Comparison Overview
Mason & Hanger

Mason & Hanger
300 West Vine Street, Lexington, 40507, US
Last Update: 13/12/2025
Mason & Hanger, a Day & Zimmermann Company, is dedicated to providing architectural and engineering (A/E) services, specializing in worldwide design of secure, mission-driven facilities, proudly serving as a partner to the United States Government for nearly two centuri...

HDR
1917 S 67th St, Omaha, 68106, US
Last Update: 01/04/2026
HDR is an employee-owned design firm specializing in engineering, architecture, environmental and construction services. We’re ranked No. 6 among the world’s design firms and we’re the largest healthcare design firm. Led by the strength of our values and a culture shap...
Compliance Ranges Comparison

Mason & Hanger







HDR






Benchmark & Cyber Underwriting Signals
Incidents vs Design Services Industry Avg (This Year)
No incidents recorded for Mason & Hanger in 2026.
Incidents vs Design Services Industry Avg (This Year)
No incidents recorded for HDR in 2026.
Incident History - Mason & Hanger (X = Date, Y = Severity)
Mason & Hanger cyber incidents detection timeline including parent company and subsidiaries.
Incident History - HDR (X = Date, Y = Severity)
HDR cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Mason & Hanger

HDR
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.