Company Details
new-york-air-brake
439
6,062
3365
nyab.com
0
NEW_1953257
In-progress

New York Air Brake Company CyberSecurity Posture
nyab.comAs an innovative leader, New York Air Brake has been serving the rail industry since 1890. Through the years, our basic philosophy has reflected a deep respect for the customer, and a commitment to providing quality products at a cost-effective price. New York Air Brake's participation in ISO 9001, and our corresponding certification, echoes a company-wide spirit. From management, to administration, to engineering, to the production floor, quality is an ever-present compass. Recent years have seen a major expansion in engineering resources dedicated to bringing new technology to the marketplace. We have made significant capital investments in new facilities, machining centers, and test equipment, while increasing efficiency by utilizing highly focused teams in our manufacturing processes. .
Company Details
new-york-air-brake
439
6,062
3365
nyab.com
0
NEW_1953257
In-progress
Between 700 and 749

NYAB Global Score (TPRM)XXXX



No incidents recorded for New York Air Brake in 2025.
No incidents recorded for New York Air Brake in 2025.
No incidents recorded for New York Air Brake in 2025.
NYAB cyber incidents detection timeline including parent company and subsidiaries

As an innovative leader, New York Air Brake has been serving the rail industry since 1890. Through the years, our basic philosophy has reflected a deep respect for the customer, and a commitment to providing quality products at a cost-effective price. New York Air Brake's participation in ISO 9001, and our corresponding certification, echoes a company-wide spirit. From management, to administration, to engineering, to the production floor, quality is an ever-present compass. Recent years have seen a major expansion in engineering resources dedicated to bringing new technology to the marketplace. We have made significant capital investments in new facilities, machining centers, and test equipment, while increasing efficiency by utilizing highly focused teams in our manufacturing processes. .


CLW GROUP TRUCK produce trucks specially for you,we are the biggest special trucks manufacturer in China,you can find all kinds of the special trucks produced in our factory ,and you can also send us the drawings and the requirement details to produced specially for you . In our factory you can f

EXOLGAN, es la mayor Terminal de Contenedores de la República Argentina. Ubicada en Dock Sud, Avellaneda, sobre un predio de 50 hectáreas y con 1.200 mts lineales de muelle, es el principal operador en el Comercio Exterior de la carga Containerizada que ingresa y egresa de nuestro País. El servic

We’re an innovative NSW government organisation comprised of a network of agencies and divisions that keep the state moving. Our focus is on delivering safe, reliable and integrated transport networks for everyone. With over 28,000 team members, we’re committed to inclusion, diversity, and opportun

Established in 1947, Grimaldi is a fully integrated multinational logistics Group specialising in maritime transport of cars, rolling cargo, containers and passengers. Wholly owned by the Grimaldi family, the Group is led by Gianluca and Emanuele Grimaldi, sons of the founder Guido, and their broth

Yellow, a Fortune 500 company headquartered in Nashville, TN is one of the largest super-regional less-than-truckload (LTL) companies in North America. Nearly 100 years ago, Yellow created the LTL industry, and now it comprises four successful regional LTL companies and an in-house logistics brokera

Transnet Freight Rail is the largest division of Transnet SOC Ltd. It is a world class heavy haul freight rail company that specialises in the transportation of freight. The company maintains an extensive rail network across South Africa that connects with other rail networks in the sub-Saharan reg
.png)
A $625000 class action settlement resolves allegations related to a Westinghouse Air Brake Technologies Corporation cybersecurity incident.
Airlines, hospitals and people's computers were affected after CrowdStrike, a cybersecurity company, sent out a flawed software update.
The Biden administration issued a new cybersecurity strategy on Thursday that calls on software makers and American industry to take far greater responsibility.
Knorr-Bremse's North American subsidiaries New York Air Brake and Knorr Brake Co. to deploy Nexxiot's technology.
article about: Cybersecurity, Association of American Railroads, AAR, Rail Information Security Committee, RISC, Mark Grant, CSX, Paul Veeneman,...
Researchers have proved a car can be remotely hacked. Now imagine if that car was being driven entirely by a computer.
The day cars drove themselves into walls and the hospitals froze. A scenario that could happen based on what already has.
Wabtec and New York Air Brake are only makers of electronic pneumatic brakes.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of New York Air Brake is https://www.nyab.com.
According to Rankiteo, New York Air Brake’s AI-generated cybersecurity score is 749, reflecting their Moderate security posture.
According to Rankiteo, New York Air Brake currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, New York Air Brake is not certified under SOC 2 Type 1.
According to Rankiteo, New York Air Brake does not hold a SOC 2 Type 2 certification.
According to Rankiteo, New York Air Brake is not listed as GDPR compliant.
According to Rankiteo, New York Air Brake does not currently maintain PCI DSS compliance.
According to Rankiteo, New York Air Brake is not compliant with HIPAA regulations.
According to Rankiteo,New York Air Brake is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
New York Air Brake operates primarily in the Railroad Equipment Manufacturing industry.
New York Air Brake employs approximately 439 people worldwide.
New York Air Brake presently has no subsidiaries across any sectors.
New York Air Brake’s official LinkedIn profile has approximately 6,062 followers.
New York Air Brake is classified under the NAICS code 3365, which corresponds to Railroad Rolling Stock Manufacturing.
No, New York Air Brake does not have a profile on Crunchbase.
Yes, New York Air Brake maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/new-york-air-brake.
As of November 27, 2025, Rankiteo reports that New York Air Brake has not experienced any cybersecurity incidents.
New York Air Brake has an estimated 274 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, New York Air Brake has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.