Cyber Security

Blackstone-backed Patria creates Latam cybersecurity platform, eyes IPO

SAO PAULO, Oct 5 (Reuters) – Brazilian asset supervisor Patria Investments Ltd (PAX.O) has acquired cybersecurity corporations Neosecure and Proteus to create the biggest data safety platform in Latin America, it stated on Tuesday.

Patria, backed by Blackstone Group Inc (BX.N), additionally stated it plans to listing shares within the new enterprise within the close to future.

The agency didn’t disclose how a lot it has paid for the businesses, however stated that it’ll make investments $250 million within the sector.

It additionally goals to speed up its development within the data safety market through new acquisitions.

The corporate added that its new cybersecurity enterprise operates in Brazil, Chile, Argentina, Peru and Colombia, with an annual income estimated at 500 million reais ($91.66 million).

“Our objective is to speed up the market consolidation by way of the acquisition of strategic gamers, and shortly elevate extra capital through an preliminary public providing,” stated Marcelo Romcy, cofounder of Proteus and associate within the new platform.

Patria raised $588 million in its personal IPO on the Nasdaq earlier this yr.

($1 = 5.4548 reais)

Reporting by Gabriel Araujo, modifying by Louise Heavens

Our Requirements: The Thomson Reuters Trust Principles.

Source link

Cyber Security

OnionShare: Safe communications platform utilized by whistleblowers and journalists patches information publicity bug

Charlie Osborne

05 October 2021 at 12:35 UTC

Up to date: 05 October 2021 at 12:44 UTC

Open supply software program is used to guard a sender’s id

OnionShare: Secure communications platform used by whistleblowers patches data exposure bug

A software utilized by whisteblowers and the media to securely ship data has patched two vulnerabilities that might have impacted the nameless nature of the file-sharing system.

OnionShare is an open source software throughout Home windows, macOS, and Linux techniques designed to maintain customers nameless whereas finishing up actions together with file sharing, web site internet hosting, and messaging.

The service, made obtainable via the Tor community and developed by The Intercept director of infoSec Micah Lee, is utilized by most of the people in addition to journalists and whistleblowers to protect privateness.

Read more of the latest privacy news

On October 4, IHTeam revealed a security advisory on OnionShare. The workforce performed an unbiased evaluation of the software program and uncovered two bugs, tracked as CVE-2021-41868 and CVE-2021-41867, which exist in variations of the software program previous to v.2.4.

CVE-2021-41868 was present in OnionShare’s file add mechanism. By default, OnionShare generates random usernames and passwords in Primary Auth at startup in personal mode, IHTeam says, and so importing performance ought to solely be restricted to these with the correct credentials.

Nonetheless, whereas analyzing the operate, the workforce discovered that a logic issue brought on recordsdata to be
uploaded and saved remotely earlier than an authentication examine happened.

DON’T MISS Mission accomplished: Security plugin HTTPS Everywhere to be deprecated in 2022

The second vulnerability reported by the Italian safety workforce, CVE-2021-41867, might be exploited to reveal the members of a chat session. This downside, present in OnionShare’s parameter (), allowed websocket connections from unauthenticated customers, whether or not or not they owned a Flask session cookie.

“It appears that evidently with out a legitimate session ID it was not attainable to intercept messages between customers, for the reason that system closely [relies] on the session to attach into the default room – and with out a legitimate one, messages stay undelivered to unauthenticated customers,” the disclosing researcher Simone ‘d0td0tslash’ said.

“It’s nonetheless really useful to keep away from initiating a connection with out prior validating the session cookie.”

OnionShare builders have now tackled each points and released a new version of the software program, v.2.4, on September 17.

The Day by day Swig has reached out to Lee and we are going to replace as and after we hear again.

YOU MAY ALSO LIKE Critical encryption vulnerability found in secure communications platform Matrix

Source link