Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Red Hat

Red Hat Vendor Cyber Rating & Cyber Score

redhat.com

Red Hat is the world’s leading provider of enterprise open source solutions, using a community-powered approach to deliver high-performing Linux, hybrid cloud, edge, and Kubernetes technologies. We hire creative, passionate people who are ready to contribute their ideas, help solve complex problems, and make an impact. Opportunities are open. Join us.


Red Hat A.I CyberSecurity Scoring

Red Hat
Company Information
Website:http://www.redhat.com
Employees number:19,335
Number of followers:1,511,408
NAICS:5112
Industry Type:Software Development
Homepage:redhat.com
Red Hat Risk Score (AI oriented)
Between 650 and 699
logo
Red HatSoftware Development
Updated:
01/04/2026
682/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Red Hat Global Score (TPRM)
xxxx
logo
Red HatSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Red Hat
Red HatWeak
Current Score
682B (WEAK)
01000
5 incidents
-40 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
688Before Incident
MAY 2026
686Before Incident
APRIL 2026
684Before Incident
MARCH 2026
682Before Incident
FEBRUARY 2026
677Before Incident
JANUARY 2026
677Before Incident
DECEMBER 2025
672Before Incident
NOVEMBER 2025
671Before Incident
OCTOBER 2025
736Before Incident
Breach
07 Oct 2025Red Hat
Red Hat Consulting

Red Hat Consulting Data Breach by Crimson Collective

667After Incident
CRITICAL-69
RED4732847100725
Red Hat Consulting, a provider of expert technical services to large enterprises, suffered a major breach by the extortion group Crimson Collective, linked to actors associated with LAPSUS$ and Scattered Spider. The attackers exfiltrated customer documentation, source code, proprietary consultancy reports, and sensitive assets, including .pfx private certificates for entities like ING Bank and Delta Airlines. Over 32 million files were compromised, affecting more than 5,000 enterprise customers, including high-profile organizations such as HSBC, Walmart, NHS Scotland (via Atos Group), AIR, AMEX_GBT, and BOC.The breach exposed consultancy engagement reports, internal assets, and proprietary code, posing severe risks of fraud, intellectual property theft, and operational disruption. The leaked data includes highly sensitive credentials and certificates, necessitating urgent remediation, including credential rotation, security reviews, and incident response measures. The scale and sensitivity of the stolen data suggest long-term reputational damage, financial losses, and potential regulatory penalties. Crimson Collective’s ties to LAPSUS$—known for high-impact attacks on telecoms and critical services—further escalate the threat severity, as the group has demonstrated a pattern of targeting major service providers with systemic consequences.
INCIDENT DETAILS -
TYPE
Data BreachExtortionUnauthorized Access
MOTIVATION
Financial GainNotorietyData Theft for Extortion
IMPACT
Customer DocumentationSource CodeConsultancy Engagement Reports (CERs)Private Certificates (.pfx)Proprietary CodeInternal AssetsOperational Impact: High (urgent credential rotation, security reviews, and remediation required for 5,000+ enterprise customers)Brand Reputation Impact: Severe (high-profile breach with sensitive data exposure, including major corporations like HSBC, Walmart, and ING Bank)Legal Liabilities: Potential (due to exposure of sensitive customer data, including PII and proprietary information)Identity Theft Risk: High (private certificates and internal assets leaked)
DATA BREACH
Customer DocumentationSource CodeConsultancy ReportsPrivate Certificates (.pfx)Proprietary CodeInternal AssetsNumber Of Records Exposed: 32,000,000+ files (370,852 directories, 3,438,976 files initially leaked)Sensitivity Of Data: High (includes private certificates, PII, and proprietary enterprise data)Data Exfiltration: Yes (2.2 GB ZIP file leaked, with file tree evidence).pfx (private certificates)PDF (consultancy reports)Source code filesInternal documentsPersonally Identifiable Information: Likely (given the nature of consultancy reports and private certificates)
SEPTEMBER 2025
782Before Incident
Breach
01 Sep 2025Red Hat
Red Hat (Consulting Division)

Red Hat Consulting Division Supply Chain Compromise by Crimson Collective

734After Incident
CRITICAL-48
RED4292342100825
The Crimson Collective, a cybercriminal group, executed a supply chain breach of Red Hat’s consulting division, compromising ~800 organizations, including U.S. defense contractors (Naval Surface Warfare Centers, SOCOM, Raytheon), government agencies (House of Representatives, NASA’s JPL), and critical infrastructure entities. The stolen data includes Customer Engagement Reports (CERs)—highly sensitive blueprints containing network architectures, authentication tokens, API keys, and infrastructure configurations, effectively granting attackers backdoor access to hundreds of interconnected systems. The breach was timed to exploit the U.S. federal government shutdown (Oct 1, 2025), crippling incident response when cybersecurity teams were understaffed. Attackers waited since mid-September, testing capabilities via attacks on Nintendo and Claro Colombia before disclosing the breach at peak vulnerability. The data is now for sale with an Oct 10 deadline, while the government remains partially paralyzed. The exposure includes cryptic defense projects, risking compromised entry points into critical systems. Collaborating with ShinyHunters’ extortion-as-a-service platform, the attack represents an ecosystem exploitation-as-a-service model, targeting entire supply chains rather than individual entities. The precision, timing, and target selection (aligning with nation-state intelligence priorities) suggest potential state-sponsored involvement or direction, weaponizing political divisions and technical gaps for asymmetric warfare. The fallout threatens U.S. defense industrial base resilience, with implications for allies and global cybersecurity stability.
INCIDENT DETAILS -
TYPE
supply chain attackdata breachextortionespionage (potential)
MOTIVATION
financial gain (extortion)strategic disruptionpotential nation-state intelligence collectionweaponizing political timing
IMPACT
Customer Engagement Reports (CERs)network architecturesauthentication tokensAPI keysinfrastructure configurationsproject blueprints (including defense systems)forensic investigations required per organizationsecurity architecture rebuildspotential defense system compromiseshigh (defense contractors, government agencies)loss of trust in Red Hat consulting services
DATA BREACH
Customer Engagement Reports (CERs)network architecturesauthentication tokensAPI keysinfrastructure configurationsproject blueprintshigh (defense systems, government networks)critical infrastructureconsulting deliverablesconfiguration filesauthentication tokens
AUGUST 2025
782Before Incident
JULY 2025
781Before Incident
JUNE 2025
784Before Incident
Vulnerability
16 Jun 2025Red Hat
Red Hat

Critical Privilege Escalation Vulnerability in Red Hat OpenShift AI (CVE-2025-10725)

781After Incident
CRITICAL-3
RED1694016100125
A critical privilege escalation vulnerability (CVE-2025-10725, CVSS 9.9) was discovered in Red Hat OpenShift AI, a platform for managing AI/ML workloads across hybrid clouds. The flaw allows a low-privileged authenticated attacker (e.g., a data scientist with standard Jupyter notebook access) to escalate privileges to full cluster administrator, compromising the entire infrastructure. This enables theft of sensitive data, disruption of all hosted services, and complete takeover of the underlying systems—posing a total breach risk to the platform and its applications.Affected versions include OpenShift AI 2.19, 2.21, and RHOAI. While Red Hat classified it as 'Important' (due to the authentication prerequisite), the impact is severe: attackers could exfiltrate proprietary AI models, customer data, or internal research, halt critical operations, or pivot to broader network infiltration. Mitigations involve restricting broad permissions (e.g., `kueue-batch-user-role` bindings) and enforcing least-privilege access for job creation. The vulnerability underscores risks in AI/ML infrastructure, where compromised environments could lead to operational shutdowns, intellectual property theft, or cascading supply-chain attacks.
INCIDENT DETAILS -
TYPE
Privilege Escalation / Vulnerability Exploitation
IMPACT
Sensitive data hosted on the clusterRed Hat OpenShift AI clusters (versions 2.19, 2.21, RHOAI)Jupyter notebook environmentsUnderlying infrastructure and hosted applicationsDowntime: Potential total disruption of servicesOperational Impact: Complete compromise of confidentiality, integrity, and availabilityBrand Reputation Impact: High (due to potential total breach of AI/ML platforms)
DATA BREACH
Sensitive data stored in OpenShift AI clustersPotentially all data hosted on the platformSensitivity Of Data: High (includes AI/ML models, training data, and operational data)Data Exfiltration: Possible (if attacker steals sensitive data)
JULY 2024
782Before Incident
Vulnerability
01 Jul 2024Red Hat
Red Hat Enterprise Linux

Critical Use-After-Free Vulnerability in Linux Kernel (CVE-2024-36904)

778After Incident
CRITICAL-4
RED318031825
The critical use-after-free vulnerability in the Linux kernel, designated CVE-2024-36904, has significant implications for Red Hat Enterprise Linux and its derivatives. This flaw, existing undetected for seven years, impacts the TCP subsystem enabling remote code execution with kernel privileges. The revelation of this vulnerability through a public PoC exploit by security researchers raises alarm, as it bypasses kernel defenses under specific conditions. Enterprises deploying Red Hat and related systems are at risk of a complete system compromise, endangering the integrity and confidentiality of their operations. Immediate patching has been advised to mitigate risks, with a patch released in July 2024. This vulnerability not only highlights the necessity of continual vigilance in cybersecurity but also underscores the latent threats residing in long-standing systems.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Red Hat Enterprise Linux and its derivativesOperational Impact: Complete system compromise
JUNE 2020
802Before Incident
Breach
16 Jun 2020Red Hat
Red Hat

Red Hat Security Incident Involving Self-Managed GitLab Instance

748After Incident
CRITICAL-54
RED3233032100325
Red Hat is investigating a security breach involving a self-managed GitLab Community Edition instance used exclusively by Red Hat Consulting. The attack, claimed by the hacker group Crimson Collective, resulted in the theft of ~570 GB of data from 28,000 internal projects, including 800 Customer Engagement Reports (CERs). These CERs contained sensitive details such as infrastructure configurations, authentication keys, and database URIs, which the attackers allegedly used to access downstream customer systems (e.g., Bank of America, T-Mobile, AT&T, Fidelity, Walmart). The breach occurred ~two weeks before detection (late September 2024), with attackers publishing directory listings of stolen repositories and CERs (2020–2025) on Telegram. Red Hat isolated the compromised instance, revoked attacker access, and reported the incident to authorities. While Red Hat asserts no impact on its software supply chain or other services, the attackers claim to have extorted the company but received only generic vulnerability reporting instructions. The group also vandalized Nintendo’s topic page around the same time, suggesting broader malicious activity.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessExtortion Attempt
MOTIVATION
Data TheftExtortionPotential Downstream Attacks on Customers
IMPACT
Internal Project Data (28,000 projects, ~570 GB)Customer Engagement Reports (800 CERs, 2020–2025)Authentication KeysDatabase URIsInfrastructure DetailsConfiguration DataSelf-Managed GitLab Community Edition Instance (Red Hat Consulting)Isolation of Affected GitLab InstanceOngoing InvestigationPotential Customer Infrastructure RisksPotential Erosion of Trust (High-Profile Customers Affected)Media Coverage of BreachHigh (PII/Authentication Keys in CERs)
DATA BREACH
Source CodeCustomer Engagement Reports (CERs)Authentication KeysDatabase URIsInfrastructure Configurations28,000 Internal Projects800 CERsSensitivity Of Data: High (Includes PII, Credentials, and Customer Infrastructure Details)Repository CodePDF/Document Files (CERs)Configuration Files

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Red Hat ?
?
What was Red Hat's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Red Hat's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Red Hat's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Red Hat ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Red Hat's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?