SIKORA A.I CyberSecurity Scoring
24/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for SIKORA in 2026.
No incidents recorded for SIKORA in 2026.
No incidents recorded for SIKORA in 2026.
At METTLER TOLEDO, our mission is to empower industries worldwide with precision instruments and services that drive progress toward a better and more #sustainable future. Our teams operate at the forefront of #innovation, delivering cutting-edge instruments to a diverse range of industries, from #LifeSciences and #pharmaceuticals to #manufacturing and #logistics. With a rich legacy spanning several decades, METTLER TOLEDO (NYSE: MTD) has a global presence in 40 countries, serves more than 140 countries, and employs 17,300 ambitious minds. Our valued global team contributes to our success in pushing the boundaries of what’s possible in the fields of biomedical sciences, food & beverage, retail, chemical analysis, industrial sectors, transport & logistics, and academia. Through our comprehensive portfolio of solutions and services, we enable businesses to achieve new levels of accuracy, efficiency, and quality. METTLER TOLEDO products cater to the unique needs of various applications, including laboratory weighing, liquid handling, industrial weighing, chemical analysis, and product inspection, while upholding our GreenMT commitment to sustainable practices. Be at the forefront of precision and excellence and follow us for more information about live events, hiring opportunities, industry latest trends, best practices, and more. Become a member of our global team at METTLER TOLEDO https://jobs.mt.com Benefit from informational videos on our YouTube channel: https://www.youtube.com/@mettlertoledo
Latest updates, reports, and threat intel affecting the global network.
As of publication, The Daily Pennsylvanian identified four separate lawsuits filed by Penn graduates that allege the University was...
The grants support new research in cybersecurity topics related to counterfeit cell towers, online safety of military families,...
Read how a lab equipment company was set up for growth by having our virtual information security office develop and manage its...
Washington Harbour Partners LP (“Washington Harbour”), a leading private investment firm that specializes in partnering with founders and...
Ted Sikora is a Project Manager, Surveys and Business Analytics at NACD. This post is based on his NACD publication.
Walter Sikora, 59, passed away unexpectedly Saturday night, September 5, 2020. Born in São Paulo Brazil on July 25, 1961 to Jan and Anna...
By LAURA LOREK, Publisher of Silicon Hills News. Dave Sikora, CEO of ALTR. Most companies wouldn't let everyone have access to a vault of...
ALTR, a cybersecurity platform looking to unleash the benefits of blockchain, has emerged from stealth with $15m in funding.
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules.
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/. The vulnerable sink in sub calculate concatenates the unmodified Filter request parameter directly into a LIKE clause of the auxiliary $strsth2 statement and executes it via DBI without bound parameters: my $f = @$filters[0]; $f =~ s/\*/%/g; $strsth2 .= " AND $column LIKE '$f' "; This enables error-based SQL injection (e.g., via EXTRACTVALUE) and full read access to sensitive tables including borrowers (password hashes, 2FA secrets, PII), borrower_password_recovery, api_keys, and sessions. Proof of concept (error-based, single request): GET /cgi-bin/koha/reports/catalogue_out.pl?do_it=1&output=screen&Limit=10&Criteria=branchcode&Filter=x'+AND+EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7c,USER(),0x7c,DATABASE(),0x7e))--+- Cookie: CGISESSID=<LIBRARIAN_SESSION> The response body contains the DBI exception leaking the MariaDB version, database user, client IP, and database name, after which arbitrary data can be paged out using LIMIT n,1 / SUBSTRING(...). The vulnerable sink was introduced in commit 6bb77ae3e4 (2008-07-09); CVE-2015-4633 patched the same class in sibling files but did not generalise the fix to reports/catalogue_out.pl. Fixed in Koha 22.11.38, 24.11.16, 25.05.11, 25.11.05, 26.05.01, and 26.11.00 by replacing the raw concatenation with a parameterised placeholder.
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default).
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.