Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

Ministère de l'Emploi et de la Solidarité sociale du QuébecMinistère de l'Emploi et de la Solidarité sociale du Québec
VS
United States Postal ServiceUnited States Postal Service
Ministère de l'Emploi et de la Solidarité sociale du Québec

Ministère de l'Emploi et de la Solidarité sociale du Québec

Québec, G1R 4Z1, CA

Last Update: 01/04/2026

View Profile
Between 750 and 799
https://www.mess.gouv.qc.ca/
770/1000Fair

Le ministère de l’Emploi et de la Solidarité sociale contribue à la prospérité, à la richesse collective et au développement du Québec : - en favorisant l’équilibre entre l’offre et la demande de main-d’œuvre; - en privilégiant l’inclusion économique et sociale des per...

NAICS:92
NAICS Definition:Public Administration
Employees:2,872
Subsidiaries:45
12-month incidents
0
Known data breaches
0
Attack type number
0
United States Postal Service

United States Postal Service

475 L’Enfant Plaza, S.W., Washington, D.C., US, 20260

Last Update: 02/08/2026

View Profile
Between 650 and 699
http://www.usps.com/
672/1000Weak

As the United States Postal Service continues its evolution as a forward-thinking, fast-acting company capable of providing quality products and services for its customers, it continues to remember and celebrate its roots as the first national network of communications ...

NAICS:92
NAICS Definition:Public Administration
Employees:160,918
Subsidiaries:1
12-month incidents
1
Known data breaches
3
Attack type number
1

Compliance Ranges Comparison

Based On Specific Ai Models Category
Ministère de l'Emploi et de la Solidarité sociale du Québec

Ministère de l'Emploi et de la Solidarité sociale du Québec

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
United States Postal Service

United States Postal Service

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Government Administration Industry Avg (This Year)

No incidents recorded for Ministère de l'Emploi et de la Solidarité sociale du Québec in 2026.

Incidents

Incidents vs Government Administration Industry Avg (This Year)

United States Postal Service has 2.91% fewer incidents than the average of all companies with at least one recorded incident.

Incidents

Incident History - Ministère de l'Emploi et de la Solidarité sociale du Québec (X = Date, Y = Severity)

Ministère de l'Emploi et de la Solidarité sociale du Québec cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - United States Postal Service (X = Date, Y = Severity)

United States Postal Service cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
Ministère de l'Emploi et de la Solidarité sociale du Québec

Ministère de l'Emploi et de la Solidarité sociale du Québec

Incidents
No explicit notable incidents reported.
United States Postal Service

United States Postal Service

Incidents
🔒 Incident : Breach
USP1776349784
🔒 Incident : Breach
USP853052025
🔒 Incident : Breach
USP001081724

FAQ

Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has the best AI Cybersecurity Score ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has experienced more cyber incidents in the past ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has experienced more cyber incidents this year ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has experienced at least one ransomware attack ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has experienced at least one data breach ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has experienced at least one targeted cyberattack ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has experienced at least one vulnerability ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one holds the most compliance certifications ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one holds the fewest compliance certifications ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has the most subsidiaries ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec company and United States Postal Service company, which one has the largest number of employees ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec and United States Postal Service, which company holds both SOC 2 Type 1 certifications ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec and United States Postal Service, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - Ministère de l'Emploi et de la Solidarité sociale du Québec or United States Postal Service ?
Which company is PCI DSS compliant - Ministère de l'Emploi et de la Solidarité sociale du Québec or United States Postal Service ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec and United States Postal Service, which company complies with HIPAA regulations for healthcare data ?
Between Ministère de l'Emploi et de la Solidarité sociale du Québec and United States Postal Service, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-18577
SUMMARY

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

PUBLISHED
Date2026-08-02
UPDATED
Date2026-08-02
RISK INFORMATION (Score: )
CVSS4
Base Score: 8.2
Complexity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
NA
EXPLOITABILITY
NA
CVE-2026-10848
SUMMARY

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1, outlen - 1) and then scanned the result with strchr(out_buf, '"'). Because strncpy does not NUL-terminate the destination when the source is at least outlen - 1 (127) bytes long, the subsequent strchr reads past the 128-byte destination buffer into adjacent stack memory; if a " byte is found beyond the buffer, a one-byte out-of-bounds NUL write also occurs. A related defect in extract_payload() runs strchr/strrchr over the receive buffer, which may not be NUL-terminated when a maximal-length frame fills it. The parsed bytes come directly from the OCPP central-system server over a websocket: the reader thread fills recv_buf via websocket_recv_msg() and calls parse_rpc_msg() on each inbound DATA frame (subsys/net/lib/ocpp/ocpp.c). A malicious or compromised central server, or an on-path attacker (OCPP is commonly deployed over plain ws://), can send an RPC frame whose uid or action field is 127+ bytes with no closing quote, triggering the out-of-bounds access. The primary impact is a remotely triggerable denial of service: the unbounded scan can fault on an unmapped page, and the stray NUL write can corrupt adjacent stack state. The over-read data is not reflected to the peer, so disclosure is limited. The feature is EXPERIMENTAL and must be explicitly enabled (CONFIG_OCPP). The fix replaces the manual parser with the bounds-respecting json_mixed_arr_parse() and copies the extracted uid with an explicitly NUL-terminated buffer, eliminating both over-reads.

PUBLISHED
Date2026-08-02
UPDATED
Date2026-08-02
RISK INFORMATION (Score: 7)
CVSS3
Base Score: 7.0
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
IMPACT SCORE
4.7
EXPLOITABILITY
2.2
CVE-2026-9856
SUMMARY

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

PUBLISHED
Date2026-08-02
UPDATED
Date2026-08-02
RISK INFORMATION (Score: 7.1)
CVSS3
Base Score: 7.1
Complexity: LOW
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
IMPACT SCORE
4.2
EXPLOITABILITY
2.8
CVE-2026-65321
SUMMARY

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.

PUBLISHED
Date2026-08-02
UPDATED
Date2026-08-02
RISK INFORMATION (Score: 9.8)
CVSS3
Base Score: 9.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS4
Base Score: 9.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
3.9
CVE-2026-10774
SUMMARY

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import is never balanced by a destroy. The imbalanced teardown is reached every time subnet keys are destroyed: deleting a subnet (Config Server NetKey Delete), completing a Key Refresh Procedure (which retires the old key set), and resetting/re-provisioning the node. The over-the-air triggers are processed only under the node's device key, so they are exercisable by the provisioner or network administrator that owns the node, reachable over the Bluetooth Mesh network. With the default CONFIG_MBEDTLS_PSA_KEY_SLOT_COUNT of 16, repeated add/delete or key-refresh cycles exhaust the shared PSA key-slot pool after roughly a dozen rounds. Once exhausted, bt_mesh_private_beacon_key() and thus subnet creation fail: the node can no longer add subnets or complete key refresh, and other PSA crypto consumers on the device may be starved, until the device is rebooted. The fix aligns the destroy guard with the import guard (CONFIG_BT_MESH_PRIV_BEACONS) so each slot is freed.

PUBLISHED
Date2026-08-02
UPDATED
Date2026-08-02
RISK INFORMATION (Score: 2.4)
CVSS3
Base Score: 2.4
Complexity: LOW
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
IMPACT SCORE
1.4
EXPLOITABILITY
0.9