Comparison Overview
NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy

NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy
One NSTAR Way, Westwood, 02090, US
Last Update: 17/02/2026
Welcome to Eversource. Please follow our new company page, Eversource Energy. Three years ago, Northeast Utilities and its operating companies Connecticut Light & Power, PSNH, Western Massachusetts Electric Company (WMECo), and Yankee Gas merged with NSTAR Electric & G...

Constellation
1310 Point Street, Baltimore, 21231, US
Last Update: 07/10/2026
Constellation Energy Corporation (Nasdaq: CEG), a Fortune 200 company headquartered in Baltimore, is the nation’s largest producer of reliable, emissions-free energy and a leading energy supplier to businesses, homes and public sector customers nationwide, including thr...
Compliance Ranges Comparison

NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy







Constellation






Benchmark & Cyber Underwriting Signals
Incidents vs Utilities Industry Avg (This Year)
No incidents recorded for NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy in 2026.
Incidents vs Utilities Industry Avg (This Year)
No incidents recorded for Constellation in 2026.
Incident History - NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy (X = Date, Y = Severity)
NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Constellation (X = Date, Y = Severity)
Constellation cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

NSTAR, now Eversource Energy- Follow our new company page, Eversource Energy

Constellation
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.