Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

ThirdPartyTrust, a Bitsight companyThirdPartyTrust, a Bitsight company
VS
Red HatRed Hat
ThirdPartyTrust, a Bitsight company

ThirdPartyTrust, a Bitsight company

111 Huntington Ave, Boston, 02199, US

Last Update: 02/04/2026

View Profile
643/1000Poor

ThirdPartyTrust is a third-party risk management platform for companies and vendors to perform assessments, automate TPRM workflows, and share security documents. We get programs out of email & spreadsheets and accelerate the third-party assessment/questionnaire review ...

NAICS:5112
NAICS Definition:Software Publishers
Employees:6
Subsidiaries:1
12-month incidents
0
Known data breaches
0
Attack type number
1
Red Hat

Red Hat

100 E. Davie St., Raleigh, NC, US, 27601

Last Update: 15/09/2026

View Profile
Between 650 and 699
http://www.redhat.com
695/1000Weak

Red Hat is the world’s leading provider of enterprise open source solutions, using a community-powered approach to deliver high-performing Linux, hybrid cloud, edge, and Kubernetes technologies. We hire creative, passionate people who are ready to contribute their idea...

NAICS:5112
NAICS Definition:Software Publishers
Employees:19,335
Subsidiaries:2
12-month incidents
0
Known data breaches
3
Attack type number
2

Compliance Ranges Comparison

Based On Specific Ai Models Category
ThirdPartyTrust, a Bitsight company

ThirdPartyTrust, a Bitsight company

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Red Hat

Red Hat

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Software Development Industry Avg (This Year)

No incidents recorded for ThirdPartyTrust, a Bitsight company in 2026.

Incidents

Incidents vs Software Development Industry Avg (This Year)

No incidents recorded for Red Hat in 2026.

Incidents

Incident History - ThirdPartyTrust, a Bitsight company (X = Date, Y = Severity)

ThirdPartyTrust, a Bitsight company cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Red Hat (X = Date, Y = Severity)

Red Hat cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
ThirdPartyTrust, a Bitsight company

ThirdPartyTrust, a Bitsight company

Incidents
🔒 Incident : Ransomware
THIIBE1774081558
Red Hat

Red Hat

Incidents
🔒 Incident : Breach
RED4732847100725
🔒 Incident : Breach
RED4292342100825
🔒 Incident : Vulnerability
RED1694016100125

FAQ

Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has the best AI Cybersecurity Score ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has experienced more cyber incidents in the past ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has experienced more cyber incidents this year ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has experienced at least one ransomware attack ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has experienced at least one data breach ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has experienced at least one targeted cyberattack ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has experienced at least one vulnerability ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one holds the most compliance certifications ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one holds the fewest compliance certifications ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has the most subsidiaries ?
Between ThirdPartyTrust, a Bitsight company company and Red Hat company, which one has the largest number of employees ?
Between ThirdPartyTrust, a Bitsight company and Red Hat, which company holds both SOC 2 Type 1 certifications ?
Between ThirdPartyTrust, a Bitsight company and Red Hat, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - ThirdPartyTrust, a Bitsight company or Red Hat ?
Which company is PCI DSS compliant - ThirdPartyTrust, a Bitsight company or Red Hat ?
Between ThirdPartyTrust, a Bitsight company and Red Hat, which company complies with HIPAA regulations for healthcare data ?
Between ThirdPartyTrust, a Bitsight company and Red Hat, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-105222
SUMMARY

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

PUBLISHED
Date2026-10-04
UPDATED
Date2026-10-04
RISK INFORMATION (Score: 7.4)
CVSS3
Base Score: 7.4
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS4
Base Score: 9.1
Complexity: HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.2
EXPLOITABILITY
2.2
CVE-2026-105221
SUMMARY

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

PUBLISHED
Date2026-10-04
UPDATED
Date2026-10-04
RISK INFORMATION (Score: 7.4)
CVSS3
Base Score: 7.4
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS4
Base Score: 9.1
Complexity: HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.2
EXPLOITABILITY
2.2
CVE-2026-105220
SUMMARY

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.

PUBLISHED
Date2026-10-04
UPDATED
Date2026-10-04
RISK INFORMATION (Score: 7.8)
CVSS3
Base Score: 7.8
Complexity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS4
Base Score: 8.5
Complexity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
1.8
CVE-2026-105167
SUMMARY

A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Date2026-10-04
UPDATED
Date2026-10-04
RISK INFORMATION (Score: 7.3)
CVSS2
Base Score: 7.5
Complexity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Base Score: 7.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 5.5
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
3.9
CVE-2026-105166
SUMMARY

A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Date2026-10-04
UPDATED
Date2026-10-04
RISK INFORMATION (Score: 7.3)
CVSS2
Base Score: 7.5
Complexity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Base Score: 7.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 5.5
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
3.9