ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

The Office for Budget Responsibility (OBR) was established in May 2010 to provide independent assessments of the economy, public finances and fiscal sustainability. We provide independent forecasts of the economy and public finances, examine the impact of the Government's policy decisions on the public finances, and assess the prospects for achieving the Government's fiscal targets and welfare cap. We publish reports on long-term fiscal sustainability, fiscal risks and trends in welfare spending, and produce papers on economic and fiscal issues. Contact us at [email protected] or 02033346117

Office for Budget Responsibility A.I CyberSecurity Scoring

OBR

Company Details

Linkedin ID:

office-for-budget-responsibility

Employees number:

52

Number of followers:

1,703

NAICS:

92

Industry Type:

Government Administration

Homepage:

obr.uk

IP Addresses:

0

Company ID:

OFF_1177795

Scan Status:

In-progress

AI scoreOBR Risk Score (AI oriented)

Between 650 and 699

https://images.rankiteo.com/companyimages/office-for-budget-responsibility.jpeg
OBR Government Administration
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreOBR Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/office-for-budget-responsibility.jpeg
OBR Government Administration
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

OBR Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Office for Budget Responsibility (OBR)Breach100611/2025
Rankiteo Explanation :
Attack threatening the economy of geographical region

Description: The **Office for Budget Responsibility (OBR)**, the UK’s independent fiscal watchdog, suffered a **critical data breach** when its **full fiscal forecast and key budget measures** were **prematurely published online**—**30 minutes before Treasury Chief Rachel Reeves’ official announcement** in the House of Commons. The leak, attributed to a **‘technical error’**, exposed **sensitive economic projections, tax policies, and financial strategies** meant to remain confidential until the formal budget release. The incident occurred amid **political turmoil**, undermining public trust in the government’s ability to manage confidential information.The OBR acknowledged the **serious error**, pledging investigations and reports to relevant authorities, including the Treasury. The leak **disrupted market expectations**, risked **insider trading or speculative financial moves**, and **embarrassed the Labour government**, which was already grappling with **internal dissent, broken election pledges, and economic instability**. While no **direct financial theft or ransomware** was involved, the **unauthorized disclosure of high-stakes economic data**—critical to national fiscal policy—**threatened financial market stability** and **eroded institutional credibility**, with opposition parties demanding resignations over the **governance failure**.

Office for Budget Responsibility (OBR)
Breach
Severity: 100
Impact: 6
Seen: 11/2025
Blog:
Rankiteo Explanation
Attack threatening the economy of geographical region

Description: The **Office for Budget Responsibility (OBR)**, the UK’s independent fiscal watchdog, suffered a **critical data breach** when its **full fiscal forecast and key budget measures** were **prematurely published online**—**30 minutes before Treasury Chief Rachel Reeves’ official announcement** in the House of Commons. The leak, attributed to a **‘technical error’**, exposed **sensitive economic projections, tax policies, and financial strategies** meant to remain confidential until the formal budget release. The incident occurred amid **political turmoil**, undermining public trust in the government’s ability to manage confidential information.The OBR acknowledged the **serious error**, pledging investigations and reports to relevant authorities, including the Treasury. The leak **disrupted market expectations**, risked **insider trading or speculative financial moves**, and **embarrassed the Labour government**, which was already grappling with **internal dissent, broken election pledges, and economic instability**. While no **direct financial theft or ransomware** was involved, the **unauthorized disclosure of high-stakes economic data**—critical to national fiscal policy—**threatened financial market stability** and **eroded institutional credibility**, with opposition parties demanding resignations over the **governance failure**.

Ailogo

OBR Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for OBR

Incidents vs Government Administration Industry Average (This Year)

Office for Budget Responsibility has 53.85% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Office for Budget Responsibility has 56.25% more incidents than the average of all companies with at least one recorded incident.

Incident Types OBR vs Government Administration Industry Avg (This Year)

Office for Budget Responsibility reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.

Incident History — OBR (X = Date, Y = Severity)

OBR cyber incidents detection timeline including parent company and subsidiaries

OBR Company Subsidiaries

SubsidiaryImage

The Office for Budget Responsibility (OBR) was established in May 2010 to provide independent assessments of the economy, public finances and fiscal sustainability. We provide independent forecasts of the economy and public finances, examine the impact of the Government's policy decisions on the public finances, and assess the prospects for achieving the Government's fiscal targets and welfare cap. We publish reports on long-term fiscal sustainability, fiscal risks and trends in welfare spending, and produce papers on economic and fiscal issues. Contact us at [email protected] or 02033346117

Loading...
similarCompanies

OBR Similar Companies

France Travail

France Travail est un acteur majeur du marché de l’emploi en France où il s’investit pour faciliter le retour à l’emploi des demandeurs d’emploi et offrir aux entreprises des réponses adaptées à leurs besoins de recrutement. Les 55 000 collaborateurs de France Travail œuvrent au quotidien pour êtr

Etat de Vaud

Le canton de Vaud, c’est plus de 800 000 personnes vivant dans plus de 300 communes ! Rejoindre l’Administration cantonale vaudoise, c’est s’engager aux côtés de près de 40’000 personnes unies dans un même but : servir la population. Pourquoi nous suivre ? Dédiez votre quart d’heure vaudois aux o

I work for NSW

The NSW public sector includes ten departments and many agencies and organisations working together to develop policy and deliver important services such as health, education, housing, transport and infrastructure across NSW. We are over 300,000 dedicated people who share the same values - making a

NOAA: National Oceanic & Atmospheric Administration

Welcome! We're the National Oceanic & Atmospheric Administration or NOAA. From daily weather forecasts, severe storm warnings and climate monitoring to fisheries management, coastal restoration and supporting marine commerce, our products and services support economic vitality and affect more than

eThekwini Municipality

EThekwini Municipality is a Metropolitan Municipality found in the South African province of KwaZulu-Natal. Home to the world-famous city of Durban. EThekwini is the largest City in the province and the third largest city in the country. It is a sophisticated cosmopolitan city of over 3 468 088 peop

State of Tennessee

State government is the largest employer in Tennessee, with approximately 43,500 employees in the three branches of government. The State of Tennessee has approximately 1,300 different job classifications in areas such as administrative, health services, historic preservation, legal, agriculture, co

O Instituto Nacional do Seguro Social (INSS) é uma autarquia do Governo Federal do Brasil que recebe as contribuições para a manutenção do Regime Geral da Previdência Social, sendo responsável pelo pagamento da aposentadoria, pensão por morte, auxílio-doença, auxílio-acidente, entre outros benefício

Texas Health and Human Services

Overview The Texas Health and Human Services Commission (HHSC) is an agency within the Texas Health and Human Services System. In September 2016, Texas began transforming how it delivers health and human services to qualified Texans, with a goal of making the Health and Human Services System more ef

Ville de Montréal

Montréal est la plus grande ville francophone d’Amérique et elle se distingue par sa vitalité culturelle exceptionnelle et des forces créatrices reconnues mondialement. Elle se développe un peu plus chaque jour en une ville contemporaine, inclusive et dynamique sur les plans économique, culturel

newsone

OBR CyberSecurity News

November 27, 2025 10:00 AM
‘External person’ may have leaked Budget document link says OBR chief

An “external person” may have been able to access the link to the Office for Budget Responsibility (OBR)'s fiscal outlook which was leaked...

November 27, 2025 09:44 AM
OBR chair ‘mortified’ by budget leak as ex-cybersecurity chief called in to investigate

Richard Hughes, head of Office for Budget Responsibility, says he has apologised to chancellor for 'letting people down'

November 27, 2025 09:43 AM
OBR chief Richard Hughes claims 'external' actor may have been behind humiliating Budget leak as he drafts in cyber security expert to investigate - but he won't quit as watchdog boss

The OBR was left humiliated on Wednesday when it prematurely published its latest fiscal outloook before the Chancellor's Budget.

November 27, 2025 09:12 AM
OBR appoints former NCSC head Ciaran Martin to investigate UK budget leak

The Office for Budget Responsibility (OBR) has hired a cybersecurity expert as part of its investigation into the UK's budget leak,...

November 27, 2025 08:45 AM
'External person' may have accessed leaked Budget document link - OBR

An “external person” may have been able to access the link to the Office for Budget Responsibility (OBR)'s fiscal outlook which was...

November 27, 2025 08:32 AM
‘External person’ may have had access to leaked OBR Budget document

An “external person” may have been able to access the link to the Office for Budget Responsibility (OBR)'s fiscal outlook which was...

November 27, 2025 08:29 AM
'External person' may have accessed leaked Budget document link, says under-fire OBR chief

OBR chairman Richard Hughes tells Radio 4's Today: 'It appears there was a link that someone was able to access - an external person'

November 27, 2025 08:19 AM
Rachel Reeves Budget leak may have been 'external person' as OBR issues major update

Richard Hughes said he took full responsibility, adding: 'On behalf of the OBR I regret the deep disruption that it caused to the...

November 27, 2025 08:16 AM
‘External person’ may have had access to leaked OBR Budget document link

The document revealed the contents of Rachel Reeves' Budget and was accidentally published half an hour before the Chancellor announced the...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

OBR CyberSecurity History Information

Official Website of Office for Budget Responsibility

The official website of Office for Budget Responsibility is https://obr.uk/.

Office for Budget Responsibility’s AI-Generated Cybersecurity Score

According to Rankiteo, Office for Budget Responsibility’s AI-generated cybersecurity score is 684, reflecting their Weak security posture.

How many security badges does Office for Budget Responsibility’ have ?

According to Rankiteo, Office for Budget Responsibility currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Office for Budget Responsibility have SOC 2 Type 1 certification ?

According to Rankiteo, Office for Budget Responsibility is not certified under SOC 2 Type 1.

Does Office for Budget Responsibility have SOC 2 Type 2 certification ?

According to Rankiteo, Office for Budget Responsibility does not hold a SOC 2 Type 2 certification.

Does Office for Budget Responsibility comply with GDPR ?

According to Rankiteo, Office for Budget Responsibility is not listed as GDPR compliant.

Does Office for Budget Responsibility have PCI DSS certification ?

According to Rankiteo, Office for Budget Responsibility does not currently maintain PCI DSS compliance.

Does Office for Budget Responsibility comply with HIPAA ?

According to Rankiteo, Office for Budget Responsibility is not compliant with HIPAA regulations.

Does Office for Budget Responsibility have ISO 27001 certification ?

According to Rankiteo,Office for Budget Responsibility is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Office for Budget Responsibility

Office for Budget Responsibility operates primarily in the Government Administration industry.

Number of Employees at Office for Budget Responsibility

Office for Budget Responsibility employs approximately 52 people worldwide.

Subsidiaries Owned by Office for Budget Responsibility

Office for Budget Responsibility presently has no subsidiaries across any sectors.

Office for Budget Responsibility’s LinkedIn Followers

Office for Budget Responsibility’s official LinkedIn profile has approximately 1,703 followers.

NAICS Classification of Office for Budget Responsibility

Office for Budget Responsibility is classified under the NAICS code 92, which corresponds to Public Administration.

Office for Budget Responsibility’s Presence on Crunchbase

No, Office for Budget Responsibility does not have a profile on Crunchbase.

Office for Budget Responsibility’s Presence on LinkedIn

Yes, Office for Budget Responsibility maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/office-for-budget-responsibility.

Cybersecurity Incidents Involving Office for Budget Responsibility

As of November 27, 2025, Rankiteo reports that Office for Budget Responsibility has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Office for Budget Responsibility has an estimated 11,098 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Office for Budget Responsibility ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Office for Budget Responsibility detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes (obr acknowledged error and committed to reporting to authorities), and containment measures with obr removed prematurely published content; issued public apology, and remediation measures with obr pledged internal review; report to treasury and relevant authorities, and communication strategy with rachel reeves labeled the leak 'deeply disappointing and a serious error' in parliament, communication strategy with obr issued a public statement attributing the leak to a 'technical error'..

Incident Details

Can you provide details on each incident ?

Incident : Data Leak / Unauthorized Disclosure

Title: UK Government Budget Leak Incident (2024)

Description: The UK government's 2024 budget details, including a £26 billion tax-raising plan, were leaked online by the Office for Budget Responsibility (OBR) 30 minutes before Treasury chief Rachel Reeves' official announcement in the House of Commons. The OBR attributed the premature disclosure to a 'technical error,' calling it a 'serious mistake.' The leak occurred amid political turmoil, including broken election promises, economic struggles, and leadership challenges within the Labour Party.

Date Detected: 2024-11-06

Date Publicly Disclosed: 2024-11-06

Type: Data Leak / Unauthorized Disclosure

Vulnerability Exploited: Technical error (premature website publication)

Motivation: Accidental (no malicious intent confirmed)

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Data Compromised: Budget fiscal forecasts, Tax policy details (e.g., income tax threshold freezes, mansion tax, capital gains tax changes), Welfare policy changes (e.g., child benefit restrictions lifted), Economic growth projections, Public finance buffers (£22 billion)

Systems Affected: Office for Budget Responsibility (OBR) website

Operational Impact: Disrupted controlled budget announcement; political fallout including calls for resignation of Treasury chief Rachel Reeves

Brand Reputation Impact: High (government credibility undermined; opposition parties criticized Labour's competence; media coverage framed as 'chaos')

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Economic Policy Documents, Taxation Plans, Fiscal Forecasts, Welfare Reforms and .

Which entities were affected by each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Entity Name: HM Treasury (UK Government)

Entity Type: Government Department

Industry: Public Administration

Location: London, United Kingdom

Customers Affected: UK public, financial markets, political stakeholders

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Entity Name: Office for Budget Responsibility (OBR)

Entity Type: Independent Fiscal Watchdog

Industry: Public Sector/Economics

Location: London, United Kingdom

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Incident Response Plan Activated: Yes (OBR acknowledged error and committed to reporting to authorities)

Containment Measures: OBR removed prematurely published content; issued public apology

Remediation Measures: OBR pledged internal review; report to Treasury and relevant authorities

Communication Strategy: Rachel Reeves labeled the leak 'deeply disappointing and a serious error' in ParliamentOBR issued a public statement attributing the leak to a 'technical error'

What is the company's incident response plan?

Incident Response Plan: The company's incident response plan is described as Yes (OBR acknowledged error and committed to reporting to authorities).

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Type of Data Compromised: Economic policy documents, Taxation plans, Fiscal forecasts, Welfare reforms

Sensitivity of Data: High (national economic strategy; market-sensitive information)

Data Exfiltration: No (data published prematurely on OBR website, not stolen)

File Types Exposed: PDF (likely), HTML/web content

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: OBR pledged internal review; report to Treasury and relevant authorities, .

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by obr removed prematurely published content; issued public apology and .

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Regulatory Notifications: OBR committed to reporting to Treasury and other authorities

References

Where can I find more information about each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Source: Associated Press (AP)

Date Accessed: 2024-11-06

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Associated Press (AP)Date Accessed: 2024-11-06.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Investigation Status: Ongoing (OBR internal review announced)

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Rachel Reeves Labeled The Leak 'Deeply Disappointing And A Serious Error' In Parliament and Obr Issued A Public Statement Attributing The Leak To A 'Technical Error'.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Stakeholder Advisories: Rachel Reeves' Statement In House Of Commons; Obr Public Apology.

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Rachel Reeves' Statement In House Of Commons; Obr Public Apology.

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Leak / Unauthorized Disclosure OFF4794147112625

Root Causes: Technical Error In Obr'S Content Publication System,

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2024-11-06.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-11-06.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Budget fiscal forecasts, Tax policy details (e.g., income tax threshold freezes, mansion tax, capital gains tax changes), Welfare policy changes (e.g., child benefit restrictions lifted), Economic growth projections, Public finance buffers (£22 billion) and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Office for Budget Responsibility (OBR) website.

Response to the Incidents

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was OBR removed prematurely published content; issued public apology.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Public finance buffers (£22 billion), Welfare policy changes (e.g., child benefit restrictions lifted), Economic growth projections, Tax policy details (e.g., income tax threshold freezes, mansion tax, capital gains tax changes) and Budget fiscal forecasts.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Associated Press (AP).

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (OBR internal review announced).

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Rachel Reeves' statement in House of Commons; OBR public apology, .

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=office-for-budget-responsibility' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge