C A.I CyberSecurity Scoring
27/02/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for No Contrabando (Altadis) in 2026.
No incidents recorded for No Contrabando (Altadis) in 2026.
No incidents recorded for No Contrabando (Altadis) in 2026.
PT Gudang Garam Tbk is one of the leading cigarette producers that has been established since 1958 in the town of Kediri, East Java. Measured by assets controlled, product sales, duties and taxes paid to the Indonesian Government and by total number of employees, PT Gudang Garam, Tbk. is the biggest company involved in the Indonesian kretek cigarette industry. 'Tbk' denotes that the company lists part of its shares in the Stock Exchange. The Company has a 21.4 per cent of the domestic cigarette market at the end of 2017 based on Nielsen market research. Until now, Gudang Garam has widely known both domestically and abroad as a producer of high quality kretek clove cigarettes. Gudang Garam products can be found in many varieties, ranging from SKL (Sigaret Kretek Klobot) or corn husk-wrapped clove cigarettes, SKT (Sigaret Kretek Linting Tangan) or hand-rolled clove cigarettes, up to SKM (Sigaret Kretek Linting Mesin) or machine-rolled clove cigarettes. For the true clove cigarettes lovers, we are committed to provide an outstanding experience in enjoying kretek clove cigarettes made from high-quality materials. Gudang Garam provides lifehoods for a workforce of 35,272 at the end of 2017, engaged in cigarette manufacturing, marketing, & distribution. In addition to its production facilities, the Company is represented by a total of 67 area offices with 281 points of distribution located throughout Indonesia and services its markets with a sales fleet of over 7,000 vehicles. Employee walfare is a priority, from paper safety practices and health facilities to training in leadership, management, clerical and technical skills through a mixture of internal and external courses. Gudang Garam contributes indirectly to the lives of about 4 million people comprising tobacco and clove farmers, retailers and hawkers across the archipelago. The cigarette industry, in which Gudang Garam is a leading player, is a major source of revenue for the Government in excise duty.
Established in 1913, PT Hanjaya Mandala Sampoerna Tbk. (Sampoerna) has been playing a significant part in the tobacco industry for more than a century. As a subsidiary of PT Philip Morris Indonesia (PMID) and an affiliate to Philip Morris International Inc. (PMI) since 2005, we have the vision to be regarded as the most respected company in Indonesia. We place our "Three Hands Philosophy" mission at heart, which represents our key stakeholders including adult consumers, employees & business partners, and society at large, to embrace in synergy and continuously innovate to reach new milestones. To deliver high-quality products for our adult consumers, we focused on our employees by formulating an inclusive and vibrant working environment. Our diverse and global teams offer a wide range of perspectives for anyone keen to learn something new every day. That is why Sampoerna has been certified as a “Top Employer” in Indonesia by the Top Employers Institute for the past years in a row. This certification is further recognition of Sampoerna's transformation progress and firmly establishes Sampoerna among the ranks of employers of choice that are focused on meeting the needs of a globally diverse workforce. Here, we strive to #MakeHistory by creating a positive impact for society at large. The initiatives towards sustainability are encapsulated in “Sampoerna for Indonesia” (“Sampoerna Untuk Indonesia”) which represents our commitment to continuously contribute to Indonesia’s development. To help the growth of our business partners and society at large, we are continuously committed to improving the MSME’s (UMKM) skills with various integrated and comprehensive training through the Sampoerna Entrepreneurship Training Center (SETC) and the Sampoerna Retail Community (SRC). With our current mission to lead the transformation of the tobacco industry, we believe that we are preparing the business for the future and create wider societal value for all stakeholders.
At Djarum, we view our people as the foundation of our success. We look for people who have a passion for progress, combined with key qualities of humility, dedication and sincerity. These are the values have enabled us to work harmoniously yet dynamically over the past six decades, generating real progress and products.
We’re JTI, Japan Tobacco International and we believe in freedom. We think that the possibilities are limitless when you’re free to choose. In fact, we’ve spent over 20 years innovating, creating new and better products for our consumers to choose from. It’s how we’ve grown to be present in 130 countries. But our business isn’t just business. Our business is our people. Their talent. Their potential. We believe when they’re free to be themselves, grow, travel and develop, amazing things can happen for our business. That’s why our employees, from around the world, choose to be a part of JTI. 83% of employees feel happy working at JTI. And that's why we’ve been awarded Global Top Employer status, 10 years running. So when you’re ready to choose a career you’ll love, in a company you’ll love, feel free to #JoinTheIdea. A 'follow' confirms you are 18+
Latest updates, reports, and threat intel affecting the global network.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message.ex and program routines 'Elixir.GRPC.Compressor.Gzip':decompress/1, 'Elixir.GRPC.Message':from_data/2. 'Elixir.GRPC.Compressor.Gzip':decompress/1 calls :zlib.gunzip/1 directly on attacker-controlled bytes with no decompressed-size limit, ratio check, or incremental decoding. Because this module is the registered gzip GRPC.Compressor implementation, it is invoked automatically whenever an incoming gRPC frame carries the grpc-encoding: gzip header. :zlib.gunzip/1 allocates the entire decompressed result as a single binary, so a small highly compressible payload (for example a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single call. The max_receive_message_length limit is enforced only against the already-decompressed message, so it provides no protection. An unauthenticated remote peer can send a single crafted frame to exhaust the BEAM node's heap and trigger an out-of-memory kill. This issue affects grpc: from 0.4.0 before 1.0.0.
Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_body/3 (lib/grpc/server/adapters/cowboy/handler.ex) accumulates every received chunk into a single growing binary with no size cap. Additionally, when the client omits the grpc-timeout header, the per-chunk read timeout resolves to :infinity, allowing a slow-trickle client to keep the connection alive indefinitely while memory grows. A single connection is sufficient to exhaust server memory and crash the node. This issue affects grpc from 0.3.1 before 1.0.0.
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process. This issue affects grpc from 0.4.0 before 1.0.0.
The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a shell command by interpolating the user-controlled cypress_config_filepath value into a template literal, then executes it via child_process.execSync(). Shell metacharacters in the config path (specifically " and ;) allow breaking out of the quoted argument and injecting arbitrary commands. This issue has been fixed in version 1.36.6.
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body. In 'Elixir.GRPC.Server.Transcode':map_request/5 (lib/grpc/server/transcode.ex), all three clauses use Map.merge/2 with path bindings as the first argument, giving them the lowest merge precedence. A request such as GET /users/me/profile?user_id=victim (or a POST with {"user_id": "victim"} when body: "*") yields a decoded protobuf struct where the path-bound field carries the attacker-supplied value rather than the router-extracted value. Any handler that uses the path-bound field for authorization, multi-tenancy scoping, or ownership checks is silently bypassed. This issue affects grpc from 0.8.0 before 1.0.0.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.