Company Details
dimension-data
12,291
434,819
5415
dimensiondata.com
0
DIM_1978732
In-progress


Dimension Data Vendor Cyber Rating & Cyber Score
dimensiondata.comDimension Data is a leading African born technology provider operating in the Middle East and Africa, offering a portfolio of services including systems integration, managed services infrastructure, cloud solutions, business applications, customer experience, and intelligent security solutions. We provide innovative solutions that optimise today’s evolving technology environments, enabling clients to leverage data in a digital age. Founded in 1983, and headquartered in Johannesburg, Dimension Data is a proud member of the NTT Group, one of the world’s leading information communication technology (ICT) companies, comprising a group of global technology companies. In 2020, Dimension Data completed its transition to operate as one entity consolidating all its subsidiaries under a single Dimension Data brand employing over 10 000 employees across 15 countries. We continue to invest heavily in innovation bringing together the world’s best technologies, from consulting, technical and support services to a fully managed service. Dimension Data is currently a level 2 BBBEE contributor after successfully concluding a significant BBBEE transaction in 2019. Dimension Data will continue to implement strategies to ensure it contributes meaningfully to transformation towards an inclusive society.
Company Details
dimension-data
12,291
434,819
5415
dimensiondata.com
0
DIM_1978732
In-progress
Between 750 and 799

Dimension Data Global Score (TPRM)XXXX

Description: The cybercrime group Coinbase Cartel targeted NTT Data, a Japanese IT services giant, by exploiting vulnerabilities in its US subsidiary Vectorform (acquired in 2022). The attack involved large-scale data exfiltration without encryption, leveraging exposed credentials in cloud repositories (e.g., AWS, GitHub) and potential insider assistance. While NTT Data denied a direct breach, Vectorform’s systems were compromised, with sensitive operational, client, or proprietary data stolen. Coinbase Cartel employed a ‘leak-only’ ransomware model, threatening public disclosure to extort payment while avoiding system disruption. The stolen data likely including logistics, supply chain, or corporate intelligence poses reputational, legal, and financial risks, particularly given the transportation/logistics sector’s reliance on third-party integrations (TMS, WMS, EDI). The breach underscores vulnerabilities in vendor access controls, credential hygiene, and segmentation, with the group staging leaks to pressure negotiations. No encryption occurred, but the theft of high-value data exposes NTT Data to regulatory scrutiny, customer distrust, and potential litigation, especially if client or employee records were exposed.


No incidents recorded for Dimension Data in 2026.
No incidents recorded for Dimension Data in 2026.
No incidents recorded for Dimension Data in 2026.
Dimension Data cyber incidents detection timeline including parent company and subsidiaries

Dimension Data is a leading African born technology provider operating in the Middle East and Africa, offering a portfolio of services including systems integration, managed services infrastructure, cloud solutions, business applications, customer experience, and intelligent security solutions. We provide innovative solutions that optimise today’s evolving technology environments, enabling clients to leverage data in a digital age. Founded in 1983, and headquartered in Johannesburg, Dimension Data is a proud member of the NTT Group, one of the world’s leading information communication technology (ICT) companies, comprising a group of global technology companies. In 2020, Dimension Data completed its transition to operate as one entity consolidating all its subsidiaries under a single Dimension Data brand employing over 10 000 employees across 15 countries. We continue to invest heavily in innovation bringing together the world’s best technologies, from consulting, technical and support services to a fully managed service. Dimension Data is currently a level 2 BBBEE contributor after successfully concluding a significant BBBEE transaction in 2019. Dimension Data will continue to implement strategies to ensure it contributes meaningfully to transformation towards an inclusive society.


In a rapidly changing world, technology is everything. It's in the fabric of society. In every part of every business. At the very heart of human evolution. It’s a great power that comes with great responsibility. At Tietoevry, we believe it’s time to shift perspective. It’s not about what technolo

Insight Enterprises, Inc. is a Fortune 500 solutions integrator helping organizations accelerate their digital journey to modernize their business and maximize the value of technology. Insight’s technical expertise spans cloud and edge-based transformation solutions, with global scale and optimizati

Akkodis is a global digital engineering company and Smart Industry leader. We enable clients to advance in their digital transformation with Talent, Academy, Consulting, and Solutions services. Our 50,000 experts combine best-in-class technologies, R&D, and deep sector know-how for purposeful innova

At Ricoh, we bring people, processes, and technology together to make information work for you. We unlock the power of information so organizations can unlock the full potential of their people. We're a leader in information management and digital services, creating competitive advantage for over 1.

Part of the Capgemini Group, Sogeti makes business value through technology for organizations that need to implement innovation at speed and want a local partner with global scale. With a hands-on culture and close proximity to its clients, Sogeti implements solutions that will help organizations wo

Tech Mahindra offers technology consulting and digital solutions to global enterprises across industries, enabling transformative scale at unparalleled speed. With 149k+ professionals across 90+ countries helping 1100+ clients, TechM provides a full spectrum of services including consulting, informa

Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized skills across more than 40 industries, we offer Strategy and Consulting, Interactive, Technology and Operations services — all powered by the w
Lenovo is a US$69 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a

Unlocking financial technology. Bringing the world’s money into harmony. At FIS, we advance the way the world pays, banks, and invests. With decades of expertise, we provide financial technology solutions to financial institutions, businesses, and developers. Headquartered in Jacksonville, Florida,
.png)
Anthropic confirms testing Claude Mythos after a data leak exposed draft documents. The model sits above Opus and raises major cybersecurity...
Data breaches have recently been reported by Cedar Valley Services and Health Dimensions Group in Minnesota, and Community Nurse in...
Cyber security refers to technologies, processes, and rules created to protect computer systems, servers, networks, programs, and data from cyber-attacks.
The rapid growth in the adoption of Internet of Things (IoT) ecosystems has led to a large-scale influx of multidimensional data,...
Artificial intelligence (AI) is a present-day reality reshaping the cybersecurity landscape. For chief information security officers (CISOs)...
Cybersecurity is one of the applications of controls, procedures, and technologies for protecting data, networks, programs, and systems from...
Ghana's cybersecurity regulator is intensifying efforts to strengthen compliance among operators of critical national infrastructure as...
Slipstream Cyber has announced the appointment of David Kaplan as General Manager – Cyber Security and Steve Macdonald as Director – Cyber Security Practise.
The CNIL publishes an analysis of the economic impact of GDPR on cybersecurity. By reinforcing obligations in this area, the regulation has helped prevent, for...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Dimension Data is http://www.dimensiondata.com/.
According to Rankiteo, Dimension Data’s AI-generated cybersecurity score is 783, reflecting their Fair security posture.
According to Rankiteo, Dimension Data currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Dimension Data has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Dimension Data is not certified under SOC 2 Type 1.
According to Rankiteo, Dimension Data does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Dimension Data is not listed as GDPR compliant.
According to Rankiteo, Dimension Data does not currently maintain PCI DSS compliance.
According to Rankiteo, Dimension Data is not compliant with HIPAA regulations.
According to Rankiteo,Dimension Data is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Dimension Data operates primarily in the IT Services and IT Consulting industry.
Dimension Data employs approximately 12,291 people worldwide.
Dimension Data presently has no subsidiaries across any sectors.
Dimension Data’s official LinkedIn profile has approximately 434,819 followers.
Dimension Data is classified under the NAICS code 5415, which corresponds to Computer Systems Design and Related Services.
Yes, Dimension Data has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/dimension-data.
Yes, Dimension Data maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/dimension-data.
As of March 28, 2026, Rankiteo reports that Dimension Data has experienced 1 cybersecurity incidents.
Dimension Data has an estimated 39,818 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with enforce least-privilege access for tms/wms/edi systems, containment measures with disable legacy email protocols (imap/pop3), containment measures with implement phishing-resistant mfa, and remediation measures with deploy data loss prevention (dlp) for microsoft 365/google drive/email, remediation measures with monitor/block mass downloads via service accounts, remediation measures with configure alerts for mailbox forwarding rules and bulk compression, remediation measures with enhance edr coverage for admin/remote hosts, and network segmentation with recommended to limit lateral movement, and enhanced monitoring with behavioral analytics for anomalies, enhanced monitoring with oauth grant monitoring..
Title: Coinbase Cartel Data Exfiltration Campaign Targeting Transportation and Logistics Sectors
Description: A new cybercrime group, 'Coinbase Cartel,' has emerged with a focus on data exfiltration (leak-only model) rather than traditional ransomware encryption. The group targets transportation, logistics, and adjacent sectors, exploiting exposed credentials, insider threats, and weak segmentation to steal high-value operational and shipment data. Victims are pressured through staged data leaks and extortion threats, with no disruption to operations, making detection difficult. Confirmed or claimed victims include NTT Data (potentially via subsidiary Vectorform). The group operates with a 'business-like' approach, including partnerships with insiders and staged evidence packages.
Date Detected: 2023-09-15
Date Publicly Disclosed: 2023-09-15
Type: Data Breach
Attack Vector: Exploiting exposed/hard-coded credentials in cloud/source code repositories (AWS, Bitbucket, GitHub)Insider-assisted accessWeak network segmentationThird-party vendor compromises (e.g., TMS, WMS, EDI systems)Staged data leaks for extortion pressure
Vulnerability Exploited: Poor credential hygiene (hard-coded/exposed credentials)Lack of least-privilege access controlsAbsence of phishing-resistant MFAUnmonitored mass data downloads/email exfiltrationLegacy email protocols (IMAP/POP3)Insufficient DLP and behavioral analytics
Threat Actor: Coinbase Cartel
Motivation: Financial Gain (Extortion)Reputational DamageOperational Disruption (via data leaks)
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Exposed credentials in cloud repositoriesInsider access (crowdsourced)Third-party vendor compromises (e.g. and Vectorform).

Data Compromised: Operational data, Shipment data, High-value corporate data (potentially pii)
Systems Affected: Transportation Management Systems (TMS)Warehouse Management Systems (WMS)EDI linksCloud repositories (AWS, Bitbucket, GitHub)Email systems (Microsoft 365, Google Drive)
Downtime: None (no encryption or operational disruption)
Operational Impact: Reputational risk from staged data leaksLegal/regulatory exposurePotential supply chain disruptions if vendor data is compromised
Brand Reputation Impact: High (public extortion threats and staged leaks)Loss of trust in supply chain integrity
Legal Liabilities: Potential GDPR/CCPA violations if PII is exposedContractual breaches with third-party vendors
Identity Theft Risk: Possible (if PII is exfiltrated)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Operational Data, Shipment Data, Source Code (Potential), Corporate Emails, Potentially Pii and .

Entity Name: NTT Data
Entity Type: IT Services
Industry: Technology
Location: Japan (global operations)
Size: Large enterprise

Entity Name: Vectorform (subsidiary of NTT Data)
Entity Type: IT Services/Software Development
Industry: Technology
Location: United States

Entity Name: Unnamed transportation/logistics companies (multiple continents)
Entity Type: 3PL Providers, Carriers, Brokers, Customs Agents
Industry: Transportation and Logistics
Location: Global

Containment Measures: Enforce least-privilege access for TMS/WMS/EDI systemsDisable legacy email protocols (IMAP/POP3)Implement phishing-resistant MFA
Remediation Measures: Deploy Data Loss Prevention (DLP) for Microsoft 365/Google Drive/emailMonitor/block mass downloads via service accountsConfigure alerts for mailbox forwarding rules and bulk compressionEnhance EDR coverage for admin/remote hosts
Network Segmentation: ['Recommended to limit lateral movement']
Enhanced Monitoring: Behavioral analytics for anomaliesOAuth grant monitoring

Type of Data Compromised: Operational data, Shipment data, Source code (potential), Corporate emails, Potentially pii
Sensitivity of Data: High (operational integrity, supply chain data)
Data Exfiltration: Confirmed (staged leaks)Mass downloads via cloud/email
Data Encryption: None (leak-only model)
File Types Exposed: ZIP archives (bulk compression)EmailsDatabase exportsSource code
Personally Identifiable Information: Possible (not confirmed)
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Deploy Data Loss Prevention (DLP) for Microsoft 365/Google Drive/email, Monitor/block mass downloads via service accounts, Configure alerts for mailbox forwarding rules and bulk compression, Enhance EDR coverage for admin/remote hosts, .
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by enforce least-privilege access for tms/wms/edi systems, disable legacy email protocols (imap/pop3), implement phishing-resistant mfa and .

Ransomware Strain: N/A (leak-only, no encryption)
Data Encryption: None
Data Exfiltration: Primary tactic

Regulations Violated: Potential GDPR (if EU data exposed), CCPA (if California residents affected), Industry-specific data protection laws,

Lessons Learned: Leak-only extortion models bypass traditional ransomware defenses (no encryption = no operational disruption but high reputational risk)., Third-party vendors (e.g., Vectorform) can serve as attack vectors for larger targets (e.g., NTT Data)., Insider threats are actively crowdsourced by groups like Coinbase Cartel., Complex supply chains (transportation/logistics) create expansive attack surfaces.

Recommendations: Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g., breach notification requirements)., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks.
Key Lessons Learned: The key lessons learned from past incidents are Leak-only extortion models bypass traditional ransomware defenses (no encryption = no operational disruption but high reputational risk).,Third-party vendors (e.g., Vectorform) can serve as attack vectors for larger targets (e.g., NTT Data).,Insider threats are actively crowdsourced by groups like Coinbase Cartel.,Complex supply chains (transportation/logistics) create expansive attack surfaces.

Source: Media investigation (unnamed)

Source: Coinbase Cartel darknet leak site

Source: NTT Data public statement (denial of confirmed breach)
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Media investigation (unnamed), and Source: Coinbase Cartel darknet leak site, and Source: NTT Data public statement (denial of confirmed breach).

Investigation Status: Ongoing (group active as of latest reports)

Entry Point: Exposed Credentials In Cloud Repositories, Insider Access (Crowdsourced), Third-Party Vendor Compromises (E.G., Vectorform),
High Value Targets: Tms/Wms/Edi Systems, Supply Chain Data, Corporate Emails,
Data Sold on Dark Web: Tms/Wms/Edi Systems, Supply Chain Data, Corporate Emails,

Root Causes: Poor Credential Management (Hard-Coded/Exposed Credentials In Repositories)., Lack Of Segmentation Between Subsidiaries (E.G., Vectorform → Ntt Data)., Insufficient Monitoring For Data Exfiltration (No Dlp/Behavioral Alerts)., Over-Reliance On Third-Party Vendors With Weak Security Postures.,
Corrective Actions: Mandate Mfa And Least-Privilege Access For All Systems., Isolate High-Value Systems (Tms/Wms) From Third-Party Networks., Deploy Dlp And Edr With Behavioral Analytics For Exfiltration Detection., Audit Cloud Repositories For Exposed Credentials.,
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Behavioral Analytics For Anomalies, Oauth Grant Monitoring, .
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Mandate Mfa And Least-Privilege Access For All Systems., Isolate High-Value Systems (Tms/Wms) From Third-Party Networks., Deploy Dlp And Edr With Behavioral Analytics For Exfiltration Detection., Audit Cloud Repositories For Exposed Credentials., .
Last Attacking Group: The attacking group in the last incident was an Coinbase Cartel.
Most Recent Incident Detected: The most recent incident detected was on 2023-09-15.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-09-15.
Most Significant Data Compromised: The most significant data compromised in an incident were Operational data, Shipment data, High-value corporate data (potentially PII) and .
Most Significant System Affected: The most significant system affected in an incident were Transportation Management Systems (TMS)Warehouse Management Systems (WMS)EDI linksCloud repositories (AWS, Bitbucket, GitHub)Email systems (Microsoft 365, Google Drive).
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Enforce least-privilege access for TMS/WMS/EDI systemsDisable legacy email protocols (IMAP/POP3)Implement phishing-resistant MFA.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were High-value corporate data (potentially PII), Shipment data and Operational data.
Most Significant Lesson Learned: The most significant lesson learned from past incidents was Complex supply chains (transportation/logistics) create expansive attack surfaces.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Enforce least-privilege access and phishing-resistant MFA across all systems (especially TMS/WMS/EDI)., Monitor for anomalies like bulk ZIP file creation, OAuth abuses, and mailbox forwarding rules., Implement DLP controls to prevent mass data exfiltration via email/cloud services., Conduct regular insider threat awareness training to mitigate crowdsourced collusion risks., Segment networks to limit lateral movement from compromised vendors/subsidiaries., Deploy behavioral analytics to detect subtle signs of data staging (e.g., unusual compression activities)., Audit third-party vendor security postures and include cybersecurity clauses in contracts (e.g. and breach notification requirements)..
Most Recent Source: The most recent source of information about an incident are Media investigation (unnamed), NTT Data public statement (denial of confirmed breach) and Coinbase Cartel darknet leak site.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (group active as of latest reports).
.png)
A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out remotely.
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.
LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. An attacker can pollute `Object.prototype` by overriding `RegExp.prototype.test` and then passing a crafted query string to `parse_str`, bypassing the prototype pollution guard. This vulnerability stems from an incomplete fix for CVE-2026-25521. The CVE-2026-25521 patch replaced the `String.prototype.includes()`-based guard with a `RegExp.prototype.test()`-based guard. However, `RegExp.prototype.test` is itself a writable prototype method that can be overridden, making the new guard bypassable in the same way as the original — trading one hijackable built-in for another. Version 3.0.25 contains an updated fix.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.