Insurer AXA Halts Ransomware Crime Reimbursement in France

Insurer AXA Halts Ransomware Crime Reimbursement in France

In an apparent industry first, the global insurance company AXA said Thursday it will stop writing cyber-insurance policies in France that reimburse customers for extortion payments made to ransomware criminals. AXA, among Europe’s top five insurers, said it was suspending the option in response to concerns aired by French justice and cybersecurity officials during a…

How Patched Android Chip Flaw Could Have Enabled Spying

How Patched Android Chip Flaw Could Have Enabled Spying

Endpoint Security , Governance & Risk Management , Hardware / Chip-level Security Check Point Report Describes Flaw’s Technical Details Prajeet Nair (@prajeetspeaks) • May 7, 2021     (Photo: Shutterstock) A severe vulnerability in a system on certain Qualcomm chips, which has been patched, potentially could have enabled attackers to remotely control Android smartphones, access…

‘Panda Stealer’ Targets Cryptocurrency Wallets

‘Panda Stealer’ Targets Cryptocurrency Wallets

Cryptocurrency Fraud , Cybercrime , Fraud Management & Cybercrime Malware Spread Through Spam Email Campaign Prajeet Nair (@prajeetspeaks) • May 7, 2021     Researchers at Trend Micro have uncovered a new cryptocurrency stealer variant that uses a fileless approach in its global spam email distribution campaign to evade detection. See Also: Live Webinar |…

New TsuNAME DNS bug allows attackers to DDoS authoritative DNS servers

New TsuNAME DNS bug allows attackers to DDoS authoritative DNS servers

Attackers can use a newly disclosed domain name server (DNS) vulnerability publicly known as TsuNAME as an amplification vector in large-scale reflection-based distributed denial of service (DDoS) attacks targeting authoritative DNS servers. In simpler terms, authoritative DNS servers translate web domains to IP addresses and pass this info to recursive DNS servers that get queried…

Intel, AMD Dispute Findings on Chip Vulnerabilities

Intel, AMD Dispute Findings on Chip Vulnerabilities

Endpoint Security , Hardware / Chip-level Security After Researchers Release Report, Chipmakers Assert That No New Defenses Are Needed Doug Olenick (DougOlenick) • May 6, 2021     Intel and AMD are disputing the findings of researchers from two universities who say they’ve discovered new attacks on Intel and AMD processors that can bypass most…

Newly Patched Peloton API Flaws Exposed Users’ Private Data

Newly Patched Peloton API Flaws Exposed Users’ Private Data

Application Security , Endpoint Security , Incident & Breach Response Pen Test Partners: Millions Could Have Had Data Exposed Marianne Kolbasuk McGee (HealthInfoSec) • May 6, 2021     Photo: Peloton Security researchers say API flaws could have exposed the private data of millions of Peloton fitness equipment online service users for months before they…