Comparison Overview
Moffatt & Nichol 

Moffatt & Nichol
4225 E Conant St, Long Beach, 90808, US
Last Update: 02/04/2026
Moffatt & Nichol is a leading U.S.-based global infrastructure advisor specializing in the planning and design of facilities that shape and serve our coastlines, harbors and rivers, as well as an innovator in the transportation complexities associated with the movement ...

GHD
133 Castlereagh St, Sydney, 2000, AU
Last Update: 04/04/2026
We are committed to addressing the world’s biggest challenges in the areas of water, energy and communities. GHD is a global network of multi-disciplinary professionals providing clients with integrated solutions through engineering, environmental, design and construct...
Compliance Ranges Comparison

Moffatt & Nichol







GHD






Benchmark & Cyber Underwriting Signals
Incidents vs Civil Engineering Industry Avg (This Year)
No incidents recorded for Moffatt & Nichol in 2026.
Incidents vs Civil Engineering Industry Avg (This Year)
No incidents recorded for GHD in 2026.
Incident History - Moffatt & Nichol (X = Date, Y = Severity)
Moffatt & Nichol cyber incidents detection timeline including parent company and subsidiaries.
Incident History - GHD (X = Date, Y = Severity)
GHD cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Moffatt & Nichol

GHD
FAQ
Latest Global CVEs
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).