Skip to content
COOEY
FAIL // HALL OF SHAME
2293 players ranked

Security failures of FedRAMP vendors, their competitors, and the hardware they ship — ranked by zero-days, RCE, active exploitation, sheer embarrassment, and False-Claims-Act recoveries. A dex.sgc.ai RAG curator writes each event's summary and scores how avoidable it was; every name links to its dossier.

☣ Most embarrassing
Ranked by how avoidable and reputation-shredding their worst failure was — the dex curator's grounded 0–100 verdict.
01
SMBv1 product
⚡ 2 ⌖ 2 ☣ 2 shame 95
95shame
02
⚡ 1 ⌖ 1 ☣ 1 shame 95
95shame
03
⚡ 1 ⌖ 1 ☣ 1 shame 95
95shame
04
⚡ 1 ⌖ 1 shame 95
95shame
05
⚡ 1 ⌖ 1 ☣ 1 shame 95
95shame
06
⚡ 1 ⌖ 1 ☣ 1 shame 95
95shame
◐ Most zero-days
Vulnerabilities exploited before a patch existed — the worst kind to ship.
01
Microsoft FEDRAMP company
◐ 7 ⚡ 239 ⌖ 383 ☣ 104 shame 95
70-days
02
windows product
◐ 3 ⚡ 97 ⌖ 172 ☣ 46 shame 95
30-days
03
Ivanti FEDRAMP company
◐ 3 ⚡ 24 ⌖ 35 ☣ 12 shame 90
30-days
04
Fortinet vendor
◐ 3 ⚡ 18 ⌖ 29 ☣ 13 shame 90
30-days
05
progress vendor
◐ 3 ⚡ 5 ⌖ 9 ☣ 4 shame 85
30-days
06
vtiger vendor
◐ 3 ⚡ 3 shame 50
30-days
⚡ Most RCEs
Remote/arbitrary code-execution flaws — full-compromise class bugs.
01
Microsoft FEDRAMP company
◐ 7 ⚡ 239 ⌖ 383 ☣ 104 shame 95
239RCEs
02
windows product
◐ 3 ⚡ 97 ⌖ 172 ☣ 46 shame 95
97RCEs
03
apple vendor
⚡ 70 ⌖ 93 shame 90
70RCEs
04
Adobe FEDRAMP company
◐ 2 ⚡ 60 ⌖ 80 ☣ 10 shame 95
60RCEs
05
⚡ 59 ⌖ 79 ☣ 8 shame 95
59RCEs
06
Cisco Systems Inc. FEDRAMP company
◐ 2 ⚡ 49 ⌖ 96 ☣ 6 shame 90
49RCEs
⌖ Most exploited
Count of their CVEs on CISA's Known-Exploited-Vulnerabilities catalog — actively used against defenders.
01
Microsoft FEDRAMP company
◐ 7 ⚡ 239 ⌖ 383 ☣ 104 shame 95
383on KEV
02
windows product
◐ 3 ⚡ 97 ⌖ 172 ☣ 46 shame 95
172on KEV
03
Cisco Systems Inc. FEDRAMP company
◐ 2 ⚡ 49 ⌖ 96 ☣ 6 shame 90
96on KEV
04
apple vendor
⚡ 70 ⌖ 93 shame 90
93on KEV
05
Adobe FEDRAMP company
◐ 2 ⚡ 60 ⌖ 80 ☣ 10 shame 95
80on KEV
06
⚡ 59 ⌖ 79 ☣ 8 shame 95
79on KEV
⚖ Biggest FCA recoveries
Dollars recovered from contractors who misrepresented their cybersecurity — DOJ Civil Cyber-Fraud settlements.
01
Hill ASC Inc. company
shame 40
$14.75M
02
Guidehouse Inc. company
shame 40
$11.30M
03
Associates company
shame 40
$11.30M
04
Nan McKay company
shame 40
$11.30M
05
Centene company
shame 40
$11.25M
06
shame 40
$11.25M