FAIL // HALL OF SHAME
2293 players ranked
Security failures of FedRAMP vendors, their competitors, and the hardware they ship — ranked by zero-days, RCE, active exploitation, sheer embarrassment, and False-Claims-Act recoveries. A dex.sgc.ai RAG curator writes each event's summary and scores how avoidable it was; every name links to its dossier.
On the board
2293
players
Zero-days
84
tracked
RCEs
1300
assessed
Exploited
1662
in the wild
Assessed
2136
events
FCA recovered
$82M
DOJ CCFI
☣ Most embarrassing
Ranked by how avoidable and reputation-shredding their worst failure was — the dex curator's grounded 0–100 verdict.
◐ Most zero-days
Vulnerabilities exploited before a patch existed — the worst kind to ship.
⚡ Most RCEs
Remote/arbitrary code-execution flaws — full-compromise class bugs.
⌖ Most exploited
Count of their CVEs on CISA's Known-Exploited-Vulnerabilities catalog — actively used against defenders.
⚖ Biggest FCA recoveries
Dollars recovered from contractors who misrepresented their cybersecurity — DOJ Civil Cyber-Fraud settlements.