Comparison Overview
USC

USC
150/154 Oxford Street, London, W1D 1ND, GB
Last Update: 02/05/2026
USC is a clothing retailer that sells branded clothing across the United Kingdom. The company was founded in 1989 in Edinburgh and has been owned by Sports Direct since 2011. Our mission is to surround ourselves with people who get it, and get us. We understand that th...

Tapestry
10 Hudson Yards, New York, New York, US, 10001
Last Update: 11/09/2026
Our global house of brands unites the magic of Coach and Kate Spade New York. By intertwining different people and ideas, we push ourselves in our work and expand the bounds of possibility. Learn about our iconic brands: tapestry.com/our-brands We’ve grown by finding p...
Compliance Ranges Comparison

USC







Tapestry






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Apparel and Fashion Industry Avg (This Year)
No incidents recorded for USC in 2026.
Incidents vs Retail Apparel and Fashion Industry Avg (This Year)
No incidents recorded for Tapestry in 2026.
Incident History - USC (X = Date, Y = Severity)
USC cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Tapestry (X = Date, Y = Severity)
Tapestry cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

USC

Tapestry
FAQ
Latest Global CVEs
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
- https://github.com/vllm-project/vllm
- https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/nixl/push_worker.py#L162-L181
- https://github.com/vllm-project/vllm/pull/55677
- https://www.vulncheck.com/advisories/vllm-through-0.29.0-memory-exhaustion-via-rejected-requests
redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.
- https://github.com/NodeRedis/node-redis-parser
- https://github.com/NodeRedis/node-redis-parser/blob/701655430f5f7d9ca00892a02f7eefcbc1193a98/lib/parser.js#L204-L213
- https://github.com/NodeRedis/node-redis-parser/blob/701655430f5f7d9ca00892a02f7eefcbc1193a98/lib/parser.js#L291-L306
- https://github.com/redis/ioredis/issues/2108
- https://www.vulncheck.com/advisories/redis-parser-through-3.0.0-denial-of-service-via-unbounded-recursion
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.