SAL A.I CyberSecurity Scoring
06/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Subex AI Labs in 2026.
No incidents recorded for Subex AI Labs in 2026.
No incidents recorded for Subex AI Labs in 2026.
Tata Communications is a digital ecosystem enabler that powers today’s fast-growing digital economy. We enable the digital transformation of enterprises globally, including 300 of the Fortune 500. We carry around 30% of the world’s internet routes and connects businesses to 60% of the world’s cloud giants. We have been a part of the rich heritage of the internet in India. Over the last 25 years, enterprise-enabled services have been essential to the adoption of digital services in the country. Connectivity is an essential fabric of sustenance for the economy. We are committed to enabling Industry leaders in this New World of Communications™, with our unique promise of delivering secure connected digital experiences. In 2020, we announced the launch of ‘Secure Connected Digital Experience’ (SCDx), a proposition intended to meet this growing, worldwide demand for new ways of operating, which includes far higher levels of working from home, rising security risks, a shift to digital commerce, and more contactless experiences. It will help companies currently relying on short-term fixes by providing holistic, secure, enterprise-level digital solutions that address current challenges and are fit for the long term. To know more, visit TataCommunications.com Tata Communications Limited is listed on the Bombay Stock Exchange and the National Stock Exchange of India and is present in over 200 countries and territories around the world. We are committed to being an equal opportunity workplace and to providing an inclusive environment to all employees. All qualified applicants will receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, or any other status protected by law. Tata Communications and its Recruitment Partners do not charge any fee or security deposit from the candidate for offering employment.
Lumen connects the world. We digitally connect people, data and applications – quickly, securely and effortlessly. Everything we do at Lumen takes advantage of our network strength. From metro connectivity to long-haul data transport to our edge cloud, security, and managed service capabilities, we meet our customers’ needs today and as they build for tomorrow.
Airtel was founded to provide global connectivity and unlock endless opportunities. Our organization embodies a unique blend of energy, innovation, creativity, dedication, scale, and ownership, all aimed at being limitless. At Airtel, we strive to go beyond our duties to create impactful solutions for our consumers. Our team is highly skilled and constantly growing, actively developing infrastructure to introduce cutting-edge technologies like 5G, IoT, IQ, and Airtel Black. We have successfully launched 5G services in over 5,000 cities and towns nationwide, with 10 million unique customers on the 5G network nationally. Airtel Black is another convenient consumer service that provides combined billing for family and friends under a single bill. We also offer enterprise solutions, including national and international long-distance services for carriers. With a subscriber base exceeding 574 million as of 2023, we are committed to delivering effective products that contribute to the realization of a 'Digital India', enabling millions of individuals to connect and thrive for a brighter future. Our presence spans 7,915 census and 802,577 non-census towns and villages, covering almost 96% of the country's population with 388,726 Rkms of optical fiber and an extensive distribution network of 1.2 million outlets. We've also implemented conservation initiatives that have saved 14,676 MWh of electricity, 4412 tonnes of paper through our e-bill initiatives, and recycled 3330 tonnes of e-waste. At Airtel, we believe in taking early ownership, delivering quality, and experimenting with various career paths to boost our trajectories and gain valuable insights into the business, making us the best in the industry. We are committed to creating the ultimate experience for our consumers while maintaining an ecological balance in the world.
Idea Cellular is an Aditya Birla Group Company, India's first truly multinational corporation. Idea is a pan-India integrated GSM operator offering 2G and 3G services, and has its own NLD and ILD operations, and ISP license. With revenue in excess of $4 billion; revenue market share of 18%; and subscriber base of over 150 million, Idea is India’s 3rd largest mobile operator. Idea ranks among the Top 10 country operators in the world with a traffic of over 1.5 billion minutes a day. Idea’s robust pan-India coverage is built on a network of over 100,000 2G and 3G cell sites, spread across over 55,000 towns in India. Using the latest in technology, Idea provides world-class service delivery through the most extensive network of customer touch points, comprising of nearly 4,500 exclusive Idea outlets, and over 7,000 call centre seats. Idea’s customer service delivery platform is ISO 9001:2008 certified, making it the only operator in the country to have this standard certification for all 22 service areas and the corporate office Idea won the ‘Best Brand Campaign’ at the esteemed World Communication Awards 2011. It also recently won 3 Awards at the ET Telecom Awards 2012, in the following categories Customer Experience Enhancement, Excellence in Marketing and Innovative products, respectively.
As the supercharged Un-carrier, T-Mobile US, Inc. (NASDAQ: TMUS) is powered by an award-winning 5G network that connects more people, in more places, than ever before. With T-Mobile’s unique value proposition of best network, best value, and best experiences, the Un-carrier is redefining connectivity and fueling competition while continuing to drive the next wave of innovation in wireless and beyond. Headquartered in Bellevue, Wash., T-Mobile provides services through its subsidiaries and operates its flagship brands, T-Mobile, Metro by T-Mobile, and Mint Mobile.
Somos una empresa orgullosamente mexicana, líder en tecnología, telecomunicaciones y entretenimiento. Estamos siempre a la vanguardia con el objetivo de llevar a nuestros clientes lo mejor en conectividad, ya sea para que estén cerca de los que más quieren ó puedan alcanzar el éxito profesional gracias a la velocidad que brinda la tecnología de fibra óptica. Nuestro impulso es el equipo que hemos formado, personas con talento, iniciativa, entusiastas y apasionados, que buscan siempre caminar unidos para llevar a más de 20 ciudades de la República Mexicana un servicio de excelencia. Queremos que nuestros clientes sean parte del camino al futuro y vivan al máximo la experiencia de la plataforma de conectividad y entretenimiento total.
Millicom (NASDAQ U.S.: TIGO, Nasdaq) is a leading provider of fixed and mobile telecommunications services in Latin America. Through our TIGO® and Tigo Business® brands, we provide a wide range of digital services and products, including TIGO Money for mobile financial services, TIGO Sports for local entertainment, TIGO ONEtv for pay TV, high-speed data, voice, and business-to-business solutions such as cloud and security. Millicom (NASDAQ U.S.: TIGO) is a leading provider of fixed and mobile telecommunications services in Latin America. Through our TIGO® and Tigo Business® brands, we provide a wide range of digital services and products, including TIGO Money for mobile financial services, TIGO Sports for local entertainment, TIGO ONEtv for pay TV, high-speed data, voice, and business-to-business solutions such as cloud and security. As of March 31, 2025, Millicom, including its Honduras Joint Venture, employed approximately 14,000 people, and provided mobile and fiber-cable services through its digital highways to more than 46 million customers, with a fiber-cable footprint over 14 million homes passed. Founded in 1990, Millicom International Cellular S.A. is headquartered in Luxembourg. Join us: www.millicom.com Twitter: @Millicom. Instagram: @millicom. Facebook: @millicom. YouTube: Millicom International. 148-150, Boulevard de la Pétrusse L-2330, Luxembourg
Televisa es una gran corporación de telecomunicaciones que posee y opera una de las compañías de cable más relevantes y un sistema líder de televisión de paga vía satélite en México. El negocio de cable de Televisa ofrece servicios integrales que incluyen video, servicios de datos de alta velocidad y servicios de voz a clientes residenciales y comerciales, así ́como servicios administrados a empresas de telecomunicación locales e internacionales. Televisa posee una participación mayoritaria en Sky, un sistema líder de televisión de paga directa al hogar vía satélite y proveedor de banda ancha que opera en México, la República Dominicana y Centroamérica. Televisa es titular de una serie de concesiones del gobierno mexicano que le autorizan a transmitir programación a través de estaciones de televisión para las señales de TelevisaUnivision, Inc. (“TelevisaUnivision”), y los sistemas de cable y televisión satelital de Televisa. Además, Televisa es el mayor accionista de TelevisaUnivision, la compañía controladora de Univision Communications Inc., una empresa de medios líder en la producción, creación y distribución de contenido en español a través de varios canales de transmisión en México, Estados Unidos y a más de 70 países a través de operadores de cable, canales de televisión y servicios adicionales por internet (“OTT”, por sus siglas en inglés). Televisa también tiene intereses en la publicación y distribución de revistas, deportes profesionales y entretenimiento en vivo, y juegos.
At Vodafone, our purpose is to connect everyone. From the seabed to the stars, we provide innovative mobile and fixed connectivity solutions to empower our customers across the globe. And we're constantly expanding coverage to bridge continents and spread inclusion, even in the most remote places. When everyone is connected, we can create a future full of possibilities. Find more information at www.vodafone.com #EveryoneConnected
Latest updates, reports, and threat intel affecting the global network.
Operators of the RagnarLocker ransomware claim to have successfully compromised the systems of telecom analytics firm Subex, including its cybersecurity...
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any application with low cache memory that causes premature eviction to free up memory and applications running macropay-solutions/maravel-framework that utilize tymon/jwt-auth for API token authentication and blacklist management or any other package that does the same may be affected. This architectural risk might also impact native Laravel applications utilizing cache tags under specific volatile or eviction-capped environments. tymon/jwt-auth automatically probes for cache tag support. If found, it forcefully wraps 14-day token blacklist entries (jti) inside a relational tymon.jwt tag. In environments where the O(1) Atomic Lazy Eviction model is active — either natively inside Maravel-Framework v20.x or manually backported into v10.x via the explicit DI container singletons provided in PR #104 (App\Cache\TaggedCache and App\Cache\TagSet) — a strict global tracking ceiling (Container::TAGGED_CACHE_TTL_CAP_SECONDS) of 7,200 seconds (2 hours) is enforced to secure the system against memory index bloat. This ceiling forcefully truncates the 14-day blacklist lifespan down to a maximum of 2 hours, after which individual tracking keys naturally expire and disappear from the active cache window. Furthermore, because the optimized engine implements a generational version matrix to achieve O(1) flush speeds, any programmatic or manual invocation of a tag flush or reset (e.g., Cache::tags([...])->flush()) instantly bumps the internal atomic master version pointer. This shifts the computed cryptographic composite hash (sha1($this->tags->getNamespace())) for all overlapping components, rendering the entire existing index immediately unreachable. Consequently, through either natural 2-hour expiration or an intervening tag flush execution (like the cache naturally cleaning old values to free up memory), the invalidation state records are entirely wiped out. Because the tokens' physical cryptographic signatures remain structurally valid for up to 14 days, stolen, hijacked, or legitimately logged-out tokens are instantly and silently resurrected across the entire API gateway, leaving the application critically vulnerable to widespread Token Replay Attacks. Because this issue is caused by an upstream architectural assumption within the tymon/jwt-auth package rather than a core defect inside the framework, there is no direct framework version upgrade that can safely bypass this lifecycle collision without breaking business cache recycling bounds. Maravel version 10.74.0 introduced a way to backport the new fixed tagged cache from 20.x into 10.x by resolving TagSet and TaggedCache from DI, which is how this latent architectural lifecycle vulnerability was discovered. Users must apply the decoupled configuration workaround outlined below. As a workaround, make sure that cache memory size does not generate early natural evictions from cache to free up space, deleting blacklisted jwt ids before they expire. Applications must decouple flat authentication vectors from the relational tagging subsystem. This forces token identifiers to write directly to the primary cache keyspace as flat, un-tagged key-value pairs where they securely retain their unclipped 14-day lifecycle.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.