Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

Tập đoàn Tân Hiệp PhátTập đoàn Tân Hiệp Phát
VS
Krispy KremeKrispy Kreme
Tập đoàn Tân Hiệp Phát

Tập đoàn Tân Hiệp Phát

219 Đại lộ Bình Dương, Thuận An,, Binh Duong, Binh Duong Province, 700000, VN

Last Update: 19/03/2026

View Profile
Between 750 and 799
https://www.thp.com.vn/
765/1000Fair

Chào mừng các bạn đến THP. Được thành lập năm 1994, Tập đoàn nước giải khát Tân Hiệp Phát ("THP"​) là công ty Việt Nam lớn nhất trong ngành hàng Tiêu dùng nhanh (FMCG). THP tự hào phát triển, sản xuất và bán ra thị trường 3 thương hiệu Quốc gia Việt Nam - Trà Thảo mộc D...

NAICS:722
NAICS Definition:Food Services and Drinking Places
Employees:504
Subsidiaries:0
12-month incidents
0
Known data breaches
0
Attack type number
0
Krispy Kreme

Krispy Kreme

2116 Hawkins St, Charlotte, North Carolina, US, 28203

Last Update: 06/09/2026

View Profile
376/1000Critical

Headquartered in Charlotte, N.C., Krispy Kreme is one of the most beloved and well-known sweet treat brands in the world. Our iconic Original Glazed® doughnut is universally recognized for its hot-off-the-line, melt-in-your-mouth experience. Krispy Kreme operates in mor...

NAICS:722
NAICS Definition:Food Services and Drinking Places
Employees:10,305
Subsidiaries:0
12-month incidents
1
Known data breaches
4
Attack type number
3

Compliance Ranges Comparison

Based On Specific Ai Models Category
Tập đoàn Tân Hiệp Phát

Tập đoàn Tân Hiệp Phát

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Krispy Kreme

Krispy Kreme

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Food and Beverage Services Industry Avg (This Year)

No incidents recorded for Tập đoàn Tân Hiệp Phát in 2026.

Incidents

Incidents vs Food and Beverage Services Industry Avg (This Year)

Krispy Kreme has 2.91% fewer incidents than the average of all companies with at least one recorded incident.

Incidents

Incident History - Tập đoàn Tân Hiệp Phát (X = Date, Y = Severity)

Tập đoàn Tân Hiệp Phát cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Krispy Kreme (X = Date, Y = Severity)

Krispy Kreme cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
Tập đoàn Tân Hiệp Phát

Tập đoàn Tân Hiệp Phát

Incidents
No explicit notable incidents reported.
Krispy Kreme

Krispy Kreme

Incidents
🔒 Incident : Breach
KRI1779668812
🔒 Incident : Ransomware
KRI1768390561
🔒 Incident : Cyber Attack
KRI5093650100125

FAQ

Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has the best AI Cybersecurity Score ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has experienced more cyber incidents in the past ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has experienced more cyber incidents this year ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has experienced at least one ransomware attack ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has experienced at least one data breach ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has experienced at least one targeted cyberattack ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has experienced at least one vulnerability ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one holds the most compliance certifications ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one holds the fewest compliance certifications ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has the most subsidiaries ?
Between Tập đoàn Tân Hiệp Phát company and Krispy Kreme company, which one has the largest number of employees ?
Between Tập đoàn Tân Hiệp Phát and Krispy Kreme, which company holds both SOC 2 Type 1 certifications ?
Between Tập đoàn Tân Hiệp Phát and Krispy Kreme, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - Tập đoàn Tân Hiệp Phát or Krispy Kreme ?
Which company is PCI DSS compliant - Tập đoàn Tân Hiệp Phát or Krispy Kreme ?
Between Tập đoàn Tân Hiệp Phát and Krispy Kreme, which company complies with HIPAA regulations for healthcare data ?
Between Tập đoàn Tân Hiệp Phát and Krispy Kreme, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-87924
SUMMARY

A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Date2026-09-09
UPDATED
Date2026-09-09
RISK INFORMATION (Score: 6.5)
CVSS2
Base Score: 6.4
Complexity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:P
CVSS3
Base Score: 6.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS4
Base Score: 5.5
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
2.5
EXPLOITABILITY
3.9
CVE-2026-87923
SUMMARY

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Date2026-09-09
UPDATED
Date2026-09-09
RISK INFORMATION (Score: 4.3)
CVSS2
Base Score: 5.0
Complexity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS3
Base Score: 4.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS4
Base Score: 2.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
1.4
EXPLOITABILITY
2.8
CVE-2026-71809
SUMMARY

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

PUBLISHED
Date2026-09-09
UPDATED
Date2026-09-09
IMPACT SCORE
NA
EXPLOITABILITY
NA
CVE-2026-15460
SUMMARY

The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target channel had reached the BT_L2CAP_CONNECTED state. A dynamic channel is assigned its RX CID and added to the connection's channel list while still in BT_L2CAP_CONNECTING (and later BT_L2CAP_CONFIG) — before configuration completes and, for PSMs that require security, before the peer is authenticated (l2cap_br_conn_req()). Because the channel is already findable by bt_l2cap_br_lookup_rx_cid() during this window, a remote peer within radio range can send a data PDU addressed to that CID and have it processed on a not-yet-established channel. The dispatch keys off channel fields (BR_CHAN(chan)->rx.mode, rx.mps) that are only initialized during configuration by l2cap_br_conf(); since channel objects are pooled and bt_l2cap_br_chan_del() does not reset rx.mode or the reassembly buffer _sdu, a reused channel can carry stale state into the CONNECTING window and route the frame into the retransmission/flow-control path (bt_l2cap_br_ret_fc_recv()) with stale parameters and a possibly stale _sdu pointer. The impact is delivery of attacker data to upper-layer protocol handlers on a half-open (and possibly unauthenticated) channel, plus operation on stale or partially initialized channel state on reused channel objects — leading to channel/link teardown (denial of service) and, in the stale-_sdu case, a dangling-pointer condition. The fix adds an explicit BR_CHAN(chan)->state < BT_L2CAP_CONNECTED guard that drops any data received before the channel is fully connected.

PUBLISHED
Date2026-09-09
UPDATED
Date2026-09-09
RISK INFORMATION (Score: 5.4)
CVSS3
Base Score: 5.4
Complexity: LOW
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
IMPACT SCORE
2.5
EXPLOITABILITY
2.8
CVE-2026-88069
SUMMARY

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to cause extracted content to be written outside the designated extraction directory, potentially overwriting files accessible to the Pandora worker process. Successful exploitation could result in unauthorized modification of application or system files, denial of service, and potentially further compromise depending on the permissions of the Pandora process and the files that can be overwritten. The vulnerability is addressed by resolving each extraction destination path before writing and verifying that it remains below the expected extraction directory. Extraction attempts resolving outside this directory are rejected and reported as path traversal attempts.

PUBLISHED
Date2026-09-09
UPDATED
Date2026-09-09
RISK INFORMATION (Score: )
CVSS4
Base Score: 9.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
NA
EXPLOITABILITY
NA