NMDC Group A.I CyberSecurity Scoring
28/01/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for NMDC Group in 2026.
No incidents recorded for NMDC Group in 2026.
No incidents recorded for NMDC Group in 2026.
We are a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world’s infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. ---
L&T Technology Services (LTTS) is one of the world’s leading engineering and technology service providers. With operations in over 25 countries and a growing annual revenue that now surpasses USD 1.2 billion, we work with organizations who design, develop or deliver products and services. We help the world’s biggest and brightest brands across practically every industry. So, how did we get here? Imagine working within a division of Larsen & Toubro (L&T) – the engineering giant with revenue in excess of USD 27 billion. Once our success became too big to contain, we were spun off into our own business, converging our engineering heritage with unmatched technology prowess, and bringing our unique brand of engineering to clients worldwide. We define it as Purposeful. Agile. Innovation. Fast-forward to today, and we’re leading the charge in industries that are shaping the future. The secret to our success is that every one of us is an Engineer at Heart💙 It’s our 23,700 (and counting) experts who constantly redefine excellence through a commitment to innovation, agility, and sustainable engineering solutions. Our engineers aren’t just experts – they’re passionate problem solvers with a relentless drive to innovate. At LTTS, being an Engineer at Heart is more than a tag line; it’s a shared mindset that powers everything we do. And it helps us focus on our shared mission: Engineering the Change the world needs to see.
Atkins is now AtkinsRéalis. Please follow AtkinsRéalis on LinkedIn. We are a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world’s infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. Please follow our page AtkinsRéalis on LinkedIn for all content: https://www.linkedin.com/company/atkinsrealis
Ramboll is a global architecture, engineering and consultancy company founded in Denmark in 1945. Our 18,000+ experts create sustainable solutions across Buildings, Transport, Energy, Environment & Health, Water, Management Consulting and Architecture & Landscape. Across the world, Ramboll combines local experience with a global knowledge base to create sustainable cities and societies. We combine insights with the power to drive positive change for our clients, in the form of ideas that can be realised and implemented. We call it: Bright ideas. Sustainable change. Visit us at ramboll.com
At ST Engineering, we apply our technology and innovation to solve real-world problems and improve lives. Our commitment to excellence and our track record as a global technology, defence, and engineering company earns us a reputation for quality and trust. Subscribe to get the latest news delivered to your inbox: http://eepurl.com/htCq_P. For more updates, follow us on Facebook, Instagram, LinkedIn and YouTube.
We are Quest Global. We’re in the business of engineering, but what we’re really building is a brighter future. It’s not just what we do, but why we do it that makes us different. We believe engineering has the unique opportunity to solve the problems of today that stand in the way of tomorrow. For more than 25 years, we have strived to be the most trusted partner for the world’s hardest engineering problems. As a global organization headquartered in Singapore, we live and work in 18 countries, with 93 global delivery centers and offices, driven by 21,000+ extraordinary employees who make the impossible possible every day. Quest Global delivers world-class end-to-end engineering solutions by leveraging our deep industry knowledge and digital expertise. By bringing together technologies and industries, alongside the contributions of diverse individuals and their areas of expertise, we are able to solve problems better, faster. This multi-dimensional approach enables us to solve the most critical and large-scale challenges across the aerospace & defense, automotive, energy, hi-tech, healthcare, medical devices, rail and semiconductor industries. Integrity Matters: Protecting Against Job Search Scams. Quest Global conducts a formal interview process however we do NOT ask for payment at any stage of the recruitment process. Find out more - https://careers.quest-global.com/global/en
We're a global product engineering and digital services company focused on fulfilling our mission of helping the world drive, fly, build, and farm by enabling our customers to realize better products and deliver better experiences. We’re the strategic engineering partner businesses turn to when they aspire to be better. Manufacturing companies rely on us to enable them to conceptualize, develop and realize better products that are safer, cleaner, and improve the quality of life for all the stakeholders, helping us achieve our vision of #EngineeringABetterWorld. We provide a full spectrum coverage of solutions across the product value chain covering outsourced product engineering services, digital transformation services, upskilling solutions and value-added reselling of software products required to develop and realize better products. From delivering discrete outcomes to end-to-end turn key product development for #Connected #Autonomous #ElectricVehicles (#EVs), we're the partner with the experience and expertise to understand what better looks like – and who can bring better to life. We're inspiring a new generation of engineers who, by embracing the opportunities that exist at the convergence of digital technology and traditional engineering, are developing better products and helping customers win in the marketplace. As a global organization, we bring together diverse teams with varying skill sets to collaborate in real time and solve complex engineering problems. In doing so, we're redefining what the world understands by engineering and spreading the influence and impact of engineering as humanity's best way of addressing its most important challenges and opportunities. As a global company headquartered in Pune, India, we are active in more than 27 countries around the world, steered by 12500+ innovators who are making #EngineeringABetterWorld a reality - every day for everyone.
𝐀 𝐰𝐨𝐫𝐥𝐝 𝐥𝐞𝐚𝐝𝐞𝐫 𝐢𝐧 𝐄𝐧𝐠𝐢𝐧𝐞𝐞𝐫𝐢𝐧𝐠 𝐚𝐧𝐝 𝐈𝐓 𝐒𝐞𝐫𝐯𝐢𝐜𝐞𝐬 ALTEN is committed to meeting the expectations of its stakeholders and anticipating their requirements in the fields of innovation, R&D, and technological information systems. Founded in 1988 and present in 30+ countries, the Group has established itself as the global leader in Engineering and IT Services. ALTEN operates with major players in the Aeronautics, Space, Defence, Naval & Security, Automotive, Rail & Mobility, Energy & Environment, Life Sciences – Health, Industrial Equipment & Electronics, Telecoms, Banking, Finance & Insurance, Retail & Services, Public Services & Government sectors. OUR VISION: BUILDING TOMORROW’S WORLD TODAY We are convinced that engineers are the architects who build tomorrow’s world today. As a global leader in Engineering and IT Services, we support businesses in their technological and sustainable transformation. We commit to making a positive impact over time and on people, pushing the boundaries of innovation, and always staying one step ahead. We are driven by one ambition: to think about the future in the present. A LEADING GLOBAL TECHNOLOGY PARTNER ALTEN is involved in all projects with a technological dimension for the Technical, Research & Development Divisions and IT Systems Divisions of major corporate, telecoms and service clients, requiring the involvement of high-level Consultant-Engineers. To achieve this, the Group has put in place a world-renowned technical organisation of excellence. 🔹 12 Industries covered 🔹 21 Delivery Centers 🔹 6,500+ Clients FULL COVERAGE OF TECHNOLOGIES The Group covers a wide range of expertise in Engineering and IT Services in order to meet our clients’ needs. We bring together and coordinate at the transnational level specialists and consultants, experts in their profession who support our clients in their issues of digital transformation, innovation, product development, supply chain, etc.
TR is an international general contractor engaged in the engineering and construction of industrial facilities in the fields of: -Oil & Gas -Refining & Petrochemical -Power Generation -Infrastructures and industries -Energy Transition Engaging in the engineering, design and construction of various types of industrial facilities for a broad spectrum of customers throughout the world, including many of the principal national oil companies and several multinational companies. Leader for engineering and construction in the oil and gas sector in Spain, one of the leaders in Europe in the design and construction of oil and gas facilities, and one of the world leaders in the refining sector. especialiced on large turnkey industrial projects, although we also provide engineering, management, start-up and operating services for industrial plants. You can also follow us on twitter: @TRSA_rrhh
Latest updates, reports, and threat intel affecting the global network.
NMDC, India's largest iron ore producer, signed an MoU with IIT Kanpur to boost cybersecurity and integrate AI and ML. This collaboration aims to strengthen...
NMDC has entered into a strategic Memorandum of Understanding (MoU) with the Indian Institute of Technology (IIT) Kanpur.
In a significant move to deepen industry–academia collaboration, NMDC, India's largest iron ore producer, has signed a Memorandum of...
National Mineral Development Corporation (NMDC), a Navratna PSU under the Ministry of Steel, has taken a major step to strengthen its...
NMDC has signed an MoU with IIT Kanpur to collaborate on cybersecurity and advanced digital technologies, including Artificial Intelligence...
NMDC partners with IIT Kanpur to enhance cyber security and digital technologies through a strategic MoU for industry-academia...
IIT Kanpur and NMDC Limited have signed an MoU to work together on improving cybersecurity and advancing the use of AI and machine learning...
The Indian Institute of Technology Kanpur (IIT Kanpur) and NMDC Limited, a Navratna Public Sector Enterprise under the Ministry of Steel,...
TechDefence Labs IPO | The company is raising Rs 38.99 crore via initial public offering (IPO) of 20.2 lakh shares with price band of Rs...
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any application with low cache memory that causes premature eviction to free up memory and applications running macropay-solutions/maravel-framework that utilize tymon/jwt-auth for API token authentication and blacklist management or any other package that does the same may be affected. This architectural risk might also impact native Laravel applications utilizing cache tags under specific volatile or eviction-capped environments. tymon/jwt-auth automatically probes for cache tag support. If found, it forcefully wraps 14-day token blacklist entries (jti) inside a relational tymon.jwt tag. In environments where the O(1) Atomic Lazy Eviction model is active — either natively inside Maravel-Framework v20.x or manually backported into v10.x via the explicit DI container singletons provided in PR #104 (App\Cache\TaggedCache and App\Cache\TagSet) — a strict global tracking ceiling (Container::TAGGED_CACHE_TTL_CAP_SECONDS) of 7,200 seconds (2 hours) is enforced to secure the system against memory index bloat. This ceiling forcefully truncates the 14-day blacklist lifespan down to a maximum of 2 hours, after which individual tracking keys naturally expire and disappear from the active cache window. Furthermore, because the optimized engine implements a generational version matrix to achieve O(1) flush speeds, any programmatic or manual invocation of a tag flush or reset (e.g., Cache::tags([...])->flush()) instantly bumps the internal atomic master version pointer. This shifts the computed cryptographic composite hash (sha1($this->tags->getNamespace())) for all overlapping components, rendering the entire existing index immediately unreachable. Consequently, through either natural 2-hour expiration or an intervening tag flush execution (like the cache naturally cleaning old values to free up memory), the invalidation state records are entirely wiped out. Because the tokens' physical cryptographic signatures remain structurally valid for up to 14 days, stolen, hijacked, or legitimately logged-out tokens are instantly and silently resurrected across the entire API gateway, leaving the application critically vulnerable to widespread Token Replay Attacks. Because this issue is caused by an upstream architectural assumption within the tymon/jwt-auth package rather than a core defect inside the framework, there is no direct framework version upgrade that can safely bypass this lifecycle collision without breaking business cache recycling bounds. Maravel version 10.74.0 introduced a way to backport the new fixed tagged cache from 20.x into 10.x by resolving TagSet and TaggedCache from DI, which is how this latent architectural lifecycle vulnerability was discovered. Users must apply the decoupled configuration workaround outlined below. As a workaround, make sure that cache memory size does not generate early natural evictions from cache to free up space, deleting blacklisted jwt ids before they expire. Applications must decouple flat authentication vectors from the relational tagging subsystem. This forces token identifiers to write directly to the primary cache keyspace as flat, un-tagged key-value pairs where they securely retain their unclipped 14-day lifecycle.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.