MITRE A.I CyberSecurity Scoring
MITRE
Company Information
Website:http://www.mitre.org/
Employees number:9,312
Number of followers:234,635
NAICS:5417
Industry Type:Research Services
Homepage:mitre.org
MITRE Risk Score (AI oriented)
Between 750 and 799
MITREResearch Services
Updated:
04/04/2026
04/04/2026
773/1000
Fair
Baa
MITRE Global Score (TPRM)
xxxx
MITREResearch Services
Score locked

MITREFair
Current Score
773Baa (FAIR)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
773
MAY 2026
773
APRIL 2026
773
MARCH 2026
773
FEBRUARY 2026
772
JANUARY 2026
772
DECEMBER 2025
772
NOVEMBER 2025
772
OCTOBER 2025
772
SEPTEMBER 2025
771
AUGUST 2025
771
JULY 2025
771
JUNE 2025
775
Vulnerability
18 Jun 2025 • MITRE
Spotify, Mitre and Splunk: Misconfigured GitHub Actions could leave repos and secrets exposed, Sysdig finds • DEVCLASS
GitHub Repositories Vulnerable to Hijacking via Insecure pull_request_target Workflows
770
HIGH-5
SPOMITSPL1767777752
GitHub Repositories at Risk: Sysdig Uncovers Critical Workflow Vulnerabilities
Sysdig researchers have identified a significant security risk in GitHub repositories, where improperly configured workflows could allow attackers to hijack projects by exploiting the `pull_request_target` event in GitHub Actions. Unlike the standard `pull_request` trigger—which runs in the context of a merge commit—`pull_request_target` executes in the base branch (typically the default branch) and has access to repository secrets and write permissions via the `GITHUB_TOKEN`.
The vulnerability arises when maintainers use `pull_request_target` to test untrusted code from public contributors, inadvertently exposing sensitive credentials. If misconfigured, attackers could inject malicious code, exfiltrate secrets, and gain elevated privileges within the repository.
Sysdig’s investigation revealed multiple affected projects, including:
- Spotipy, an open-source Python library for the Spotify Web API, where researchers demonstrated the ability to execute malicious Python packages and steal the `GITHUB_TOKEN`. The flaw has since been patched.
- Mitre’s cyber analytics repository, where attackers could exfiltrate the `GITHUB_TOKEN` and other secrets, potentially gaining full control. Mitre addressed the issue promptly.
- Splunk’s security_content repository, where two secrets were exposed, though the extracted `GITHUB_TOKEN` had limited read-only access.
Stefan Chierici, Sysdig’s threat research lead, warned that the impact depends on the privileges of the extracted token. In severe cases, attackers could modify workflows, exfiltrate additional secrets, or alter files in the main branch—effectively taking over the repository. While `pull_request_target` can be used safely, its nuances require careful handling to avoid exploitation.
Sysdig has reported additional vulnerable repositories and is awaiting remediation before disclosing further details. The findings underscore the need for maintainers to audit their GitHub Actions workflows for potential misconfigurations.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2025
775
Vulnerability
13 May 2025 • MITRE
MITRE Corporation
Launch of European Union's Vulnerability Database and Concerns Over CVE Program Funding
774
CRITICAL-1
MIT3490134112625
The MITRE Corporation faced a critical funding crisis for its CVE (Common Vulnerabilities and Exposures) Program, a cornerstone of global cybersecurity infrastructure used by vendors, governments, and critical infrastructure entities to track and prioritize vulnerabilities. The U.S. federal government initially appeared unwilling to renew MITRE’s contract, risking the shutdown of the CVE program—halting new vulnerability entries and eventually taking the platform offline. While historical CVE records would remain accessible via GitHub, the disruption would sever a vital resource for real-time threat intelligence, leaving organizations worldwide exposed to unpatched vulnerabilities without centralized tracking.The temporary 11-month contract extension by CISA averted immediate collapse, but the uncertainty underscored systemic risks: reliance on a single entity for a foundational cybersecurity service, potential exploitation gaps during transitions, and the broader fragility of public-private partnerships in critical infrastructure. ENISA’s parallel launch of the European Vulnerability Database further highlighted the urgency of decentralizing such dependencies, as MITRE’s near-lapse revealed how a funding lapse could cascade into global cybersecurity blind spots, delaying patch management and increasing attack surfaces for threat actors.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MITRE ??
What was MITRE's A.I Rankiteo Cyber Score in May 2026 ??
What was MITRE's A.I Rankiteo Cyber Score in April 2026 ??
What was MITRE's A.I Rankiteo Cyber Score in March 2026 ??
What was MITRE's A.I Rankiteo Cyber Score in February 2026 ??
What was MITRE's A.I Rankiteo Cyber Score in January 2026 ??
What was MITRE's A.I Rankiteo Cyber Score in December 2025 ??
What was MITRE's A.I Rankiteo Cyber Score in November 2025 ??
What was MITRE's A.I Rankiteo Cyber Score in October 2025 ??
What was MITRE's A.I Rankiteo Cyber Score in September 2025 ??
What was MITRE's A.I Rankiteo Cyber Score in August 2025 ??
What was MITRE's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on MITRE's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MITRE ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MITRE's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?