Comparison Overview
U.S. Department of Health and Human Services (HHS)

U.S. Department of Health and Human Services (HHS)
200 Independence Avenue S.W., Washington, District of Columbia, US, 20201
Last Update: 05/10/2026
The Department of Health and Human Services (HHS) is the United States government's principal agency for protecting the health of all Americans and providing essential human services, especially for those who are least able to help themselves.

Københavns Kommune
Rådhuset, København V, 1599, DK
Last Update: 14/09/2026
Københavns Kommune er Danmarks største arbejdsplads med ca. 45.000 medarbejdere. Vi udvikler hovedstaden og servicerer over 500.000 københavnere. Vores mål er at fastholde og udvikle København som en af verdens bedste byer at bo i – og skabe øget vækst gennem viden, inn...
Compliance Ranges Comparison

U.S. Department of Health and Human Services (HHS)







Københavns Kommune






Benchmark & Cyber Underwriting Signals
Incidents vs Government Administration Industry Avg (This Year)
U.S. Department of Health and Human Services (HHS) has 104.08% more incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Government Administration Industry Avg (This Year)
No incidents recorded for Københavns Kommune in 2026.
Incident History - U.S. Department of Health and Human Services (HHS) (X = Date, Y = Severity)
U.S. Department of Health and Human Services (HHS) cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Københavns Kommune (X = Date, Y = Severity)
Københavns Kommune cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

U.S. Department of Health and Human Services (HHS)

Københavns Kommune
FAQ
Latest Global CVEs
Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.
Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS session before permitting application traffic. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing the clients to accept an attacker-terminated connection as the attested enclave. This issue is fixed in 0.5.0.
Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27.
- https://github.com/Privasys/enclave-os-virtual/commit/9a6be91e29f2b6738d0b77c33cd1ad5cd3d8a347
- https://github.com/Privasys/enclave-os-virtual/releases/tag/tdx-gpu-v0.6.27
- https://github.com/Privasys/enclave-os-virtual/releases/tag/tdx-v0.2.43
- https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9
- https://privasys.org/blog/binding-attestation-to-the-tls-session
Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5.
Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS` file executes arbitrary code with the privileges of the Aegisub process. From 3.4.0 to 3.4.2, inconsistent handling of embedded `NUL` characters between extension validation and filesystem operations additionally allows a crafted `ASS/Lua` polyglot to reference and execute itself as a single-file variant. The vulnerability is fixed in Aegisub 3.5.0.
- https://github.com/TypesettingTools/Aegisub/commit/0a3073d59f10432eeebea65018b02ef4d0a87fff
- https://github.com/TypesettingTools/Aegisub/commit/b5bf23979e7453f7b1cc8ffeb82b3cc2d2ca75e6
- https://github.com/TypesettingTools/Aegisub/commit/e4099055711cce327840870c050ce46e58f4aee0
- https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23