YKF A.I CyberSecurity Scoring
13/12/2025
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Yapı Kredi FRWRD in 2026.
No incidents recorded for Yapı Kredi FRWRD in 2026.
No incidents recorded for Yapı Kredi FRWRD in 2026.
En Banamex una palabra nos ha definido durante nuestra historia: Estar. Estar es acompañar. Estar es avanzar juntos. Acompañar para forjar relaciones auténticas, duraderas, significativas, que nos den confianza y nos impulsen a alcanzar aquello que es importante para ti, para nosotros, para todos. Queremos renovar nuestro compromiso de confianza mutua, no solo trabajando para responder a la confianza que depositas cada día en nosotros, sino comprometiéndonos a hacerla crecer, creando una relación que perdure más allá de lo financiero, más allá de ti y de nosotros, más allá del tiempo. Porque creemos que la confianza es la base de todo. Un proceso en ambas direcciones, en el que nosotros queremos estar y que estés. Un camino que se construye por nuestra parte de una forma sencilla: proporcionándote soluciones y experiencias financieras de una forma sostenida, cercana y honesta. Soluciones que te acompañan, que cambian y se adaptan como cambias tú, que están ahí cuando las necesitas. Para que tú puedas ser tú y nosotros podamos estar aquí, para ti, siempre. Porque nadie es mejor solo, nosotros somos mejores gracias a ti y queremos que tú seas mejor gracias a nosotros.
We are the largest bank in Poland and one of the largest financial institutions in the region. Our strength rests on three strong pillars: the retail, the corporate and the investment segment. Irrespective of the unique nature of each of those areas, what joins them is the undivided attention they pay to the needs of their customers and clients, and their pursuit of superlative quality in customer service. Consistent campaigning established the “PKO Bank Polski” brand as a virtual guarantee of the right banking partner choice, one that not only delivers the relevant products and services, but also provides capable support in financial and business decisions. The professionalism and the experience of our advisers help them meet their customers’ expectations and to offer them the best available solutions. Though traditionally dedicated to retail customers, over the years PKO Bank Polski has also become a corporate finance leader of the Polish market. As at the end of 2012, the number our corporate clients exceeded 12,000. For years now, our corporate banking segment has participated in projects of major importance for the entire Polish economy. We have financed major investment projects, engaged in restructuring and recovery processes and have supported regional development through solutions dedicated to local government units. In 2012 we continued in activity that perpetuated our image of a true partner of the Polish enterprise and local government sectors, which we gained during the first wave of the financial crisis. At the heart of our corporate offer is our ability to engineer comprehensive solutions out of the products of the Bank and its Group Companies (factoring, leasing) of relevance to the differing needs of the various size companies: from small entities in the early stages of development to the largest corporates.
Bank Mandiri was established on 2 October 1998, as part of the bank restructuring program of the Government of Indonesia. In July 1999, four state-owned banks - Bank Bumi Daya, Bank Dagang Negara, Bank Exim and Bapindo - were amalgamated into Bank Mandiri. The history of these four banks can be traced back to over 140 years, and together they had contributed to the beginning of the Indonesian banking sector. We are continuously seeking mutually beneficial business opportunities that create synergies, building alliances and strengthening our supporting businesses with and through our subsidiaries, notably Bank Syariah Mandiri in Islamic banking, PT. Bank Mandiri Taspen in banking, Mandiri Europe in international banking, AXA Mandiri Financial Services in insurance, Mandiri Sekuritas in investment banking, Mandiri Capital Indonesia in venture capital, Mandiri Tunas Finance in multi-finance, Mandiri Utama Finance in multi-finance, and Mandiri International Remittance in remittance. With various subsidiaries that support our businesses, we have further strengthened our position as a prominent financial holdings institution in Indonesia.
We are a global financial services provider with presence in Nigeria, the United Kingdom, Ghana, Sierra Leone and Gambia. Operating from our head office in Lagos, Nigeria, we have a network of over 500 branches and business offices in prime commercial centres in all the states of the Federation and the Federal Capital Territory (FCT), Nigeria as well as representative offices in South Africa and China. We have a shareholder base of about one million and currently Nigeria’s biggest bank by tier-1 capital. In 2013, about $850 million worth of our shares were listed at the London Stock Exchange (LSE) at $6.80 each. Over the years, we have built a reputation in e-Banking in Nigeria, having blazed new trails in the deployment of Information and Communication Technology (ICT) infrastructure to create innovative products that meet the needs of its teeming customers. We are market leaders in the deployment of various channels of banking technology, and the Zenith brand has become synonymous with the deployment of state-of-the-art technologies in banking.
At U.S. Bank, we help millions of clients achieve their goals with a balance of best-in-class technology and human expertise tailored to individual needs. As the fifth-largest commercial bank in the United States, we’ve built a reputation for strength and stability across a diversified mix of businesses, including commercial and institutional banking, business banking, payments, wealth management and consumer banking. We’ve been named one of the World’s Most Ethical Companies® by the Ethisphere Institute and the most admired superregional bank by Fortune. In addition to thousands of branches serving consumers, U.S. Bank offers a complete suite of products, services and strategic partnerships for business. Within our Wealth, Corporate, Commercial and Institutional Banking division, we serve more than half a million clients across the country and around the world, ranging from wealthy individuals and families to the largest corporations, including 90% of Fortune 1000 companies. We’re also consistently recognized as a great place to work. We’re shaping our company culture with intention, focused on creating a workplace where it’s safe to speak up, share ideas and try new things. We’re proud to be recognized as a “Best for Vets” employer by the Military Times and included on Fair360’s (formerly DiversityInc.) list of Top 50 Companies for Diversity. U.S. Bank, NA. Member FDIC. Equal Housing Lender.
Banque Misr (BM) was established in 1920 by the pioneer economist and financial expert Mohamed Talaat Harb Pasha, who spearheaded the concept of investing in national savings and directing them toward economic and social development. Thus, Banque Misr was established as the first wholly Egyptian-owned bank. Banque Misr has funded many businesses spanning across multiple domestic sectors, such as: textiles, insurance, transportation, aviation, entertainment, and filmmaking. Currently, BM owns shares in 157 companies across different fields, ranging from finance, tourism, housing, agriculture and food, and communication and information technology. A true pioneer in the region, Banque Misr became the first bank in Egypt and North Africa to comply with PCI data security standards, upon obtaining the latest version of the global Payment Card Industry Data Security Standard (PCI DSS 3.2.1) certification. Utilizing the latest technology in the banking sector, Banque Misr is constantly looking to expand customer access to banking services. Today, Banque Misr is proud to offer one of Egypt’s largest ATM networks, located across all areas of Egypt. Banque Misr’s role is visible in all economic fields due to its geographic outreach. The bank has more than 20,000 employees, serving a large base of more than 13 million clients in Egypt, with a total paid-up capital amounting to EGP 15 billion. The bank has more than 800 electronically integrated local branches located nationwide to provide the best and most accessible services to customers. Banque Misr also values its regional and international presence, which includes its five branches in the United Arab Emirates and one in France. In addition, the bank’s international presence includes subsidiaries in Lebanon and Germany, as well as representative offices in China, Russia, South Korea, and Italy and a global network of correspondents.
Crédit Agricole CIB is the corporate and investment banking arm of Crédit Agricole Group, 9th largest banking group worldwide in terms of balance sheet size in 2023 (The Banker, July 2024). Nearly 8,600 employees across Europe, the Americas, Asia-Pacific, the Middle East and North Africa support Crédit Agricole CIB's clients, meeting their financial needs throughout the world. Crédit Agricole CIB offers its large corporate and institutional clients a range of products and services in capital markets activities, investment banking, structured finance, commercial banking and international trade. The Bank is a pioneer in the area of climate finance, and is currently a market leader in this segment with a complete offer for all its clients.
Since its establishment in 1946, BNI has been part of the dynamic of national development in Indonesia. Now BNI has grown and developed into a solid national bank with a sustainable financial performance. ‘Serving the Country, the Pride of the Nation”, BNI continues to increase its contribution for the progress of the nation and country, today and in the future. As of the end of 2025, BNI operated 1 (one) Head Office, 17 Regional Offices, 10 overseas Office Networks, and 1,834 Domestic Office Networks, comprising Branch Offices, Sub-Branch Offices, and Business Centers. Of the 10 Overseas Office Networks, 6 are licensed Overseas Branch Offices, 2 are Representative Offices, 1 is an Overseas Sub-Branch, and 1 is a remittance Branch Office, strategically located across 8 key countries (USA, UK, Japan, Singapore, South Korea, Hongkong, Netherlands, and Australia). BNI always strives to be the bank of choice by providing excellent service and value added solutions to all of its customers. BNI offers integrated financial services to its customers, supported by its subsidiaries: BNI Multi Finance, BNI Securities, BNI Life Insurance, BNI Remittance, BNI Asset Management, hiBank, and BNI Ventures
ING ING is a global bank with a strong European base. With 14,500 employees in the Netherlands, we’re one of the biggest employers of the country. Our research tells us that we stand out here because of our great working culture, competitive benefits, and interesting work. We believe in sustainable progress for all, not just for the few. We aim to support and contribute to economic, social and environmental progress. Collaborative and inclusive We’re proud of our diverse and multinational make-up. Joining the ING team means contributing to a collaborative and inclusive culture, having a hybrid way of working, and being part of the positive impact that we strive to make on people and the planet. Purpose ING's purpose is empowering people to stay a step ahead in life and in business. This purpose guides us in everything we do. Rather than telling our people what to do, we trust them and encourage them to carve out their career in a way that works best for them. We want to enable them to grow in their own way, without being held down. Because doing great things starts by doing your thing.
Latest updates, reports, and threat intel affecting the global network.
A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling `__import__(module_path, ...)`. The module is imported — running its top-level code (import side effects) — before the framework checks that the resolved object is a `LiveView` subclass and before any per-view authentication. The `LIVEVIEW_ALLOWED_MODULES` allowlist that should contain this is fail-open (`if allowed_modules:` — skipped when the setting is unset, the framework default) and uses loose `startswith` matching. An unauthenticated WebSocket client (the WS handshake does not require auth; per-view auth runs only after import + instantiate) can therefore send a `mount` / `live_redirect_mount` / `url_change` frame (or an SSE mount) with `view = "<any.importable.module>.AnyName"` and cause the server to import — and execute the top-level code of — any importable Python module by name. Version 1.0.7 fixes the issue with a fail-closed resolution gate (`djust._view_resolution.is_view_import_allowed`): a client view path resolves only if (a) its module is already loaded (`sys.modules` — so resolving runs no new code; URL-routed views loaded by URLconf at startup keep working with zero config) or (b) it matches `LIVEVIEW_ALLOWED_MODULES` on a module-segment boundary (explicit opt-in for lazily-imported views). The gate runs before `__import__` at all three sinks (+ defense-in-depth inside `_instantiate_view`). As a workaround, set `LIVEVIEW_ALLOWED_MODULES` to the narrow list of modules that contain your mountable LiveView classes. (Note: pre-patch the allowlist is `startswith`-matched and the import still precedes the subclass check, so this is mitigation, not a complete fix.)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA `url_change` navigation, and (c) `{% live_render %}` embedded child views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views. This is fixed in djust 1.0.7. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns 403, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op). No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` on the live path while the HTTP path resolved correctly. With `STRICT_MODE=False` the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against `ALLOWED_HOSTS` (the same logic as the CSWSH Origin gate, parsed with Django's `split_domain_port` so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with `STRICT_MODE=False`.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Because exposing model objects to templates is a normal djust pattern, this could leak credentials/PII without the developer realizing the full object crossed the wire. This is fixed in djust 1.0.7. Model serialization applies a secure-by-default sensitive-field denylist (password/hash/token/secret-style fields and known privilege flags are withheld) with an identity-subset fallback. As a workaround, keep `Model` instances on `_private` attributes and expose only the specific fields needed, until patched.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.