SE A.I CyberSecurity Scoring
04/12/2025
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Sparkle for Enterprises in 2026.
No incidents recorded for Sparkle for Enterprises in 2026.
No incidents recorded for Sparkle for Enterprises in 2026.
We are a forward-focused digital champion always been focused on innovation and evolution. Our purpose is to create and bring greater dimension and richness to people’s personal and professional lives. With stc, You will always be empowered to focus on delivering what’s next through collaborative and agile ways of working, and a culture that is open to fresh ideas. Transforming the future through impactful digital solutions and mega-projects while fostering our commitment to sustainability. Join a people-centric environment; that cares about maximizing your wellbeing, and is committed to unlocking your potential.
Globe is a leading full-service telecommunications company in the Philippines and publicly listed in the PSE with the stock symbol GLO. The company serves the telecommunications and technology needs of consumers and businesses across an entire suite of products and services including mobile, fixed, broadband, data connectivity, internet and managed services. It has major interests in financial technology, digital marketing solutions, venture capital funding for startups, and virtual healthcare. In 2019, Globe became a signatory to the United Nations Global Compact, committing to implement universal sustainability principles. Its principals are Ayala Corporation and Singtel, acknowledged industry leaders in the country and in the region. VISION We see a Philippines where Families' dreams come true, Businesses flourish, and the Nation is admired. MISSION To do our part, we create Wonderful Experiences for people to have choices, Overcome Challenges, and discover new ways to Enjoy Life. OUR VALUES We put our customers first. We value People & together we make the difference. We act with integrity. We care like an owner. We keep things simple. We move Fast, We are Better Everyday.
TELMEX, la empresa líder de telecomunicaciones y servicios TI en México, ha realizado importantes inversiones para desarrollar la plataforma tecnológica más robusta y vanguardista del país, que le permite ofrecer la más amplia gama de soluciones, con los mayores estándares de calidad, seguridad, confiabilidad y competitividad; por ello, es el mejor socio estratégico en servicios avanzados de telecomunicaciones y TI. Las Soluciones TI de TELMEX van desde la Conectividad hasta Servicios de Nube, Centros de Datos, Ciberseguridad, Colaboración y Soluciones de Negocio. Un portafolio enfocado a cubrir las necesidades y proporcionar atención en infraestructura y procesos, lo que permite a los clientes aprovechar al máximo su inversión en tecnología, mientras evolucionan hacia nuevos sistemas y plataformas como servicio. TELMEX permite desarrollar e implementar proyectos en empresas de cualquier tamaño y en cualquier vertical de industria, ofreciendo soluciones integrales, innovadoras y de clase mundial, a través de tecnología de punta; brindando conectividad soportada por la mayor cobertura nacional e internacional y anchos de banda que garantizan la continuidad de las operaciones de sus clientes.
At TELUS, our purpose-driven team works together every day to innovate and do good. From providing technology solutions that make our lives safer and easier, to supporting those who need it most, our inclusive, spirited and giving people are passionate about empowering our customers, communities and each other to thrive in our digital world. A company that helps you be your best self at home and at work: Find a place where you truly belong, your opinions are valued and you can be your best self. A career that ignites your full potential: Get the guidance and support you need to explore your interests, build your skills and get where you want to go. A culture that goes beyond the expected to strengthen communities and the planet: Seize the opportunity to make a difference in our communities and do good for our planet as part of our purpose-driven team. An innovative team committed to solving complex, real world problems: Join a digitally-enabled workforce that’s pushing the boundaries to create sustainable change. We're always building Canada, join us at www.telus.com/careers
Ciena (NYSE:CIEN) is the global leader in high-speed connectivity. We build advanced networks to support exponential growth in bandwidth demand—empowering our customers, partners, and communities to thrive in the AI era. With unparalleled expertise and innovation, our networking systems, interconnects, automation software, and services revolutionize data transmission and network management.
Safaricom is the leading provider of converged communication solutions in Kenya. In addition to providing a broad range of first-class products and services for Telephony, Broadband Internet and Financial services, Safaricom seeks to uplift the welfare of Kenyans through value-added services and support for community projects. With over 29 Million subscribers and an estimated market share of 67%, the Company has the widest modern mobile network coverage in Kenya and prides in its experienced shareholders, attractive tariffs, a nationwide network of effective dealers, high caliber staff and management enabling it to maintain its position as the region’s mobile market leader. M-PESA has over 23 million subscribers, supported by a nationwide agent network of over 156,000 outlets. M-PESA is the world's most developed biggest mobile payment system. Facts about Safaricom • Employs over 5,500 staff directly and over 500,000 indirectly • Has approximately 4,945 network sites across the country • 50% of employees and 32% of senior management working at Safaricom are women. • Has the largest call center in Sub-Saharan Africa Our people are our most valuable asset and are key to the achievement of our vision of transforming lives. This is reflected in our commitment to creating a working environment that supports our staff. We offer employees a wellness programme, crèche facilities, access to subsidized gym facilities, leisure amenities, regular social events, competitive salaries and career opportunities. We give back to the society through the Safaricom Foundation. Since inception, the foundation has disbursed 2 billion shillings in different initiatives that provide sustainable community-based solutions, contributing towards Kenya’s development agenda, and the Millennium Development Goals. Safaricom is a key member and supporter of the B Team and the B Team – Africa, alliances of business leaders who are committed to responsible and sustainable business practices.
SFR is the number one alternative telecoms operator in France. SFR is also an operator providing a comprehensive range of services meeting the expectations of private and business customers alike, offering them the best of the digital world. At year-end 2011, the total number of mobile customers was 21.5 million, and the active broadband residential customer base represented 5 million customers, which represent respectively a 31.3% and 22% market share.
We’re the people who make the net work. As the nation’s largest wholesale broadband network, we’re rolling out Ultrafast Full Fibre broadband across the UK. It’s our fastest and most reliable broadband yet, and we’re well on our way to making it available to 25m homes and businesses – building the UK’s fibre future. Check openreach.co.uk/ultrafastfullfibre to see when Ultrafast Full Fibre may be available at your address.
VEON is a global digital operator headquartered in Dubai, providing connectivity and digital services across dynamic frontier markets that are home to more than 6% of the world’s population. With our digital operators, we transform lives through technology-driven services that empower millions and drive economic growth. Social media guidelines: We want everybody to have a positive and welcoming experience across the social media channels we use - and so we ask that everyone keeps their comments and discussions on VEON's page, or posts tagging the company, respectful to other members and our teams. Content which is abusive or harassing, obscene, deceptive or misleading, contains false or defamatory information, is discriminatory against any individual or group, or is considered spam may be removed - including reporting and blocking users responsible from our social media channels.
Latest updates, reports, and threat intel affecting the global network.
Honoring standout achievements in building the automated network supply chain for the AI era. DALLAS, Nov. 12, 2025 (GLOBE NEWSWIRE)...
Antonella Sanguineti explains how Sparkle's efforts can avert looming threats from quantum computing. Partner Content: Sparkle.
Algerian operator Algerie Telecom, which offers a wide range of fixed-line, internet and enterprise solutions and Sparkle,...
Unveiled at the Italy-Algeria Business Forum, the MoU outlines a strategic partnership aimed at accelerating Algeria's digital...
TIM Group's global operator Sparkle and Al-Bawaba for Telecommunications and Informatics, a Libyan ISP provider offering a wide range of ICT...
Mphasis, an IT solutions provider specializing in cloud and cognitive services, has partnered with SecPod, a SaaS-based cybersecurity...
MEF recently completed our second annual Global NaaS Event (GNE), gathering leaders and stakeholders from 140 organizations globally to advance NaaS across an...
GMA Network and Bank of the Philippine Islands (BPI) have teamed up, once again, to spread awareness about cybersecurity during a workshop.
Sparkle has joined their plan to construct a new subsea cable system – renamed MANTA – connecting the US, Mexico, Panama and Colombia.
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_SSL_CID_OUT_LEN_MAX) into that buffer without a destination-size parameter, so a caller-supplied optlen smaller than the CID causes a write of up to 31 bytes past the buffer end. In CONFIG_USERSPACE builds the getsockopt syscall verifier (z_vrfy_zsock_getsockopt) bounce-buffers the user's optval into a kernel allocation of exactly optlen bytes (k_usermode_alloc_from_copy -> z_thread_malloc), so an unprivileged user thread that passes a small optlen on a connected DTLS socket with Connection ID enabled induces a kernel-heap buffer overflow, with the overflowing content being the remote peer's CID. The defect requires CONFIG_MBEDTLS_SSL_DTLS_CONNECTION_ID, an established DTLS session with a negotiated peer CID, and (for the kernel-crossing case) CONFIG_USERSPACE. Introduced when the TLS_DTLS_CID option was added (v3.5.0). The fix rejects callers whose optlen is below MBEDTLS_SSL_CID_OUT_LEN_MAX with -EINVAL.
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-19 01:07:01 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity since 2026-05-19 01:07:01, and clean local clones.
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote ctx.fds[ctx.nfds] and incremented ctx.nfds with no bounds check. Two independent paths mutate ctx concurrently: the background autohandler running on the system workqueue, and user-triggered operations reached through the updatehub run shell command, direct API calls, or — since the operations are exposed as syscalls — userspace threads. When a second flow enters prepare_fds() while ctx.nfds is already 1, the write lands one element past the array; by struct layout it overlaps the adjacent ctx.sock/ctx.nfds members. More broadly, the unsynchronized sharing lets two flows interleave connection setup and teardown, double-closing a socket descriptor or scribbling the shared buffers. The result is corruption of the update subsystem's internal state and denial of service of the firmware-update path; the out-of-bounds write is contained within the ctx structure and there is no demonstrated path to memory outside it or to code execution. Triggering requires a local actor able to invoke update operations (or, with CONFIG_USERSPACE, an unprivileged userspace thread) and to win a timing race against the background handler; remote peers cannot control the race timing. The fix serializes the entry points with a mutex and adds a bounds check to prepare_fds().
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.