Comparison Overview
台灣特洛奇資訊

台灣特洛奇資訊
新北市中和區中正路920號, 新北市, 235, TW
Last Update: 05/04/2026
特洛奇深耕資安市場多年,在網路資安以及環境資安控管方面,特洛奇擁有多樣化的產品,能針對客戶需求提出彈性化的解決方案,協助客戶找出各種威脅,完整資安防護環境。產品及服務內容涵蓋以下: 網路流量側錄與保全 網路安全與流量頻寬可視/可控化 資安服務(弱點掃描、滲透測試、紅隊演練) 資安檢測工具(DDOS檢測、效能檢測、弱點掃描、模糊測試、源碼檢測) 端點防護與資產管理查核系統 特洛奇是領先全球、服務可靠的資安解決方案供應商,不僅幫助服務提供商改善網路的效能,並協助企業從複雜的IT基礎設備中獲得更好的效益。特洛奇的客戶涵蓋了電信業與網路服務...

Indeed
6433 Champion Grandview Way, Bldgs I & II, Austin, Texas, US, 78750
Last Update: 22/09/2026
More people get jobs on Indeed than anywhere else. As the world’s #1 job site (Comscore, Total Visits, March 2026), Indeed is a global hiring platform connecting over 685 million Job Seeker Profiles with 3.5 million employers across more than 60 countries. Indeed uses A...
Compliance Ranges Comparison

台灣特洛奇資訊







Indeed






Benchmark & Cyber Underwriting Signals
Incidents vs Technology, Information and Internet Industry Avg (This Year)
No incidents recorded for 台灣特洛奇資訊 in 2026.
Incidents vs Technology, Information and Internet Industry Avg (This Year)
No incidents recorded for Indeed in 2026.
Incident History - 台灣特洛奇資訊 (X = Date, Y = Severity)
台灣特洛奇資訊 cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Indeed (X = Date, Y = Severity)
Indeed cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

台灣特洛奇資訊

Indeed
FAQ
Latest Global CVEs
Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.
- https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18
- https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.
- https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03
- https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.
- https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6
- https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v