SPDX SBOM A.I CyberSecurity Scoring
29/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for SPDX SBOM in 2026.
No incidents recorded for SPDX SBOM in 2026.
No incidents recorded for SPDX SBOM in 2026.
Latest updates, reports, and threat intel affecting the global network.
Let's look at the available open-source tools that generate SBOMs. General tools: Syft, The SBOM Tool, Tern, CycloneDX Generator, SPDX SBOM...
NEWS RELEASE: ICS Launches SBOMGuard: A Powerful SBOM Tool Purpose-Built for Medical Device Cybersecurity in a Complex Threat Landscape ICS'...
A Software Bill of Material (SBOM) is a comprehensive inventory that details every software component that makes up an application.
Software development teams started using SBOMs over a decade ago to manage open-source libraries and third-party repositories. Cybersecurity concerns moved...
As cybersecurity legislation takes hold, it will become apparent how SBOM authoring and distribution tools for embedded systems will evolve.
Working with the world's largest enterprises and global policymakers to address the complexities of optimizing your software supply chain...
Explore SBOM standards and formats like CycloneDX, SPDX, and SWID. Learn how they boost transparency, security, and compliance in software...
This release introduces the CSMS Cockpit, enabling automotive OEMs and device manufacturers to significantly improve their cybersecurity management...
SBOMs are a crucial step forward in providing visibility and ultimately, greater resilience across the entire software supply chain.
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.