Skip to content
COOEY
FAIL // HALL OF SHAME
2364 players ranked

Security failures of FedRAMP vendors, their competitors, and the hardware they ship — ranked by zero-days, RCE, active exploitation, sheer embarrassment, and False-Claims-Act recoveries. A dex.sgc.ai RAG curator writes each event's summary and scores how avoidable it was; every name links to its dossier.

☣ Most embarrassing
Ranked by how avoidable and reputation-shredding their worst failure was — the dex curator's grounded 0–100 verdict.
01
⚡ 1 ⌖ 1 shame 95
95shame
02
WSO2 vendor
⚡ 1 ⌖ 1 ☣ 1 shame 95
95shame
03
BQE vendor
⚡ 1 ⌖ 1 ☣ 1 shame 95
95shame
04
CyberPersons vendor
⚡ 2 ⌖ 2 ☣ 2 shame 95
95shame
05
RARLAB vendor
⚡ 4 ⌖ 5 ☣ 3 shame 95
95shame
06
Atlassian vendor
◐ 1 ⚡ 8 ⌖ 13 ☣ 8 shame 95
95shame
◐ Most zero-days
Vulnerabilities exploited before a patch existed — the worst kind to ship.
01
Fortinet vendor
◐ 3 ⚡ 18 ⌖ 29 ☣ 13 shame 90
30-days
02
progress vendor
◐ 3 ⚡ 5 ⌖ 9 ☣ 4 shame 85
30-days
03
vtiger vendor
◐ 3 ⚡ 3 shame 50
30-days
04
flowiseai vendor
◐ 2 ⚡ 2 shame 50
20-days
05
apache vendor
◐ 1 ⚡ 33 ⌖ 40 ☣ 7 shame 95
10-days
06
Synacor vendor
◐ 1 ⚡ 15 ⌖ 18 ☣ 5 shame 90
10-days
⚡ Most RCEs
Remote/arbitrary code-execution flaws — full-compromise class bugs.
01
apple vendor
⚡ 70 ⌖ 93 shame 90
70RCEs
02
apache vendor
◐ 1 ⚡ 33 ⌖ 40 ☣ 7 shame 95
33RCEs
03
D-Link vendor
⚡ 23 ⌖ 26 ☣ 2 shame 95
23RCEs
04
Fortinet vendor
◐ 3 ⚡ 18 ⌖ 29 ☣ 13 shame 90
18RCEs
05
linux vendor
⚡ 17 ⌖ 26 ☣ 2 shame 90
17RCEs
06
Synacor vendor
◐ 1 ⚡ 15 ⌖ 18 ☣ 5 shame 90
15RCEs
⌖ Most exploited
Count of their CVEs on CISA's Known-Exploited-Vulnerabilities catalog — actively used against defenders.
01
apple vendor
⚡ 70 ⌖ 93 shame 90
93on KEV
02
apache vendor
◐ 1 ⚡ 33 ⌖ 40 ☣ 7 shame 95
40on KEV
03
Fortinet vendor
◐ 3 ⚡ 18 ⌖ 29 ☣ 13 shame 90
29on KEV
04
linux vendor
⚡ 17 ⌖ 26 ☣ 2 shame 90
26on KEV
05
D-Link vendor
⚡ 23 ⌖ 26 ☣ 2 shame 95
26on KEV
06
Synacor vendor
◐ 1 ⚡ 15 ⌖ 18 ☣ 5 shame 90
18on KEV
⚖ Biggest FCA recoveries
Dollars recovered from contractors who misrepresented their cybersecurity — DOJ Civil Cyber-Fraud settlements.
No entries yet — the curator populates this board as failure events are assessed.