Company Details
federation-of-american-scientists
128
7,100
541
fas.org
0
FED_1118640
In-progress

Federation of American Scientists Company CyberSecurity Posture
fas.orgThe Federation of American Scientists (FAS) works to provide science-based analysis of and solutions to protect against catastrophic threats to national and international security. Specifically, FAS works to reduce the spread and number of nuclear weapons, prevent nuclear and radiological terrorism, promote high standards for nuclear energy’s safety and security, illuminate government secrecy practices, as well as track and eliminate the global illicit trade of conventional, nuclear, biological and chemical weapons. FAS was founded in 1945 by many of the Manhattan Project scientists who wanted to prevent nuclear war and is one of the longest serving organizations in the world dedicated to reducing nuclear threats and informing the public debate by providing technically-based research and analysis on these issues.
Company Details
federation-of-american-scientists
128
7,100
541
fas.org
0
FED_1118640
In-progress
Between 750 and 799

FAS Global Score (TPRM)XXXX



No incidents recorded for Federation of American Scientists in 2025.
No incidents recorded for Federation of American Scientists in 2025.
No incidents recorded for Federation of American Scientists in 2025.
FAS cyber incidents detection timeline including parent company and subsidiaries

The Federation of American Scientists (FAS) works to provide science-based analysis of and solutions to protect against catastrophic threats to national and international security. Specifically, FAS works to reduce the spread and number of nuclear weapons, prevent nuclear and radiological terrorism, promote high standards for nuclear energy’s safety and security, illuminate government secrecy practices, as well as track and eliminate the global illicit trade of conventional, nuclear, biological and chemical weapons. FAS was founded in 1945 by many of the Manhattan Project scientists who wanted to prevent nuclear war and is one of the longest serving organizations in the world dedicated to reducing nuclear threats and informing the public debate by providing technically-based research and analysis on these issues.


Over the past two decades, the Center for Global Development has maintained an unwavering focus on providing independent non-partisan research that has driven major changes in global development policy and practice. Our staff, located in Washington, D.C. and London, are our most valuable asset in a

UHack is one of Australia's leading Hackathons! UHack is a fast-paced three-day innovation competition, that encourages you and your team to think outside the box, creating business ideas and developing solutions for real world problems. UHack is open to students, staff of the University and mem

Centre for Civil Society advances social change through public policy. Our work in education, livelihood, and policy training promotes choice and accountability across the private and public sectors. To translate policy into practice, we engage with policy and opinion leaders through research, pilot
The mission of the Council on Foreign Relations is to inform U.S. engagement with the world. Founded in 1921, CFR is a nonpartisan, independent national membership organization, think tank, educator, and publisher, including of Foreign Affairs. It generates policy-relevant ideas and analysis, conve

Founded in 2008, Cenfri is an independent, not-for-profit development consultancy. We have physical offices in Cape Town and Kigali and have worked in more than 40 countries across Africa, the Middle East, Asia and Latin America. Find out more: https://cenfri.org/ In collaboration with our partn

Pando exists to bring entrepreneurs who love the mountains together, empowering positive change for our local and global communities. Pando is a 501(c) 3 organization that connects, supports and empowers entrepreneurs, thought leaders, and change makers. We create lasting connections and opportuniti
.png)
Does FAS sound like an organization that you would be energized to join? Is it aligned to your values? The Federation of American Scientists (FAS) takes...
One expert said those contracting IT services to the government can do nothing more than look to win more business.
AI safety is a rapidly evolving field that draws attention from a diverse range of policymakers across the political spectrum,...
Getting into a shutdown is the easy part, getting out is much harder. Both sides will be looking to pin responsibility on each other,...
Our Director of Government Affairs gives you the skinny on the latest from the Hill and White House – and what it means for S&T policy.
The federal government needs to strengthen energy systems through investments in energy infrastructure across energy generation,...
The current lack of public trust in AI risks inhibiting innovation and adoption of AI systems, meaning new methods will not be discovered...
America's Data Index aims to serve as a “weather forecast” on the state of government data.
Federal and state governments need to ensure that the development of new AI and data center infrastructure does not increase costs for...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Federation of American Scientists is http://www.fas.org.
According to Rankiteo, Federation of American Scientists’s AI-generated cybersecurity score is 751, reflecting their Fair security posture.
According to Rankiteo, Federation of American Scientists currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Federation of American Scientists is not certified under SOC 2 Type 1.
According to Rankiteo, Federation of American Scientists does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Federation of American Scientists is not listed as GDPR compliant.
According to Rankiteo, Federation of American Scientists does not currently maintain PCI DSS compliance.
According to Rankiteo, Federation of American Scientists is not compliant with HIPAA regulations.
According to Rankiteo,Federation of American Scientists is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Federation of American Scientists operates primarily in the Think Tanks industry.
Federation of American Scientists employs approximately 128 people worldwide.
Federation of American Scientists presently has no subsidiaries across any sectors.
Federation of American Scientists’s official LinkedIn profile has approximately 7,100 followers.
No, Federation of American Scientists does not have a profile on Crunchbase.
Yes, Federation of American Scientists maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/federation-of-american-scientists.
As of December 05, 2025, Rankiteo reports that Federation of American Scientists has not experienced any cybersecurity incidents.
Federation of American Scientists has an estimated 812 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, Federation of American Scientists has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string format is provided, it is passed directly to shell interpretation (sh -c) without input validation, allowing shell metacharacters to be interpreted. This vulnerability can be exploited through direct command injection or indirect prompt injection attacks, where AI agents may execute commands without explicit user intent. This vulnerability is fixed in 2.9.8.
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.