wind tre A.I CyberSecurity Scoring
wind tre
Company Information
Website:https://www.windtregroup.it
Employees number:7,160
Number of followers:106,790
NAICS:517
Industry Type:Telecommunications
Homepage:windtregroup.it
wind tre Risk Score (AI oriented)
Between 650 and 699
wind treTelecommunications
Updated:
20/07/2026
20/07/2026
685/1000
Weak
B
wind tre Global Score (TPRM)
xxxx
wind treTelecommunications
Score locked

wind treWeak
Current Score
685B (WEAK)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
682
JULY 2026
685
Vulnerability
22 Jul 2026 • wind tre
Check Point: CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
Critical Check Point Authentication Flaw Actively Exploited in the Wild
681
CRITICAL-4
CHE1784787889
Critical Check Point Authentication Flaw Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about CVE-2026-16232, a critical authentication vulnerability in Check Point SmartConsole that is being actively exploited. The flaw, rated 9.3 on the CVSS scale, affects Check Point Security Management and Multi-Domain Management platforms, allowing unauthenticated remote attackers to obtain an application login token and gain full administrative access to affected systems.
The vulnerability was discovered during an internal BLAST (Business Logic Attack Surface Testing) review under Check Point’s Frontier AI Readiness Program. Exploitation has been confirmed in real-world attacks, though limited to environments where management interfaces are exposed to the internet without IP-based restrictions. Attackers could leverage this access to modify security policies, deploy malicious configurations, or pivot deeper into enterprise networks, risking full infrastructure compromise.
CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the need for immediate patching. Affected versions include R81.10, R81.20, R82, and R82.10, with older versions also potentially vulnerable. Check Point has released a Jumbo Hotfix (July 22, 2026) to remediate the issue and strengthen system resilience.
In the same advisory, Check Point disclosed two additional high-severity vulnerabilities:
- CVE-2026-62144 (CVSS 9.3): Another authentication bypass and privilege escalation flaw in management systems, though not yet exploited.
- CVE-2026-62145 (CVSS 7.5): A local privilege escalation issue in GaiaOS WebUI, currently unexploited.
Security teams are advised to restrict SmartConsole and management access to trusted IP addresses, enforce firewall protections, and monitor for indicators of compromise, including:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
The incident underscores the risks of exposed management interfaces and the necessity of proactive patching, strict access controls, and continuous monitoring to mitigate evolving threats.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2026
684
MAY 2026
682
APRIL 2026
681
MARCH 2026
679
FEBRUARY 2026
677
JANUARY 2026
675
DECEMBER 2025
673
NOVEMBER 2025
671
OCTOBER 2025
669
SEPTEMBER 2025
667
FEBRUARY 2025
771
Breach
01 Feb 2025 • wind tre
WINDTRE: Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
WINDTRE Fined €1.7M Over Dual Data Breaches Affecting 365,000 Customers
650
CRITICAL-121
WIN1784558266
Italian Telecom Giant WINDTRE Fined €1.7M Over Dual Data Breaches Affecting 365,000 Customers
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, imposed a €1.7 million fine on WINDTRE, one of the country’s largest telecom operators, for "serious data security shortcomings" that enabled two separate breaches in February 2025. The attacks compromised the personal data of over 365,000 customers, with payment details exposed for 41,359 individuals.
The breaches stemmed from social engineering tactics rather than software vulnerabilities. Attackers posed as support technicians, tricking staff at two WINDTRE stores into granting access to internal systems. Once inside, they extracted customer names, contact details, and in some cases postal payment slips, IBAN numbers, partially masked credit card numbers, and card expiry dates.
The regulator’s investigation uncovered critical flaws in WINDTRE’s security practices. Despite the company’s claims of robust defenses including three-factor authentication, firewalls, and access restrictions audits revealed lapses in credential and certificate management. Digital certificates and private keys were not stored in encrypted vaults, leaving them vulnerable if devices were compromised. Additionally, internal APIs, which facilitated a large-scale enumeration attack (roughly 2 million requests), lacked rate-limiting and CAPTCHA protections, violating OWASP’s API Security Top 10 standards.
WINDTRE argued that the incidents resulted from human error, not systemic failures, and noted challenges in enforcing password managers for independently run stores. However, the regulator dismissed these defenses, ruling that the company violated GDPR’s data integrity, confidentiality, and security requirements.
As part of the ruling, WINDTRE was ordered to strengthen credential and certificate protection, implement secure password management tools, and enhance cybersecurity procedures. The fine amount reflected the company’s prompt breach reporting, post-incident remediation efforts, cooperation during the investigation, and lack of prior privacy violations.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for wind tre ??
What was wind tre's A.I Rankiteo Cyber Score in July 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in June 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in May 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in April 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in March 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in February 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in January 2026 ??
What was wind tre's A.I Rankiteo Cyber Score in December 2025 ??
What was wind tre's A.I Rankiteo Cyber Score in November 2025 ??
What was wind tre's A.I Rankiteo Cyber Score in October 2025 ??
What was wind tre's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on wind tre's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with wind tre ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view wind tre's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?