Comparison Overview
Rosatom

Rosatom
RU
Last Update: 14/09/2026
The State Atomic Energy Corporation "Rosatom" (short name Rosatom) runs all nuclear assets of the Russian Federation, both civil and weapons. Along with commercial activities which move forward nuclear power and nuclear fuel cycle facilities, it acts as a governmental a...

American Electric Power
1 Riverside Plaza, Columbus, 43215, US
Last Update: 10/09/2026
Our team at American Electric Power is committed to improving our customers' lives with reliable, affordable power. We are investing $72 billion from 2025 through 2029 to enhance service for customers and support the growing energy needs of our communities. Our more tha...
Compliance Ranges Comparison

Rosatom







American Electric Power






Benchmark & Cyber Underwriting Signals
Incidents vs Utilities Industry Avg (This Year)
No incidents recorded for Rosatom in 2026.
Incidents vs Utilities Industry Avg (This Year)
No incidents recorded for American Electric Power in 2026.
Incident History - Rosatom (X = Date, Y = Severity)
Rosatom cyber incidents detection timeline including parent company and subsidiaries.
Incident History - American Electric Power (X = Date, Y = Severity)
American Electric Power cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Rosatom

American Electric Power
FAQ
Latest Global CVEs
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).