NDF A.I CyberSecurity Scoring
17/12/2025
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Nuclear Detection and Forensics in 2026.
No incidents recorded for Nuclear Detection and Forensics in 2026.
No incidents recorded for Nuclear Detection and Forensics in 2026.
PRIVACY POLICY at the University of Copenhagen: https://informationssikkerhed.ku.dk/english/protection-of-information-privacy/privacy-policy/ With over 40,000 students and more than 9,000 employees, the University of Copenhagen is the largest institution of research and education in Denmark. The purpose of the University – to quote the University Statute – is to ’conduct research and provide further education to the highest academic level’. Approximately one hundred different institutes, departments, laboratories, centres, museums, etc., form the nucleus of the University, where professors, lecturers and other academic staff, as well as most of the technical and administrative personnel, carry out their daily work, and where teaching takes place. These activities take place in various environments ranging from the plant world of the Botanical Gardens, through high-technology laboratories and auditoriums, to the historic buildings and lecture rooms of Frue Plads and other locations.
About Aarhus University Aarhus University is a leading international research university covering all scientific areas with a staff of 11.000 employees and 44.500 students, the majority are post-graduate students enrolled on Master’s and PhD programmes. Aarhus University is among the top 100 universities in the world. The aim of the university is to sustain and enhance a high standard in both research and education, which has placed it among the international elite. Aarhus University was established in 1928 as a small private initiative. It has since grown to become a leading public research university with international reach covering all academic fields and address basic, applied and strategic research as well as the research-based consultancy provided to public authorities and private business. One of Aarhus University’s focus areas is talent development. An activity considered so important that it is singled out as one of the four core activities in the Aarhus University strategy alongside excellent research, world-class education and inspiring research-based consultancy. Research at Aarhus University is both organised in traditional departments under the four faculties and in interdisciplinary research centres. In addition, Aarhus University researchers engage in research collaboration under the auspices of Knowledge Management Centres with external partners such as government organisations, private enterprises, NGOs and Aarhus University’s wide range of international partner universities.
Latest updates, reports, and threat intel affecting the global network.
US News: President Trump announced the US will resume nuclear testing, citing actions by Russia and China. This decision reverses a...
US News: Former President Donald Trump has called for the United States to resume nuclear weapons testing, breaking a 30-year moratorium.
US News: President Trump ordered the immediate resumption of nuclear weapons testing, ending a 33-year moratorium, citing China's...
Eighty years after the dawn of the nuclear age, current plans for the rapid expansion of advanced reactors to satisfy global energy needs...
Counterfeit goods in the nuclear supply chain pose a significant threat to security, necessitating more robust measures within India's...
Explore Industrial Control Systems (ICS) Cybersecurity and learn how to protect critical infrastructure against cyberattacks.
An interagency exercise of the National Technical Nuclear Forensics Ground Collections Task Force was successfully executed at the Nevada...
The International Atomic Energy Agency (IAEA) has provided, upon request, assistance to Member States and supported their national efforts in the area of...
These exercises enable countries to practise and prepare their response to the worst-case scenario of a breach of cybersecurity at a nuclear facility.
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules.
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/. The vulnerable sink in sub calculate concatenates the unmodified Filter request parameter directly into a LIKE clause of the auxiliary $strsth2 statement and executes it via DBI without bound parameters: my $f = @$filters[0]; $f =~ s/\*/%/g; $strsth2 .= " AND $column LIKE '$f' "; This enables error-based SQL injection (e.g., via EXTRACTVALUE) and full read access to sensitive tables including borrowers (password hashes, 2FA secrets, PII), borrower_password_recovery, api_keys, and sessions. Proof of concept (error-based, single request): GET /cgi-bin/koha/reports/catalogue_out.pl?do_it=1&output=screen&Limit=10&Criteria=branchcode&Filter=x'+AND+EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7c,USER(),0x7c,DATABASE(),0x7e))--+- Cookie: CGISESSID=<LIBRARIAN_SESSION> The response body contains the DBI exception leaking the MariaDB version, database user, client IP, and database name, after which arbitrary data can be paged out using LIMIT n,1 / SUBSTRING(...). The vulnerable sink was introduced in commit 6bb77ae3e4 (2008-07-09); CVE-2015-4633 patched the same class in sibling files but did not generalise the fix to reports/catalogue_out.pl. Fixed in Koha 22.11.38, 24.11.16, 25.05.11, 25.11.05, 26.05.01, and 26.11.00 by replacing the raw concatenation with a parameterised placeholder.
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default).
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.