NFI A.I CyberSecurity Scoring
08/09/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for NFI in 2026.
No incidents recorded for NFI in 2026.
No incidents recorded for NFI in 2026.
At DSV, we keep supply chains flowing in a world of change. We provide and manage supply chain solutions for thousands of companies every day – from small family-run businesses to large global corporations. Our reach is global, yet our presence is local and close to our customers. Approx. 160,000 employees in over 90 countries work passionately to deliver great customer experiences and high-quality services. We aspire to lead the way towards a more sustainable future for our industry and are committed to trading on nature’s terms. DSV is a dynamic organisation that fosters inclusivity and diversity. We conduct our business with integrity, respecting different cultures and the dignity and rights of individuals. Read more at www.dsv.com.
CEVA provides world-class supply chain solutions for large and medium-size national and multinational companies across the globe. As an industry leader, CEVA offers customers complete supply chain design and implementation in contract logistics and freight management, alone or in combination. Together with CMA CGM, a leading worldwide shipping group and CEVA’s strategic partner, we are able to offer our customers end-to-end logistics solutions. CEVA’s integrated global network has over 1,000 facilities in more than 170 countries and 110,000 employees; all dedicated to delivering consistently excellent operations and supply chain solutions.
MSC is a privately owned global shipping company founded in 1970 by Gianluigi Aponte. As one of the world’s leading container shipping lines with headquarters in Geneva, Switzerland, MSC operates in over 675 offices across more than 155 countries worldwide with over 200,000 MSC Group employees. With access to an integrated network of road, rail and sea transport resources which stretches across the globe, the company prides itself on delivering global service with local knowledge. OUR SERVICES MSC is a world leader in global container shipping and a company offering global service with local knowledge. MSC also provides integrated network of road, rail and sea transport resources which stretches across the globe. YOUR INDUSTRY Bringing you industry-specific expertise; whatever you’re shipping, wherever you’re shipping it. MSC delivers a professional, efficient service tailored to the specific needs of your business. Our services are designed around you.
Yusen Logistics is the insight-driven, customer-centric logistics partner to global business. We deliver this through an extended range of services from International Freight Forwarding and Contract Logistics to Supply Chain Solutions and Industry insights covering the full supply chain. We invest in a deep understanding of our customers' business, their customers, the challenges they face and the goals they want to achieve. Yusen Logistics has a global network linking Japan, the Americas, Europe, East Asia and South Asia & Oceania, and operates more than 650 distribution centers/offices in 46 countries and over 25.000 employees. Designing and implementing award winning solutions to complex supply chain requirements, Yusen Logistics’ skilled teams, state-of-the-art equipment and sophisticated technology deliver cost effective results with added value. Yusen Logistics delivers high performance solutions from raw materials to finished products throughout the supply chain. Working with manufacturers and retailers Yusen Logistics offers specialist expertise in: • Automotive • Aerospace • Consumer Electronics & Technology • Healthcare & Pharmaceuticals • Retail • Food Logistics Yusen Logistics works closely with customers to create enhanced solutions with the design, planning, and execution of key services including: • Global Freight Forwarding • Transportation Management • Warehousing and Distribution • End to end Supply Chains With regional headquarters in Europe, Japan, East Asia, Oceania and the Americas, Yusen Logistics’ international network covers almost every country in the world. Building on its established infrastructure Yusen Logistics is rolling out networks in emerging markets to mirror clients’ changing sourcing patterns. INSIGHT INTO ACTION. YUSEN LOGISTICS
Lineage is one of the world’s leading temperature-controlled industrial REITs and integrated solutions providers with a global network of over 480 strategically located facilities, totaling nearly 2.9 billion cubic feet of capacity across countries in North America, Europe, and Asia-Pacific. Coupling industry-leading expertise in end-to-end logistical solutions and innovative technology, Lineage partners with the world’s largest food and beverage companies to increase distribution efficiency, advance sustainability, minimize supply chain waste, and, most importantly, help feed the world. In recognition of the company’s leading innovations and sustainability initiatives, Lineage has been named a CNBC Disruptor 50 Company for three consecutive years, twice named a US Best Managed Company, named the No. 1 Data Science company, and 23rd overall, on Fast Company’s list of The World’s Most Innovative Companies, and was included on Fortune’s Change the World list. Nasdaq: LINE
As the custodian of ports, rail and pipelines, Transnet’s objective is to ensure a globally competitive freight system that enables sustained growth and diversification of the country’s economy. As a state-owned company, Transnet continues to leave an indelible mark on the lives of all South Africans. With a geographical footprint that covers our entire country, Transnet is inextricably involved in all aspects of life in South Africa. Through the Transnet Foundation - which is the Corporate Social Investment arm of Transnet - we have invested time and money in several diverse programmes around the country that provide much-needed succour to our communities. Looking ahead, Transnet is focused on modernizing infrastructure, driving growth, and enhancing efficiency through strategic partnerships. Our vision is clear: to contribute meaningfully to South Africa’s economic aspirations through sustainable growth and modernization.
The Brink’s Company (NYSE:BCO) is a leading global provider of cash and valuables management, digital retail solutions (DRS), and ATM managed services (AMS). Our customers include financial institutions, retailers, government agencies, mints, jewelers and other commercial operations. Our network of operations in 51 countries serves customers in more than 100 countries. For more information, please visit our website at www.brinks.com.
𝗪𝗲 𝘀𝗵𝗮𝗽𝗲 𝘀𝘂𝗽𝗽𝗹𝘆 𝗰𝗵𝗮𝗶𝗻𝘀 𝗴𝗹𝗼𝗯𝗮𝗹𝗹𝘆 Logistics seems so simple – just goods in, goods out. For us there is so much more to it. By combining deep industry expertise with the right technologies, we develop innovative supply chain management and e-commerce solutions for our clients. We have aligned our organization to the needs of our internationally operating clients to offer them the greatest value. A strong team with clear value propositions takes care of our clients in order to ensure a strong relationship. Customer centricity, sustainable, scalable and data-driven solutions will be defining factors of modern supply chains. This is exactly where we come in with our solutions and support our clients in their growth objectives. Our work in the warehouse is determined by well-established processes and a high degree of digitization and automation. There is a fast pace in the office as well as the warehouse that we master together. We're on the move and empower one another. Approximately 20,000 employees across 100 locations are jointly working towards our common mission: to be our clients' trusted global supply chain partner for growth and transformation with a drive for excellence.
Delhivery is India’s largest fully-integrated logistics services provider. With a nationwide network spanning over 18,850 pin codes, the company offers a comprehensive range of logistics solutions — including express parcel transportation, partial-truckload (PTL) and full-truckload (FTL) freight, cross-border services, supply chain solutions, Delhivery Direct (national and local courier services) and technology-enabled logistics. Comprehensive Solutions for Every Need ➡️Express Parcel: Send shipments across India, including heavy goods, with value-added services like real-time tracking, NDR Management, WhatsApp based updates, RTO, Protect ➡️Delivery Direct: All-in-one courier service that lets you send anything within the city or anywhere in India ➡️Rapid: A sub-2-hour delivery service helping brands offer faster deliveries and a better customer experience ➡️Supply Chain Solutions: Store and manage inventory at optimized locations across India, fulfilling orders for both B2B and B2C channels with precision. ➡️Partial Truckload (PTL):Leverage India’s large PTL network for door-to-door or hub-to-hub delivery with multimodal freight and smart dashboards. ➡️Full Truckload (FTL): Handle high-volume shipments with speed and efficiency through our professional network of truckload partners and our own fleet. ➡️Cross-Border Services: Ship parcels and freight to 220+ countries with door-to-door and port-to-port logistics ➡️TransportOne: Delhivery’s AI‑powered TMS that gives enterprises end‑to‑end optimization, from intelligent sourcing and load stacking to agentic ePOD and automated billing Our Impact at Scale ✔️4 Billion+ parcels shipped since inception ✔️Coverage of 99.5% of India’s population ✔️Trusted by 48,000+ businesses ✔️Shipped over 4.7 Million tonnes of freight ✔️Managing 22.05 Million+ sqft of logistics infrastructure Start shipping: https://one.delhivery.com/register Download Delhivery Direct App: https://appdelhivery.go.link/5YuVn
Latest updates, reports, and threat intel affecting the global network.
A Cybersecurity expert and Chief Executive Officer of Ash Nelson Partners, Sheila Ash Nelson, has raised alarm over the increasing risk.
Gattaca also announced that it has acquired the entire issued share capital of Infosec People for an aggregate cash consideration of £2.1...
Interface to Network Security Functions (I2NSF) Working Group within Internet Engineering Task Force (IETF) has developed a framework and its interfaces...
Alexander Dennis, a subsidiary of NFI Group Inc., one of the world's leading independent global bus manufacturers, today announced that its cyber security...
NFI Connect is a 5G capable and cybersecure telematics solution that provides real-time oversight of fleets, ultimately improving bus uptime, driver safety,...
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any application with low cache memory that causes premature eviction to free up memory and applications running macropay-solutions/maravel-framework that utilize tymon/jwt-auth for API token authentication and blacklist management or any other package that does the same may be affected. This architectural risk might also impact native Laravel applications utilizing cache tags under specific volatile or eviction-capped environments. tymon/jwt-auth automatically probes for cache tag support. If found, it forcefully wraps 14-day token blacklist entries (jti) inside a relational tymon.jwt tag. In environments where the O(1) Atomic Lazy Eviction model is active — either natively inside Maravel-Framework v20.x or manually backported into v10.x via the explicit DI container singletons provided in PR #104 (App\Cache\TaggedCache and App\Cache\TagSet) — a strict global tracking ceiling (Container::TAGGED_CACHE_TTL_CAP_SECONDS) of 7,200 seconds (2 hours) is enforced to secure the system against memory index bloat. This ceiling forcefully truncates the 14-day blacklist lifespan down to a maximum of 2 hours, after which individual tracking keys naturally expire and disappear from the active cache window. Furthermore, because the optimized engine implements a generational version matrix to achieve O(1) flush speeds, any programmatic or manual invocation of a tag flush or reset (e.g., Cache::tags([...])->flush()) instantly bumps the internal atomic master version pointer. This shifts the computed cryptographic composite hash (sha1($this->tags->getNamespace())) for all overlapping components, rendering the entire existing index immediately unreachable. Consequently, through either natural 2-hour expiration or an intervening tag flush execution (like the cache naturally cleaning old values to free up memory), the invalidation state records are entirely wiped out. Because the tokens' physical cryptographic signatures remain structurally valid for up to 14 days, stolen, hijacked, or legitimately logged-out tokens are instantly and silently resurrected across the entire API gateway, leaving the application critically vulnerable to widespread Token Replay Attacks. Because this issue is caused by an upstream architectural assumption within the tymon/jwt-auth package rather than a core defect inside the framework, there is no direct framework version upgrade that can safely bypass this lifecycle collision without breaking business cache recycling bounds. Maravel version 10.74.0 introduced a way to backport the new fixed tagged cache from 20.x into 10.x by resolving TagSet and TaggedCache from DI, which is how this latent architectural lifecycle vulnerability was discovered. Users must apply the decoupled configuration workaround outlined below. As a workaround, make sure that cache memory size does not generate early natural evictions from cache to free up space, deleting blacklisted jwt ids before they expire. Applications must decouple flat authentication vectors from the relational tagging subsystem. This forces token identifiers to write directly to the primary cache keyspace as flat, un-tagged key-value pairs where they securely retain their unclipped 14-day lifecycle.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.