USAVS A.I CyberSecurity Scoring
02/04/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for University of South Africa/Universiteit van Suid-Afrika in 2026.
No incidents recorded for University of South Africa/Universiteit van Suid-Afrika in 2026.
No incidents recorded for University of South Africa/Universiteit van Suid-Afrika in 2026.
Higher Education
Cornell is a privately endowed research university and a partner of the State University of New York. As the federal land-grant institution in New York State, we have a responsibility—unique within the Ivy League—to make contributions in all fields of knowledge in a manner that prioritizes public engagement to help improve the quality of life in our state, the nation, the world.
Ranked a Tier One research university by the Carnegie Classification, UNT is the flagship of the UNT System and is located in Denton, Texas. With 242 degree programs and a thriving community of nearly 44,000 students, UNT serves the North Texas region and helps drive the state’s economy through groundbreaking research, educational excellence focused on career readiness, and a spirit of creativity, innovation, and entrepreneurship. Across its Denton and Frisco campuses, UNT students earned more than 13,000 degrees last year.
Uppsala University strives to bring new perspectives to the basic questions of science as well as knowledge contributing to sustainable development and human health. We offer 39 different master programmes covering over 60 different specialisations. In Uppsala you walk in the gardens of Linnaeus, follow in the footsteps of Nobel laureates, and at the same time meet today’s – and tomorrow’s – smartest teachers and researchers. Uppsala University. Quality, knowledge and creativity. Since 1477. Please address questions on official matters to [email protected]
Founded in 1927, the University of Houston is the leading public research university in the vibrant international city of Houston. Each year, we educate more than 47,000 students in more than 250 undergraduate and graduate academic programs, on campus and online. UH awards over 10,000 degrees annually, with more than 332,000 alumni.
On our beautiful campus spanning the Iowa River, our faculty and staff enjoy access to an array of cultural, educational, and recreational activities. With more than 30,000 students, more than 14,000 employees, and a budget of $3 billion, the University of Iowa is one of the nation's top public research universities.
School of Visual Arts has been a leader in the education of artists, designers, and creative professionals for more than seven decades. With a faculty of distinguished working professionals, a dynamic curriculum, and an emphasis on critical thinking, SVA is a catalyst for innovation and social responsibility. Comprising 6,000 students at its Manhattan campus and over 43,000 alumni from some 130 countries, SVA also represents one of the most influential artistic communities in the world. For information about the College’s 30 undergraduate and graduate degree programs, visit sva.edu.
Monash University is Australia’s largest and most international university. Its extensive educational offering, delivered via our 10 faculties, includes undergraduate, postgraduate and research courses. Monash is a research-intensive university, known for some significant and lasting discoveries that have delivered impact beyond the academic community. The university is home to a range of world-leading facilities and technologies, giving it wide-ranging capabilities across many fields, sectors and industries. Monash works with a variety of industry, government and community groups, allowing its researchers to share their discoveries with the world. Monash is a truly global institution, with five Australian campuses, a campus in Malaysia, a joint graduate school in China, a learning centre in Italy, and a research centre in India. At Monash, cultural experiences are lived, not described. Registered Australian University CRICOS No: 00008C
At Colorado State, there’s this energy we all share—this undeniable excitement for what’s next. And it’s a feeling you can only find here. As you choose a college, one of the biggest questions most students have is what to study. At Colorado State, we offer over 250 programs, over 50 minors, and several advising tracks. That means you’ll have the ability to reach your goals — no matter what they are. Founded in 1870 as the Colorado Agricultural College, Colorado State University is now among the nation's leading research universities. Our world-class research in infectious disease, atmospheric science, clean energy technologies, environmental science, and biomedical technology attracted more than $300 million in research funding annually. Our professional programs in veterinary medicine, occupational therapy, journalism, agriculture and construction management are ranked among the nation's best. Colorado State is the "university of choice" for Colorado residents; 30% of all of Colorado's science, math, engineering and technology majors pursue degrees at CSU. This is LinkedIn account is officially recognized by Colorado State University; however, the views and opinions expressed on this page are not necessarily those of the University. CSU retains discretion to allow or disallow comments and/or posts on this page. For more information about CSU’s Social Media Policy, visit http://www.socialmedia.colostate.edu.
We’re Virginia Commonwealth University — the university FOR Virginia. You will see an incredible mix of attitudes, styles and stories. Inclusion is our heartbeat and it drives us to tackle difficult challenges others can’t or won’t. We do things differently here, because we know that different works. We're proud of our rankings, but they don't define us. Rankings don’t change lives, we do. VCU’s unequaled combination of excellence, diversity, research and creativity makes success possible for every one of our 300,000+ RAMily members. And that makes us one of the most innovative universities in the U.S. We are Richmond's largest employer. And we prove every day that when you come to VCU, you can become anything. As one of Virginia’s top three research institutions, every student has the chance to participate in activities that result in breakthrough work. Our sponsored research has increased 71% since 2018, to $464.6 million. And our discoveries have led to thousands of patents and successful student startups. In addition, our VCU Health System is dedicated to ending health care disparities. We are Richmond's top hospital and serve as a renowned training facility for future health care leaders. All students receive unique benefits to improve their quality of life, and to make a difference by helping others. Every step moves society closer to the next life-changing solution. Our graduates are trained to make an impact in the world, and they carry that responsibility wherever they go. We reject traditional thinking and champion the unconventional, setting standards that others follow. We give our students the freedom to rewrite the rule books and the skills to disrupt expectations. We’re pursuing a future that’s built by us. A future that improves learning and health for ALL. Learn more at: linkin.bio/vcu
Latest updates, reports, and threat intel affecting the global network.
Sello Mmakau was appointed as chief digital officer (CDO) of Telkom in April 2024. Prior to joining Telkom, Sello served as the chief information and digital...
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_SSL_CID_OUT_LEN_MAX) into that buffer without a destination-size parameter, so a caller-supplied optlen smaller than the CID causes a write of up to 31 bytes past the buffer end. In CONFIG_USERSPACE builds the getsockopt syscall verifier (z_vrfy_zsock_getsockopt) bounce-buffers the user's optval into a kernel allocation of exactly optlen bytes (k_usermode_alloc_from_copy -> z_thread_malloc), so an unprivileged user thread that passes a small optlen on a connected DTLS socket with Connection ID enabled induces a kernel-heap buffer overflow, with the overflowing content being the remote peer's CID. The defect requires CONFIG_MBEDTLS_SSL_DTLS_CONNECTION_ID, an established DTLS session with a negotiated peer CID, and (for the kernel-crossing case) CONFIG_USERSPACE. Introduced when the TLS_DTLS_CID option was added (v3.5.0). The fix rejects callers whose optlen is below MBEDTLS_SSL_CID_OUT_LEN_MAX with -EINVAL.
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-19 01:07:01 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity since 2026-05-19 01:07:01, and clean local clones.
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote ctx.fds[ctx.nfds] and incremented ctx.nfds with no bounds check. Two independent paths mutate ctx concurrently: the background autohandler running on the system workqueue, and user-triggered operations reached through the updatehub run shell command, direct API calls, or — since the operations are exposed as syscalls — userspace threads. When a second flow enters prepare_fds() while ctx.nfds is already 1, the write lands one element past the array; by struct layout it overlaps the adjacent ctx.sock/ctx.nfds members. More broadly, the unsynchronized sharing lets two flows interleave connection setup and teardown, double-closing a socket descriptor or scribbling the shared buffers. The result is corruption of the update subsystem's internal state and denial of service of the firmware-update path; the out-of-bounds write is contained within the ctx structure and there is no demonstrated path to memory outside it or to code execution. Triggering requires a local actor able to invoke update operations (or, with CONFIG_USERSPACE, an unprivileged userspace thread) and to win a timing race against the background handler; remote peers cannot control the race timing. The fix serializes the entry points with a mutex and adds a bounds check to prepare_fds().
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.