Company Details
oncore-mfg-inc
13
217
None
bloomberg.com
0
ONC_1624083
In-progress

OnCore Manufacturing Services Company CyberSecurity Posture
bloomberg.comOnCore Manufacturing Services LLC provides electronic manufacturing and product commercialization services. It provides design and engineering services, including product design services, design for manufacturability reviews, and test development services; and manufacturing solutions, including supply chain solutions, electronics assembly/PCBA, system integration and test, direct fulfillment, and repairs. The company also offers simple wiring kits, flat cables, coaxial harness assemblies, multi conductor I/O cables, simple harness assemblies, and coaxial RF cable assemblies.
Company Details
oncore-mfg-inc
13
217
None
bloomberg.com
0
ONC_1624083
In-progress
Between 750 and 799

OMS Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported that OnCore Manufacturing Services experienced a data breach on July 5, 2013. The breach involved the theft of a company laptop that contained sensitive employee information, including names, Social Security Numbers, and employment details. Approximately 00000 individuals were affected by this incident.


No incidents recorded for OnCore Manufacturing Services in 2025.
No incidents recorded for OnCore Manufacturing Services in 2025.
No incidents recorded for OnCore Manufacturing Services in 2025.
OMS cyber incidents detection timeline including parent company and subsidiaries

OnCore Manufacturing Services LLC provides electronic manufacturing and product commercialization services. It provides design and engineering services, including product design services, design for manufacturability reviews, and test development services; and manufacturing solutions, including supply chain solutions, electronics assembly/PCBA, system integration and test, direct fulfillment, and repairs. The company also offers simple wiring kits, flat cables, coaxial harness assemblies, multi conductor I/O cables, simple harness assemblies, and coaxial RF cable assemblies.


Based in Morrisville, Vermont along the spine of the Green Mountains, STI is equipped to work with titanium, ceramics, and other challenging and demanding materials. STI develops innovative processes that produce consistent and predictable results for our customers. We have state of the art 5 axi

Paragon Products is a leading global innovator of electromechanical fluid management technologies for large diesel engine and heavy equipment applications for OEMs and end-users alike. For more than 25 years, we've been designing and manufacturing fluid control solutions that keep industry moving—p

If it's metal, we can make it! We are a full service precision machine components and tooling manufacturer. We have the tools and the expertise to manufacture for the automotive, shipbuilding, power generations & research industries. We are proud to be a supplier of technical services and products t

GRAVOTECH GROUP: WORLD NUMBER 1 IN PERMANENT MARKING The Gravotech group is the worldwide leader in the design, manufacture and distribution of innovative solutions for engraving, marking and artistic modelling. Gravotech has over 900 employees in over 100 countries. The group boasts a vast internat

The Innovation Center by Viable Engineering Solutions is a world-class industrial rapid solution concept-to-completion center for the industrial market. We take Research and Development to the next level by providing complete all-in-one fast prototyping solutions for industrial problems in our stat

Sophisticated industrial torque tool users reach for tools that are accurate, reliable, and durable. They need tools they trust. Sturtevant Richmont makes tools you trust. How durable is durable? We stopped making our Cal-30 torque screwdriver in 1972. We still get those tools back for calibration.
.png)
ServiceNow Inc. is reportedly in advanced talks to acquire Veza Inc., a startup with an identity management platform of the same name.
A 15-year-old known online as “Rey” has been allegedly identified as a key figure in Scattered LAPSUS$ Hunters (SLSH), a hacking group said...
Thinking about whether Palo Alto Networks is a buy right now? If you have even a hint of curiosity about the stock's value,...
By Juliet ETEFE ([email protected]) Virtual Infosec Africa (VIA), in partnership with global cybersecurity firm Exabeam, has launched Ghana's...
Mohit Chawla, Deputy Inspector General (DIG) of Himachal Pradesh Police, has been honoured with the Chief Information Security Officer...
CINCINNATI (WXIX) -As Black Friday weekend approaches, cybersecurity experts are warning shoppers about increased online scams targeting...
There have been a lot of updates in privacy and cybersecurity in the last month. Read on to find out what they are.
As the social media ban for kids under 16 approaches, popular messaging app Snapchat says young people will be able to verify their age by...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of OnCore Manufacturing Services is https://www.bloomberg.com/research/stocks/private/snapshot.asp?privcapId=1136848.
According to Rankiteo, OnCore Manufacturing Services’s AI-generated cybersecurity score is 751, reflecting their Fair security posture.
According to Rankiteo, OnCore Manufacturing Services currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, OnCore Manufacturing Services is not certified under SOC 2 Type 1.
According to Rankiteo, OnCore Manufacturing Services does not hold a SOC 2 Type 2 certification.
According to Rankiteo, OnCore Manufacturing Services is not listed as GDPR compliant.
According to Rankiteo, OnCore Manufacturing Services does not currently maintain PCI DSS compliance.
According to Rankiteo, OnCore Manufacturing Services is not compliant with HIPAA regulations.
According to Rankiteo,OnCore Manufacturing Services is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
OnCore Manufacturing Services operates primarily in the Mechanical Or Industrial Engineering industry.
OnCore Manufacturing Services employs approximately 13 people worldwide.
OnCore Manufacturing Services presently has no subsidiaries across any sectors.
OnCore Manufacturing Services’s official LinkedIn profile has approximately 217 followers.
OnCore Manufacturing Services is classified under the NAICS code None, which corresponds to Others.
No, OnCore Manufacturing Services does not have a profile on Crunchbase.
Yes, OnCore Manufacturing Services maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/oncore-mfg-inc.
As of November 28, 2025, Rankiteo reports that OnCore Manufacturing Services has experienced 1 cybersecurity incidents.
OnCore Manufacturing Services has an estimated 2,060 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: OnCore Manufacturing Services Data Breach
Description: The California Office of the Attorney General reported that OnCore Manufacturing Services experienced a data breach on July 5, 2013. The breach involved the theft of a company laptop that contained sensitive employee information, including names, Social Security Numbers, and employment details. Approximately 00000 individuals were affected by this incident.
Date Detected: 2013-07-05
Type: Data Breach
Attack Vector: Theft of Laptop
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Social security numbers, Employment details
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, Employment Details and .

Entity Name: OnCore Manufacturing Services
Entity Type: Company
Industry: Manufacturing
Customers Affected: 00000

Type of Data Compromised: Names, Social security numbers, Employment details
Number of Records Exposed: 00000
Sensitivity of Data: High

Source: California Office of the Attorney General
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney General.
Most Recent Incident Detected: The most recent incident detected was on 2013-07-05.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security Numbers, Employment Details and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Social Security Numbers, Employment Details and Names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 0.0.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.