The organizations the security industry is discussing right now. Ranked by mention velocity across breach reports, vendor advisories, and threat intelligence — refreshed continuously.
Ranked by Mallory's mention-velocity model across sources.
Microsoft Corporation is a multinational technology company headquartered in Redmond, Washington, United States. Founded in 1975, it develops and sells software, cloud-computing services, enterprise platforms, devices, and consumer technology. Its major product and service lines include Windows, Microsoft 365, Azure, Dynamics 365, LinkedIn, GitHub, Xbox, and security offerings such as Microsoft Defender, Microsoft Sentinel, and Microsoft Entra. Microsoft is among the world’s largest technology companies, with a global workforce exceeding 200,000 employees. Microsoft operates extensive security research, incident-response, and threat-intelligence functions, including the Microsoft Security Response Center, Microsoft Threat Intelligence, and the Digital Crimes Unit. It publishes security updates and vulnerability advisories, maintains coordinated vulnerability-disclosure and bug-bounty programs, and provides security products for endpoint protection, identity, cloud security, SIEM, and automation. Its widely deployed operating systems, productivity software, cloud infrastructure, and developer platforms make vulnerabilities and supply-chain risks affecting Microsoft products significant to organizations globally.
Google LLC is a multinational technology company headquartered in Mountain View, California, United States, and a subsidiary of Alphabet Inc. It operates major internet products and platforms including Google Search, advertising services, YouTube, Android, Chrome, Google Maps, Google Play, Google Workspace, Google Cloud, and Gemini AI services. Google Cloud provides enterprise cloud computing, data analytics, identity, logging, Kubernetes, and security services. Google maintains significant product-security and threat-intelligence capabilities. Its security organizations include Project Zero, which researches high-impact vulnerabilities; the Google Threat Analysis Group, which investigates government-backed and coordinated threat activity; and Google Threat Intelligence, which incorporates Mandiant capabilities acquired in 2022. Google develops and maintains Chromium and Chrome, publishes security updates for its products, operates the Android ecosystem’s Play Protect malware-defense service, and offers Advanced Protection for users at elevated risk of targeted attacks. As a major cloud and software provider, Google’s products and infrastructure are frequent targets for vulnerability research, abuse by threat actors, phishing impersonation, and supply-chain risk. Google operates vulnerability disclosure and reward programs and regularly issues security advisories and patches for supported products and services.
OpenAI is a United States artificial-intelligence research and deployment organization headquartered in San Francisco, California. Founded in 2015, it develops and operates large language models and related AI systems. Its widely used products include ChatGPT, the OpenAI API, GPT-family models, and Codex tools for software-development workflows. OpenAI operates through a nonprofit and affiliated commercial structure. Its technologies are used by consumers, developers, enterprises, and public-sector organizations for conversational AI, content generation, coding assistance, data analysis, and agentic workflows. Security-relevant considerations for OpenAI products include protection of API credentials and account tokens, secure integration of model tools and external data sources, resistance to prompt injection, and strong access controls for AI-enabled development and automation environments. OpenAI maintains vulnerability-disclosure processes, including Bugcrowd-managed reporting for certain products.
Amazon Web Services (AWS) is Amazon’s cloud-computing business, providing on-demand infrastructure, platform, data, analytics, artificial intelligence, security, networking, storage, and managed application services. Launched in 2006 and headquartered in Seattle, Washington, AWS operates globally through a distributed cloud infrastructure of Regions and Availability Zones and serves organizations ranging from startups and public-sector entities to large enterprises. AWS’s security and identity portfolio includes AWS Identity and Access Management (IAM), AWS Security Token Service (STS), AWS Organizations, Amazon EKS identity integrations, AWS Systems Manager, AWS Key Management Service, Amazon GuardDuty, AWS Security Hub, Amazon Inspector, and AWS Secrets Manager. Its IAM architecture supports temporary credentials, role assumption, federation, workload identities, and centralized authorization controls intended to reduce reliance on long-term access keys and enable least-privilege access. AWS CloudTrail provides audit logging for API activity. Security considerations in AWS environments commonly include protecting root-user credentials, enforcing multifactor authentication, tightly scoping IAM roles and trust policies, restricting access to instance metadata services, monitoring role-assumption activity, and preventing exposure of temporary credentials. AWS provides mechanisms such as IAM Roles for Service Accounts, IAM Roles Anywhere, resource control policies, and IoT certificate-based credential provisioning to support workload-specific, short-lived access credentials.
Anthropic PBC is a U.S.-based artificial-intelligence research and product company headquartered in San Francisco, California. Founded in 2021 by former OpenAI employees, including Dario Amodei and Daniela Amodei, it develops the Claude family of general-purpose large language models and associated enterprise, API, and developer products, including Claude Code. The company is structured as a public-benefit corporation and emphasizes AI safety, alignment research, and the responsible deployment of increasingly capable AI systems. Anthropic provides models and services for consumer, enterprise, software-development, and cloud-platform use, with availability through its own products and major cloud providers. Its safety work includes model evaluations, policy controls for high-risk capabilities, responsible-scaling practices, and research into AI-system misuse and autonomy risks. Security considerations relevant to Anthropic products include the risks inherent in AI coding agents, tool integrations, Model Context Protocol deployments, prompt injection, and access to local files, shells, credentials, and third-party services. Claude Code has had publicly reported vulnerabilities involving filesystem containment, command validation, and Windows machine-wide configuration handling; Anthropic issued fixes for reported issues and assigned CVE-2026-35603 to a Windows cross-user code-execution flaw affecting managed settings. Organizations deploying Anthropic products should apply least privilege, protect API credentials, constrain tool and MCP-server permissions, maintain current software versions, and ensure human oversight for sensitive or production-impacting actions.
Apple Inc. is a multinational technology company headquartered in Cupertino, California, United States. It designs and sells consumer hardware including iPhone, Mac, iPad, Apple Watch, Apple TV, and Vision products; develops operating systems including iOS, iPadOS, macOS, watchOS, tvOS, and visionOS; and operates services including the App Store, iCloud, Apple Music, Apple TV+, Apple Pay, and HomeKit. Apple is one of the world’s largest publicly traded companies and maintains a global retail, developer, software-distribution, and cloud-services ecosystem. Security-relevant operations include platform security engineering, vulnerability remediation through operating-system and application updates, application notarization and App Store review controls, and targeted threat notifications for users assessed to be at risk from mercenary spyware. Apple has remediated vulnerabilities affecting components such as iMessage, AirPlay, Calendar, and WebKit; its products and services are frequent targets for sophisticated vulnerability research and commercial spyware operations.
VulnCheck is a cybersecurity threat-intelligence and vulnerability-intelligence organization. It publishes vulnerability advisories and CVE-related disclosures, tracks exploit activity, and operates Canary sensors to observe attacks against exposed services. Its reporting has documented active exploitation of critical vulnerabilities affecting internet-facing software, including Langflow, and post-exploitation activity aimed at identifying administrator credentials, cloud-service credentials, API keys, SSH material, and other sensitive data. VulnCheck also maintains vulnerability intelligence intended to help organizations prioritize remediation based on exploitation risk.
Hewlett Packard Enterprise (HPE) is a multinational enterprise information-technology company headquartered in Spring, Texas, United States. Formed in 2015 through the separation of the former Hewlett-Packard Company, HPE provides enterprise servers, storage, networking, cloud and hybrid-cloud platforms, software, and related consulting and support services. Its major businesses include HPE Aruba Networking, which supplies enterprise networking hardware and management products, and data-center infrastructure offerings including HPE Compute and HPE Storage. HPE maintains a product security response function and publishes security advisories and software updates for supported products. In September 2026, HPE released fixes for numerous vulnerabilities affecting HPE Aruba Networking ArubaOS-CX and HPE Networking Fabric Composer. These included critical unauthenticated remote-code-execution and authentication-bypass issues that could compromise exposed network-management infrastructure. HPE stated that it was not aware of active exploitation or public exploit code for the referenced ArubaOS-CX and Fabric Composer vulnerabilities at the time of disclosure. Organizations using affected products should apply supported fixed releases, isolate management interfaces, and restrict administrative access.
NVIDIA Corporation is a U.S. multinational technology company headquartered in Santa Clara, California. Founded in 1993, it designs GPUs, accelerated-computing platforms, networking products, data-processing hardware, and software used in gaming, professional visualization, high-performance computing, data centers, and artificial intelligence. Its major enterprise technologies include CUDA, AI inference and training software, DGX systems, NVIDIA Container Toolkit, GPU Operator, Triton Inference Server, BlueField data processing units, ConnectX network adapters, and NVIDIA networking platforms. NVIDIA is a major supplier of AI-computing infrastructure, with its GPUs and associated software widely deployed in cloud, enterprise, research, and Kubernetes-based environments. The company also operates security-response and product-advisory processes for vulnerabilities affecting its hardware, drivers, firmware, networking products, and software stack. CVE-2024-0132, a critical container-escape vulnerability in NVIDIA Container Toolkit, affected GPU-enabled container environments and was remediated through NVIDIA Container Toolkit version 1.16.2; NVIDIA GPU Operator version 24.6.2 was also recommended for affected Kubernetes deployments. Organizations using NVIDIA infrastructure should maintain component-level inventories and track updates across drivers, container tooling, firmware, DPUs, network adapters, telemetry, and inference software.
GitHub, Inc. is a software-development platform and subsidiary of Microsoft headquartered in San Francisco, California. Founded in 2008 and acquired by Microsoft in 2018, GitHub provides cloud-hosted and enterprise products for source-code hosting, version control, collaboration, issue tracking, package distribution, code review, and developer automation. Its principal offerings include GitHub.com, GitHub Enterprise, GitHub Actions, GitHub Copilot, GitHub Advanced Security, Dependabot, and Codespaces. GitHub Actions is widely used for CI/CD and automation, making workflow permissions, third-party actions, repository secrets, OpenID Connect federation, and self-hosted runners important security considerations. GitHub provides security features including secret scanning, push protection, dependency alerts, security advisories, code scanning, token permission controls, environment protections, and OIDC-based short-lived cloud authentication. GitHub’s security ecosystem has been the subject of substantial public research into software supply-chain risks. Researchers have demonstrated that unsafe configuration of self-hosted runners in public repositories can enable untrusted pull-request code to execute on owner-managed build infrastructure and persist beyond a job in certain configurations. In 2023, GitHub implemented mitigations after responsible disclosure involving its runner-image development infrastructure. GitHub Actions workflows and third-party actions have also been affected by publicly disclosed command-injection and privilege-escalation vulnerabilities, reinforcing the need to pin actions to immutable revisions, apply least-privilege token permissions, isolate untrusted builds, and require approval for external contributions on self-hosted runners.
Meta Platforms, Inc. is a U.S.-headquartered technology company based in Menlo Park, California. Formerly known as Facebook, Inc., it adopted the Meta name in 2021. Meta operates major social and communications services including Facebook, Instagram, Messenger, and WhatsApp, and develops advertising, artificial-intelligence, virtual- and mixed-reality, and social-platform technologies through businesses including Reality Labs. It is one of the world’s largest digital advertising and social-media companies, serving users globally and employing tens of thousands of people. The company has been the subject of significant privacy and security scrutiny. The Cambridge Analytica controversy involved the improper collection and use of Facebook user data by a third-party application and led to extensive regulatory, legal, and policy consequences. Meta operates security engineering and vulnerability-disclosure initiatives, including bug-bounty programs, and has remediated reported product vulnerabilities. Its open-source Llama Stack framework was affected by CVE-2024-50050, a remote code execution issue in a default Python inference implementation; Meta released a fix in Llama Stack version 0.0.41.
CrowdStrike Holdings, Inc. is a U.S. cybersecurity company headquartered in Austin, Texas. Founded in 2011, it provides cloud-delivered cybersecurity products and threat-intelligence services through the CrowdStrike Falcon platform. Its offerings include endpoint detection and response, endpoint protection, managed detection and response, cloud-security, identity-protection, exposure-management, and incident-response capabilities. CrowdStrike is publicly traded on Nasdaq under the symbol CRWD. CrowdStrike conducts threat research and tracks intrusion sets using its own adversary-naming taxonomy, including groups associated with financially motivated cybercrime and state-linked operations. Its Counter Adversary Operations team has participated with international law-enforcement and nonprofit partners in disruption activity targeting the Sality peer-to-peer botnet, including sinkholing operations intended to sever infected devices from criminal control infrastructure. On July 19, 2024, a defective CrowdStrike Falcon content update for Windows caused widespread system crashes and a global IT outage. The incident disrupted organizations across aviation, healthcare, finance, government, and other sectors. CrowdStrike withdrew the faulty update and issued remediation guidance; the event prompted broad scrutiny of software-update safeguards, staged deployment practices, and the operational risks of privileged endpoint-security software.
Hugging Face, Inc. is a U.S.-based artificial-intelligence company headquartered in New York City. It operates a widely used platform for hosting, sharing, evaluating, and deploying machine-learning models, datasets, and applications, particularly open-weight models. Its ecosystem includes the Hugging Face Hub and developer libraries such as Transformers, which are broadly used across research, enterprise, and open-source machine-learning communities. Hugging Face is a significant distribution and tooling layer for AI developers and supports deployment across multiple hardware and cloud environments. Its security relevance stems from the scale of its model and software supply chain: users may download third-party model artifacts and associated code from repositories. CVE-2026-80047 affects certain Hugging Face Transformers releases and can cause attacker-controlled Python content from a malicious model repository to be written to a local module cache before remote-code-execution consent is evaluated; direct execution remains subject to the consent control in the affected workflow.
Elastic N.V. is a publicly traded search, observability, and security software company best known for Elasticsearch and the Elastic Stack. Founded in 2012, it is headquartered in Mountain View, California, and has global operations. Its products support search, log analytics, application performance monitoring, infrastructure observability, endpoint security, SIEM, cloud security, and AI-assisted search applications. The Elastic Stack includes Elasticsearch, Kibana, Elastic Agent, Beats, Logstash, and related cloud and Kubernetes offerings, including Elastic Cloud and Elastic Cloud on Kubernetes. Elastic develops and maintains widely deployed enterprise software that processes sensitive operational and security data. It publishes security advisories and releases fixes for vulnerabilities affecting products including Kibana, Elasticsearch, Filebeat, Elastic Agent, APM Server, and Elastic Cloud on Kubernetes. Reported issues have included authorization flaws, path traversal, configuration-injection risks, data exposure, and denial-of-service conditions. Elastic Cloud Serverless has at times received remediation before public disclosure of affected self-managed product vulnerabilities. Elastic Security is the company's cybersecurity business, providing detection and response capabilities integrated with Elastic's data platform. Elastic Security Labs conducts and publishes threat research, including analysis of malware associated with the DPRK-attributed Contagious Interview campaign.
Patchstack is a cybersecurity company specializing in security for the WordPress ecosystem. Its platform provides vulnerability intelligence, coordinated vulnerability disclosure, a public vulnerability database, and mitigation rules intended to help website owners, hosting providers, and managed service providers identify and defend against vulnerable WordPress plugins, themes, and related components. Patchstack publishes advisories for vulnerabilities including SQL injection, arbitrary file upload, insecure deserialization, authentication bypass, cross-site request forgery, and privilege-escalation flaws, and contributes vulnerability information to the CVE ecosystem. It has also coordinated disclosure of high-severity WordPress plugin vulnerabilities and issued protective rules for reported exploitation activity.
CVEFeed.io is a vulnerability-intelligence website that publishes CVE history and vulnerability records. It aggregates CVSS severity information, presents vulnerability details, and scans GitHub repositories for proof-of-concept exploit material associated with disclosed vulnerabilities. The available information does not establish its corporate ownership, organization size, or physical location.
Tenable Holdings, Inc. is a publicly traded cybersecurity company headquartered in Columbia, Maryland, United States. Founded in 2002, it develops exposure-management and vulnerability-management products for enterprise, cloud, identity, operational-technology, web-application, and container environments. Its best-known technology is Nessus, a widely used vulnerability assessment scanner. Tenable’s portfolio includes Tenable One, Tenable Vulnerability Management, Tenable Cloud Security, Tenable OT Security, and related security research and detection content. The company publishes vulnerability intelligence, risk-prioritization data, and software composition analysis checks used to identify vulnerable assets and packages. In 2023, Tenable reported that information relating to some employees was affected by the MOVEit Transfer zero-day mass-exploitation campaign; it stated that its products and customer data were not affected.
F5, Inc. is a U.S.-based application delivery and security company headquartered in Seattle, Washington. Formerly known as F5 Networks, the company develops enterprise networking, application-delivery, traffic-management, load-balancing, API-security, and application-security products and services. Its principal product lines include BIG-IP, NGINX, F5OS, and related access-policy and edge-client offerings. F5 acquired NGINX in 2019 and maintains NGINX software and commercial products including NGINX Plus, NGINX Ingress Controller, NGINX Gateway Fabric, and NGINX JavaScript. F5 operates a product security incident-response capability and publishes security advisories, vulnerability assessments, mitigations, and fixed-release guidance for supported products. Security issues disclosed for its products have included authentication and privilege-escalation flaws affecting BIG-IP management interfaces, configuration-injection vulnerabilities in Kubernetes-oriented NGINX components, and memory-safety and denial-of-service vulnerabilities in NGINX JavaScript. The company is a significant vendor in internet-facing enterprise infrastructure, making prompt assessment and patching of exposed management planes, application-delivery systems, and NGINX deployments operationally important.
SonicWall is a U.S. cybersecurity company headquartered in Milpitas, California. It develops network-security products and services, including next-generation firewalls, secure remote-access and VPN appliances, zero-trust access capabilities, endpoint security, email security, and managed security offerings. The company was founded in 1991, operated as part of Dell following its 2012 acquisition, and became independent again in 2016. SonicWall’s Secure Mobile Access (SMA) 1000 enterprise remote-access appliance line has been targeted in repeated zero-day exploitation activity. In September 2026, SonicWall disclosed active exploitation of CVE-2026-83548, a critical pre-authentication server-side request forgery vulnerability, and CVE-2026-83549, an authenticated operating-system command-injection vulnerability. The vulnerabilities affect specified SMA 1000 appliance models and can be chained to obtain unauthenticated remote code execution. SonicWall released hotfixes and advised affected customers to assess systems for compromise; where compromise is confirmed, recommended actions include rebuilding or redeploying appliances and rotating passwords and time-based one-time-password tokens.
Advanced Micro Devices, Inc. (AMD) is a publicly traded multinational semiconductor company headquartered in Santa Clara, California. AMD designs high-performance computing and graphics products, including x86 processors for consumer PCs, workstations, and servers; Radeon graphics processors; EPYC server processors; adaptive computing devices and FPGAs obtained through its acquisition of Xilinx; and AI- and data-center-oriented accelerators and software platforms. Its products are used across consumer, enterprise, cloud, telecommunications, embedded, gaming, and high-performance-computing environments. AMD has issued security guidance and mitigations for vulnerabilities affecting its products and associated reference implementations. CVE-2023-20593, known as Zenbleed, affected Zen 2 processors and could permit locally executed code to infer sensitive data across isolation boundaries under certain conditions; remediation required processor microcode or system-firmware updates. AMD has also disclosed vulnerabilities in Trusted Platform Module reference code that can require downstream OEM-specific firmware updates. In addition, an older AMD-signed Windows ATI DSM Dynamic Driver has been documented as exposing privileged hardware-control capabilities that may be abused for local privilege escalation or bring-your-own-vulnerable-driver activity where the driver is installed and reachable from user mode.
Wordfence is a WordPress security platform and threat-intelligence operation developed by Defiant, Inc., a U.S. cybersecurity company headquartered in Seattle, Washington. Its offerings include a WordPress application firewall, malware scanning and remediation capabilities, vulnerability intelligence, and managed security services. Wordfence maintains a vulnerability-research program, operates a bug bounty program, coordinates responsible disclosure with WordPress theme and plugin developers, and publishes CVE-related vulnerability records. Its research team has identified critical vulnerabilities affecting widely deployed WordPress components, including Elementor Pro, Gravity Forms, TranslatePress, Avada and Fusion Builder, and WPMU DEV Dashboard. Wordfence also develops the Argus research framework and distributes protective firewall rules to supported customers.
Cisco Systems, Inc. is a multinational technology company headquartered in San Jose, California. Founded in 1984, Cisco designs, manufactures, and sells networking, security, collaboration, observability, and cloud-managed IT products and services. Its portfolio includes enterprise routing and switching platforms, wireless networking, data-center infrastructure, network-security appliances and software, collaboration products, and the Meraki cloud-managed networking platform. Cisco also owns Duo Security and operates Cisco Talos, its threat-intelligence and security-research organization. Cisco is one of the world’s largest enterprise networking and cybersecurity vendors, serving businesses, governments, telecommunications providers, educational institutions, and other large organizations globally. Cisco Product Security Incident Response Team coordinates vulnerability disclosure and publishes security advisories and remediation guidance for affected products. Cisco products are frequently targeted because of their widespread use in enterprise and critical-infrastructure environments. The ArcaneDoor cyber-espionage campaign targeted Cisco Adaptive Security Appliance and related perimeter-security devices through vulnerabilities including zero-days. Cisco has also issued security updates for high-severity vulnerabilities affecting products including Cisco Nexus switches, Cisco IOS XR Software, Secure Firewall Management Center, Secure Email, IP phones, and video phones. Organizations operating Cisco infrastructure should maintain supported software versions, apply Cisco security updates promptly, restrict management-plane exposure, and monitor vendor advisories and compromise-detection guidance.
Telegram is a cloud-based instant-messaging and social-media service founded in 2013 by Pavel Durov and Nikolai Durov. The platform provides private and group messaging, public channels, voice and video communications, file sharing, and a developer platform that includes bots and APIs. Telegram FZ-LLC is associated with Dubai, United Arab Emirates. Telegram is widely used for legitimate communications, broadcasting, communities, and automated services. Its public channels, groups, and Bot API have also been repeatedly abused by cybercriminals and threat actors for malware promotion and sales, affiliate coordination, phishing-kit administration, victim tracking, credential and telemetry collection, command-and-control communications, and data exfiltration. This abuse reflects adversary use of a legitimate third-party web service rather than evidence that Telegram itself participated in or was compromised by those operations.
Cloudflare, Inc. is a U.S.-based internet infrastructure and cybersecurity company headquartered in San Francisco, California. Founded in 2009, it operates a global edge network providing content delivery, authoritative DNS, DDoS mitigation, web application firewall, zero-trust access, application-security, developer-platform, cloud-storage, and serverless-computing services. Its products are used by organizations ranging from individual developers and small businesses to large enterprises and public-sector entities. Cloudflare has been a significant participant in internet-security operations, including large-scale DDoS defense and public reporting on exploitation activity affecting widely deployed technologies such as Apache Log4j. Its infrastructure and services may also be used or abused by third parties for malicious hosting, phishing, or payload distribution; such use does not by itself establish Cloudflare involvement in those operations. Cloudflare has remediated publicly reported security issues affecting its Pages continuous-deployment platform. Reported historical findings included command injection in build configuration processing, insufficient isolation between build workloads and Kubernetes host services, exposure of sensitive build-environment credentials, privilege-escalation paths in build infrastructure, and an H2C-smuggling condition that could bypass Cloudflare Access controls. Cloudflare reportedly addressed the disclosed Pages and H2C-related issues following coordinated reporting. These findings underscore the security importance of tenant isolation, least-privilege credentials, robust server-side input handling, secure CI/CD orchestration, and defense against proxy-protocol edge cases.