With its new Solution-as-a-Service (SaaS) offering, AESG will offer comprehensive commissioning, handover and asset management services, and integrated data solutions on a digital, cloud-based platform with enhanced data management capabilities.
Followingthe announcement of its ongoing global expansion, AESG, a specialist consultancy, engineering, and advisory firm, today strengthened its position as a leading provider of consultancy services for the built environment through the acquisition of Springboard Middle East. In addition to gaining ownership of Springboard Middle East’s regional contracts, staff, IP, and assets, the deal has enabled AESG to launch its new digital commissioning, handover and asset management platform, Data+.
As highlighted in the seminal ‘Building a Safer Future – Independent Review of Building Regulations and Fire Safety’ report[1], insufficient or inaccurate data can significantly impact the performance, efficiency, and safety of buildings. While over the last decade, the building industry has gradually moved away from traditional paper-based documentation to digital alternatives, issues around the accuracy, accessibility, and updatability of building data continue to linger due to the static nature of the pdfs, spreadsheets, and documents typically used in the process.
By offering one of the first comprehensive digital handover solutions in the Middle East, AESG hopes to introduce new practices for the industry, while strengthening the value proposition of its existing services. “Our acquisition of Springboard Middle East perfectly aligns with our strategy of pioneering new and more effective means of service delivery. Their revolutionary platform perfectly rounds out the digitalisation of our offerings and enhances both the immediate and long-term value of the projects we deliver. By adopting an integrated, digital approach across commissioning, handover and asset management, AESG is committed to leading the data revolution in the built environment,” said Saeed Al Abbar, CEO at AESG.
As a value add to its clients, the company will now offer full digital handovers on all commissioning and handover management projects, along with the option of hosting project data on Data+, its cloud-based platform – making it accessible from anywhere, easily searchable, and instantly updatable. When utilized as a subscription-based service, Data+ serves as a secure, collaborative environment that stands as a ‘single, central source of truth’ for all stakeholders and project teams.
Because Data+ has been built on industry standards and follows a COBie and BIM Level 2 compliant framework, it can be integrated with most Building Information Modelling (BIM) and Computer Aided Facility Management (CAFM) solutions. This allows for accurate and validated asset data to be seamlessly exported to these platforms, greatly enhancing building owners modelling, performance optimisation, and maintenance capabilities. The platform also features integration with IOT and AI systems to provide digital twins of assets that enables the use of advanced analytics to optimize the performance of systems during the operational phase of a building’s lifecycle.
While AESG believes clients of all sizes can benefit from its new offering, Al Abbar noted that Data+ will prove to be especially valuable to mega-projects. “We are working on a number of such high-value projects across the region and the size and scale of these undertakings warrants a more streamlined approach to data management. With all teams having instant access to the up-to-date information they need, they can have a clear picture of the real-time project metrics which will greatly enhance their efficiency and effectiveness. We are excited to work together with our clients in familiarising them with this new approach to handover and ongoing project management,” he concluded.
Why is 5G RAN slicing key to delivering on the promise of 5G? As a vital part of end-to-end network slicing technology, RAN slicing will help unlock the potential of a wide range of use cases for various industries, enterprise and enhanced mobile broadband segment. In our latest paper, we discuss what is Ericsson RAN slicing and how it can help realize the full potential of 5G.
From smartphones to smart factories, the promise of 5G is an open innovation platform that enables business and society to take the leap towards a smarter, safer and more sustainable future.
5G network slicing gives service providers the ability to serve a multitude of use cases with lightning-fast connectivity and enhanced performance. Service providers around the world are moving towards 5G network slicing, where slices of virtual networks are allocated to the meet connectivity demands of different use cases. Network slicing facilitates service differentiation and secures the necessary capacity and performance during high load to fulfill service-level agreements (SLA).
A case in point is online gaming. An Ericsson ConsumerLab survey of 7,000 consumers found that 90 percent of those who play video games at least weekly were negatively affected by lag when playing, with at least 1 in 3 sometimes quitting as a result.
Different game genres have different data rates, latency and reliability requirements on mobile networks. This is an area where service providers can offer customized slices for cloud gaming or any AR/VR application. The slicing framework can reserve dedicated resources by orchestrating these across the radio, transport and core networks.
Just like with this cloud gaming example , service providers can use network slicing as a way of differentiating their 5G offering. It helps tap the huge potential of a wide range of use cases for the enterprise and enhanced mobile broadband markets with guaranteed performance.
Ericsson RAN slicing solution enables service providers to offer differentiated handling of new services with respective quality of service and radio resource management for SLA fulfillment. What’s more, our solution is scalable and flexible enough to support a growing number of slicing use cases with faster time to market.
There are many ways of wearing a Hijab (headscarf). Be inspired by Kashkha’s latest range of Hijabs that is available online (www.kashkha.com and in-stores) in an array of colours and fabrics to help you coordinate your headwrap with your outfit.
According to the Kashkha Management, “Distinguished by high quality tailoring, stunning designs and fabulous fabrics, each Kashkha Hijab is adorned with a signature rhinestone logo in the corner. Embodying the spirit of beauty and gracefulness, there is something for everyone in our collections, ranging from classics to best sellers.”
The Kashkha stylists have put together five great looks that require minimal effort and are ideal for any occasion.
Classic: Those with long hair can tie their lengths into a no-fuss updo before draping the Hijab over the head. Wrap the Hijab around your face, keeping one side longer. Cross the longer end over the shorter end and secure at the top with a pin or magnet.
Voluminous: To achieve this chic look, wrap the Hijab around your face keeping one side longer and securing the shorter end under your chin. Roll the longer part over the head for a layered look and secure from the side with a pin or magnet.
Twisted Turban: To get the Twisted Turban look, place the hijab at the back of your neck with the ends in front. Cross the two ends over each other, then twist them one more time so the end you started with is in the same hand. Tug tightly and secure at the nape of your neck. You may even go for the pre-twisted Hijabs from Kashkha that are super easy to wear.
Over the Shoulder: For a glamorous vibe, fold the Hijab and wrap it over your head before letting the other longer end hang over the shoulder. Having the Hijab fall down the shoulder means you look stylish from all angles.
Tucked In: Embrace this sophisticated look which takes only a few minutes to do. Wrap the Hijab around your face, keeping one side slightly longer than the other before tucking at the nape.
Following that Wizz Air’s Q3 2021 financial results showed a year-on-year revenue fall of 76.5% but increased ancillary revenue;
Gus Gardner, Travel and Tourism Analyst at GlobalData, a leading data and analytics company, offers his view:
“Wizz Air has, once again, proven its ability to drive ancillary revenues: the lifeblood of the airline. The company has proved it is resilient and reactive in its recovery approach, managing to achieve increases in ancillary revenue per passenger despite traffic levels being at an all-time low.
“Pandemic-concerned passengers are more likely to purchase packages that include baggage and seat selection to ensure a safer journey. Further, flexibility is now expected, and Wizz Air has benefitted from providing ‘flexible tickets’ to mitigate ever-changing travel restrictions.
“People who are eager to travel during the pandemic are often doing so to visit friends and relatives – a clear shift away from the idea of travelling for a ‘short break’. These pandemic travelers are more likely to purchase extras because they tend to travel with additional baggage such as gifts and food to take home. This could be a key market for the airline in the coming months. Even though Wizz Air’s reported total ancillary revenues decreased by 72.9% year-on year, there was a bright spot in these uncertain times as ancillary revenue per passenger increased by 19.5%.
“The airline’s ambitious expansion plan remains very much in motion and could pay dividends. Since March 2020, the airline has opened a further 14 bases – in stark contrast to its competitors Ryanair and easyJet, who have both pulled out of some markets. This move could put the airline in a stronger position to rapidly expand post-COVID-19, and will help it become a more recognizable brand. The agile approach it has deployed is likely to benefit Wizz Air going forward.”
The French marine leisure industry, represented by Fédération des Industries Nautiques (FIN, the French federation for Marine Leisure Actors) has launched an immersive boat show which will be held on March 12th and 13th. More than a hundred brands have already joined the adventure and FIN now calls on international companies to participate.
The French federation wants to make Virtual Nautic the largest virtual boat show ever organized with at least 200 exhibitors and a target audience of 25,000 to 30,000 visitors.
Going beyond barriers: an opportunity to meet, conquer new clients and make business in a pandemic context.
“It is not a replacement for physical boat shows. Although as most of them have been cancelled, the goal of this virtual event is to create a moment of meeting for the marine leisure community in this pandemic context, allowing professionals to meet their clients, and giving them the opportunity to open up to new clients, new commercial dynamics, without the geographical nor the budgetary constraints of a physical boat show.” explains Fabien Metayer, General Delegate of FIN.
FIN also aims to create an opportunity for marine tourism stakeholders to prepare for the 2021 summer season.
An interactive, authentic and innovative experience
To do so, FIN has chosen to partner with Virbela and Laval Virtual which both collaborate to conceive and create immersive virtual event experiences that are deeply social and collaborative.
Virbela’s virtual world platform is easy-to-use, accessible to anyone with Wi-Fi and a computer, and available in several languages, including English, French, Spanish, Portuguese, Chinese, and many others.
“Virbela provides an all-in-one virtual venue with expo halls, auditoriums and social spaces to help organizations replicate the experience you get at an in-person event. We’re excited to partner with Laval Virtual World and Virtual Nautic to host a memorable and engaging event experience that will give attendees an opportunity to explore, learn, and connect with others,” said Alex Howland, president and co-founder of Virbela.
At Virtual Nautic, it will be possible for attendees to move from one booth to another with their avatars, use direct voice chats with exhibitors – connected from all over the world, use presentation tools (videos, brochures…), schedule appointments, look for a product, a service or a destination.
This new experience, based on the latest interactive technologies, will provide high visibility and business opportunities to the international marine leisure industry, while preserving the warmth of a physical show.
How Saudi Label Leem is Redefining what it means to dress as an Arab Woman
In its original form, the modest fashion industry was a grassroots movement borne out of a growing generation of young women wanting to celebrate their identity. Since then the sector has expanded beyond traditional elements such as the hijab to include loose-fitting and less revealing clothing. And while many brands world-wide are beginning to situp and take notice of the needs of Arab Women there is still far to go and an urge to encourage those brands not to dictate the modest “rules” of dressing.
Saudi label Leem celebrates the significant strides made by women in the region, celebrating them rather than their decision to dress modestly or not. What does this mean for Arab women? Leem is dramatically altering the landscape of contemporary design for the region, and indeed women worldwide, creating trend-led pieces that can be worn throughout the season and allow its wearer to take a more traditional approach, for example, an abaya or jalabiya, or a more modern take on modest dressing through the likes of free-flowing kaftans, maxi skirts and dresses, the timeless trench, tailored power suits with fluid, ambiguous layers, all distinguished by their sleek structure and elegant lines. However, it doesn’t stop there, why can’t that maxi dress, that modestly drapes the silhouette brushing the ankles and wrists, be pulled down to an off the shoulder piece when a woman feels comfortable? It can, and it should! We should celebrate, applaud and not dictate the boundaries of dressing, and rather design without preconceived notions of what modest fashion is or indeed should be.
As a brand Leem is not about defining the boundaries of modest fashion but rather supplying the modern Arab woman with a wardrobe that suits her, the occasion, and the ‘feeling’ of the day. Leem’s vision is to redefine modest wear with global appeal. Specialising in essential staples with an air of luxe that form the building blocks of any modest wardrobe, Leem’s stylish silhouettes carefully mark the intersection of conservative fit and modern flair, elevating the fashion quotient of its all-inclusive clientele-base, whether they choose to conceal for culture or as a personal preference of style.
Elevate your spring style with a symphony of hoop pairings
Get your spring wardrobe ready with the launch of the new La Marquise Hoopscollection, the perfect accessory this spring. With sunny days, sundresses and sun shades on the horizon, add some shine to your outfit with La Marquise delicate jewels.
For Spring 2021, La Marquise is showcasing their elegant spin on the trendy hoops with a symphony of hoops with playful placements that are reminiscent of the sunshine of the glorious spring season.
Elevate your classic pieces with a cool twist with the Hoop Collection that you can wear all day. Dress up or down your La Marquise with a pair of classic Hoops during the day or charm hoops paired with delicate studs made of ruby or emerald gemstones at night. Up your ear game with stand-out petite or medium-sized golden hoops with a miniature diamond. With layering in mind, the Hoops Collection is diverse with endless possibilities.
The collection allows you to mix varying diamond shapes to create a classy look. Switch up your style eye-catching round diamond hoops and dazzling studs with a single gemstone. The most captivating look is playing with various silhouettes by pairing gold and diamond hoops with vibrant emerald stud earrings.
Using its customised approach, jewellery brand La Marquise Hoops collection offers a unique selection of pieces to complement your spring wardrobe.
Shop the collection online at lamarquisejewellery.com and on the Personal Shopper WhatsApp at +971 52 453 4551.
Product Details
Price: AED 900 – AED 18,000
Metal: 18K Solid Gold – Rose Gold, Yellow Gold and White Gold
Stones: Diamonds, Precious stones – Emerald, Ruby and Sapphire
Customers can shop the full collection in store at Mall Of the Emirates, The Dubai Mall, City Centre Mirdif and other boutiques across the GCC. The collection is also available online at:www.lamarquisejewellery.com and on WhatsApp at +971 52 453 4551.
Cyber-crime is a complex landscape, but when it comes to actually launching cyber-attacks, there are three main techniques that criminals have relied on for decades to help them get around organizations’ defenses and into their networks: phishing, credentials theft and business email compromise. According to Verizon’s Data Breach Investigation Report, these ‘big three’ are the cause over two-thirds (67%) of all successful data breaches globally.
Check Point Research recently joined forces with Otorio to analyze and take a deep dive into a large scale phishing campaign that targeted thousands of global organizations, revealing the campaign’s overall infection chain, infrastructure and how the emails were distributed.
In August, attackers initiated a phishing campaign with emails that masqueraded as Xerox scan notifications, prompting users to open a malicious HTML attachment. While this infection chain may sound simple, it successfully bypassed Microsoft Office 365 Advanced Threat Protection (ATP) filtering and stole over a thousand corporate employees’ credentials.
Interestingly, due to a simple mistake in their attack chain, the attackers behind the phishing campaign exposed the credentials they had stolen to the public Internet, across dozens of drop-zone servers used by the attackers. With a simple Google search, anyone could have found the password to one of the compromised, stolen email addresses: a gift to every opportunistic attacker.
Figure 1: Personalized HTML Phishing file example
Infection Chain
The initial attack started with one of several phishing email templates. The attacker would send an email imitating a Xerox (or Xeros) scan notification with the target’s first name or company title in the subject line.
Figure 2: Phishing email example
Once the victim double-clicked the attached HTML file, the default system browser displayed a blurred image with a preconfigured email within the document (see figure 1 above).
Throughout the campaign several other phishing page variants were used, but the blurred background image remained the same.
After the HTML file was launched, a JavaScript code would then run in the background of the document. The code was responsible for simple password checks, sending the data to the attackers’ drop-zone server, and redirecting the user to a legitimate Office 365 login page.
Figure 3: C&C address for exfiltration
Figure 4: Password verification process and redirection
Throughout the campaign, the code was continuously polished and refined, with the attackers creating a more realistic experience so the victims were less likely to have their suspicions aroused, and more likely to provide their login credentials.
By using simple techniques, the attackers were also successful in evading detection by most Anti-Virus vendors, as can be seen from the following detection rates from the latest iteration of the campaign:
Figure 5: Low detection rates for the phishing pages on VirusTotal
Infrastructure
This campaign utilized both unique infrastructure, and compromised WordPress websites that were used as drop-zone servers by the attackers.
While using a specialized infrastructure, the server would run for roughly two months with dozens of XYZ domains. These registered domains were used in the Phishing attacks.
Figure 6: Passive total domains-per-day view for drop-zone server 45.88.3.233
Figure 7: Example drop-zone domains used for phishing attacks
We discovered dozens of compromised WordPress servers that hosted the malicious PHP page (named “go.php”, “post.php”, “gate.php”, “rent.php” or “rest.php”) and processed all incoming credentials from victims of the phishing attacks.
Attackers usually prefer to use compromised servers instead of their own infrastructure because of the existing websites’ well-known reputations. The more widely recognized a reputation is, the chances are higher that the email will not be blocked by security vendors.
Email Distribution
Analyzing the different email headers used in this campaign allowed us to draw several conclusions regarding the Tactics Techniques & Procedures (TTPs) used by the attackers:
The emails are sent from a Linux server hosted on Microsoft’s Azure
The emails are often sent by using PHP Mailer 6.1.5 (latest version from Mar 19 to May 27)
The emails are delivered using 1&1 email servers
Attackers used compromised email accounts to distribute spam through high-reputation phishing campaigns because the emails are harder to block. In one specific campaign, we found a phishing page impersonating IONOS by 1&1, a German web hosting company. It is highly likely that the compromised IONOS account credentials were used by the attackers to send the rest of the Office 365 themed spam.
Figure 8: Alternative Phishing page
Targeted Organizations
We found that once the users’ information was sent to the drop-zone servers, the data was saved in a publicly visible file that was indexable by Google. This allowed anyone access to the stolen email address credentials with a simple Google search.
Figure 9: Example credentials format stored on a publicly available URL
The public availability of this data allowed us to create a breakdown of the victims according to their industry (based on a subset of ~500 stolen credentials).
Figure 10: Distribution of targets by industry
Although there was a wide distribution of targeted industries, there appears to be a special interest in Energy and Construction companies.
Previous Campaigns
We found several correlations to previous phishing activity by comparing the campaign’s TTPs. Due to the similarities, these activities were likely executed by the same attacker or group of attackers.
Figure 11: Email from a previous campaign
We discovered a phishing email from May 2020 that perfectly matched the TTP’s described above. It also used the same JavaScript encoding that was used by this campaign in August.
Figure 12: First lines of the Phishing page compared
In this older scenario, the script redirected the user to another variant of an Office 365 phishing page that was not entirely encoded within the initial HTML file.
Figure 13: Phishing page from an older campaign via Urlscan
Google search engine algorithm naturally indexes the internet, and that is what makes it the most popular search engine ever invented. Thanks to its powerful algorithm, it also capable of indexing the hackers pages where they temporarily store the stolen credentials. We informed Google for them indexing the hackers’ failures and victims now can use Google search capabilities to look for their stolen credentials and change their passwords accordingly.
Conclusion
Our analysis of this campaign highlights the efforts that attackers will make to conceal their malicious intentions, bypass security filtering and trick users. To protect yourself against this type of attack, be suspicious of any email or communication from a familiar brand or organization that asks you to click on a link or open an attached document. Here are some practical tips to help keep your data safe:
Beware of lookalike domains, spelling errors in emails or websites, and unfamiliar email senders.
Be cautious with files received via email from unknown senders, especially if they prompt for a certain action you would not usually do.
Ensure you are ordering goods from an authentic source. One way to do this is to NOT click on promotional links in emails, and instead, Google your desired retailer and click the link from the Google results page.
Beware of “special” offers that don’t appear to be reliable or trustworthy purchase opportunities.
Make sure you do not reuse passwords between different applications and accounts.
Organizations should prevent zero-day attacks with an end-to-end cyber architecture, to block deceptive phishing sites and provide alerts on password reuse in real time. Check Point Infinity is effective because it combines two key ingredients: full convergence across all attack surfaces and all attack vectors, and advanced prevention that can tackle the most sophisticated zero-day phishing and account takeover attacks.
As the airline that flies to the most international destinations in the world, Turkish Airl ines also managed to become one of the busiest airlines during the pandemic period that has been plaguing the globe since last year. With its extra guidelines for safe travel and comprehensive hygiene precautions due to pandemic, the flag carrier airline has been awarded the highest “Diamond” status by APEX (Airline Passenger Experience Association) Health Safety powered by SimpliFlying.
Analyzed in three categories named Gold, Platinum and Diamond according to the hygiene precautions and preventative measures taken by airlines in the face of the ongoing pandemic, the online audit was conducted with 10 categories and 75 touchpoints in mind as the answers about the health and hygiene precautions were entered with concrete indicators by the participants. Reviewed alongside other airlines, Turkish Airlines achieved the Diamond status which symbolizes the highest health and safety level, thus maintaining its unparalleled service approach and quality in these extraordinary times.
Meticulously implementing comprehensive precautions and newly developed changes since the start of the pandemic in order to continue providing a healthy and safe travel experience for its passengers, Turkish Airlines achieved the Diamond status with numerous criteria such as touch-free check-in process, implementation of social distancing, temperature measuring at entrances, Covid-19 test service at the airport, extra hygiene precautions, in-flight social distancing, hygiene expert cabin crews appointed in flights and hygiene kits offered to passengers.
As the pandemic and its effects are still present around the globe, the precautions may differ from time to time due to rapidly changing conditions. But since the fight against the pandemic requires continuity and commitment, the precautions and measures taken by the airlines in the report will be reviewed every three months to check on the continuity of their statuses.
On the results, Turkish Airlines Chairman of the Board and the Executive Committee, M. İlker Aycı stated: “We continue to meticulously implement the comprehensive hygiene precautions in order to ensure that our passengers can travel in health and safety during the pandemic. We provided comfort and reassurance for our passengers with our Hygiene Expert cabin crews appointed in our flights and hygiene kits offered to all of our passengers, along with all the precautions taken in airports and in our aircrafts. We are glad that our guidelines for safe travel have achieved the highest “Diamond” status. We will continue to work selflessly to provide the best possible travel experience for our passengers.”
In his statement on the matter APEX CEO Dr. Joe Leader said: “Turkish Airlines consistently has provided incredible passengers experience now topped by Diamond level certified, hospital-grade health safety for its customers. From the outset of the COVID-19 pandemic forward, Turkish Airlines has demonstrated a step-by-step customer health safety plan as expansive as its 127 country route-map. APEX applauds the incredible commitment and diligence by Turkish Airlines for passenger safety worldwide.”