e38f5da8f
- https://github.com/openchoreo/openchoreo/pull/4122
- https://github.com/openchoreo/openchoreo/releases/tag/v1.0.2
- https://github.com/openchoreo/openchoreo/releases/tag/v1.1.2
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-qh9r-j7rp-4x2m
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.
- https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04
- https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129
- https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a
- https://github.com/openchoreo/openchoreo/pull/4256
- https://github.com/openchoreo/openchoreo/pull/4258
- https://github.com/openchoreo/openchoreo/pull/4259
- https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3
- https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3
- https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.2.0.