Comparison Overview
Allianz Global Assistance Canada

Allianz Global Assistance Canada
700 Jamieson Pkwy, Cambridge, N3C 4N6, CA
Last Update: 13/03/2026
For 30 years, Allianz Global Assistance has supported travelling Canadians when they need it most with value-added travel insurance and assistance services. More than 600 employees support long-term partnerships with some of the best known brands in the travel and fina...

AXA
25, avenue Matignon, Paris, 75008, FR
Last Update: 18/07/2026
As one of the largest global insurers, our purpose is to act for human progress by protecting what matters. Protection has always been at the core of our business, helping individuals, businesses and societies to thrive. And AXA has always been a leader, an innovator, ...
Compliance Ranges Comparison

Allianz Global Assistance Canada







AXA






Benchmark & Cyber Underwriting Signals
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for Allianz Global Assistance Canada in 2026.
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for AXA in 2026.
Incident History - Allianz Global Assistance Canada (X = Date, Y = Severity)
Allianz Global Assistance Canada cyber incidents detection timeline including parent company and subsidiaries.
Incident History - AXA (X = Date, Y = Severity)
AXA cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Allianz Global Assistance Canada

AXA
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).