Comparison Overview

American Institute of Physics

VS

Goodwill Industries International

American Institute of Physics

American Center for Physics, College Park, MD, 20740, US
Last Update: 2025-03-04 (UTC)
Between 900 and 1000

Excellent

The American Institute of Physics (AIP) advances, promotes, and serves the physical sciences for the benefit of humanity. As both a federation of physical science societies and an institute, AIP offers programs, products, and services that empower physical scientists to continue to change our world and advance the frontiers of knowledge. AIP Member Societies cover a broad range of fields in the physical sciences and collectively represent more than 120,000 scientists, engineers, educators and students in the global physical sciences community. They include the Acoustical Society of America (ASA), the American Association of Physicists in Medicine (AAPM), the American Association of Physics Teachers (AAPT), the American Astronomical Society (AAS), ACA: The Structural Science Society, the American Meteorological Society (AMS), the American Physical Society (APS), AVS: Science & Technology of Materials, Interfaces, and Processing, Optica, and the Society of Rheology (SoR). In 2020, the AIP Foundation was launched to directly support AIP programs that preserve and celebrate the history of physics, foster support for future generations of physicists, and create a more equitable and accessible field for all. AIP Publishing is a wholly owned not-for-profit subsidiary of the American Institute of Physics.

NAICS: 8135
NAICS Definition: Others
Employees: 422
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Goodwill Industries International

15810 Indianola Dr., None, Rockville, Maryland, US, 20855
Last Update: 2025-07-26 (UTC)

Excellent

Between 900 and 1000

Goodwill Industries is all about people working. We are North Americaโ€™s leading nonprofit provider of education, training, and career services for people with disadvantages, such as welfare dependency, homelessness, and lack of education or work experience, as well as those with physical, mental and emotional disabilities. We believe that work has the power to transform lives by building self-confidence, independence, creativity, trust and friendships. Everyone deserves a chance to have these. Goodwill provides that chance. Considering working at Goodwill? Goodwill is nonprofit brand that is respected and highly relevant in todayโ€™s economy. Forbes recently named Goodwill one of the "Top 25 Most Inspiring Companies."โ€‹

NAICS: 8135
NAICS Definition: Others
Employees: 21,755
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/american-institute-of-physics.jpeg
American Institute of Physics
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/goodwill-industries-international.jpeg
Goodwill Industries International
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
American Institute of Physics
100%
Compliance Rate
0/4 Standards Verified
Goodwill Industries International
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Non-profit Organizations Industry Average (This Year)

No incidents recorded for American Institute of Physics in 2025.

Incidents vs Non-profit Organizations Industry Average (This Year)

No incidents recorded for Goodwill Industries International in 2025.

Incident History โ€” American Institute of Physics (X = Date, Y = Severity)

American Institute of Physics cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” Goodwill Industries International (X = Date, Y = Severity)

Goodwill Industries International cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/american-institute-of-physics.jpeg
American Institute of Physics
Incidents

No Incident

https://images.rankiteo.com/companyimages/goodwill-industries-international.jpeg
Goodwill Industries International
Incidents

No Incident

FAQ

Both American Institute of Physics company and Goodwill Industries International company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Historically, Goodwill Industries International company has disclosed a higher number of cyber incidents compared to American Institute of Physics company.

In the current year, Goodwill Industries International company and American Institute of Physics company have not reported any cyber incidents.

Neither Goodwill Industries International company nor American Institute of Physics company has reported experiencing a ransomware attack publicly.

Neither Goodwill Industries International company nor American Institute of Physics company has reported experiencing a data breach publicly.

Neither Goodwill Industries International company nor American Institute of Physics company has reported experiencing targeted cyberattacks publicly.

Neither American Institute of Physics company nor Goodwill Industries International company has reported experiencing or disclosing vulnerabilities publicly.

American Institute of Physics company has more subsidiaries worldwide compared to Goodwill Industries International company.

Goodwill Industries International company employs more people globally than American Institute of Physics company, reflecting its scale as a Non-profit Organizations.

Latest Global CVEs (Not Company-Specific)

Description

Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Question Mark button, the Help Button, the About button, and the Help Button, leading to a transition out of kiosk mode into local administrative access. NOTE: the reporter indicates that the "behavior was observed sporadically" during "limited time on the client site," making it not "possible to gain more information about the specific kiosk mode crashing issue," and the only conclusion was "there appears to be some form of race condition." Accordingly, there can be doubt that a reproducible cybersecurity vulnerability was identified; sporadic software crashes can also be caused by a hardware fault on a single device (for example, transient RAM errors). The reporter also describes a variety of other issues, including initial access via USB because of the absence of a "lock-pick resistant locking solution for the External Controller PC cabinet," which is not a cybersecurity vulnerability (section 4.1.5 of the CNA Operational Rules). Finally, it is unclear whether the device or OS configuration was inappropriate, given that the risks are typically limited to insider threats within the mail operations room of a large company.

Risk Information
cvss3
Base: 6.4
Severity: HIGH
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. The vulnerability is located in numerous repository related handlers in the util/db/repository_secrets.go file. A valid API token with repositories resource permissions (create, update, or delete actions) is required to trigger the race condition. This vulnerability causes the entire Argo CD server to crash and become unavailable. Attackers can repeatedly and continuously trigger the race condition to maintain a denial-of-service state, disrupting all GitOps operations. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Description

Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via any rich text field in a web content article.

Risk Information
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1, released on September 23, 2025.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request.