12, Jul 2023
Patch Tuesday – M. Walters, VP of Vulnerability and Threat Research at Action1, comments
This Patch Tuesday, Microsoft has released a significant number of updates, addressing a total of 142 vulnerabilities. This includes 132 new fixes and updates for 10 previously addressed issues, resulting in a record-breaking number of fixes for the year. Among these, there are nine critical vulnerabilities that have been resolved, along with an update for an older critical vulnerability. This month’s updates also cover six zero-day vulnerabilities, with one of them publicly disclosed, and an update for a previously patched zero-day. Additionally, one older vulnerability now has a Proof of Concept (PoC) available.
Now, let’s dive into the details of the most noteworthy critical updates.
Office and Windows HTML Remote Code Execution Vulnerability
Office and Windows HTML Remote Code Execution Vulnerability (CVE-2023-36884) is an important zero-day vulnerability that impacts Office and Windows HTML. It possesses a network attack vector with high complexity, requiring user interaction but not elevated privileges. With a CVSS rating of 8.3, it is categorized as important, although it could potentially warrant an even higher severity if executed with user interaction and complexity. The vulnerability affects all versions of Windows Server from 2008 onwards, Windows 10, as well as Microsoft Word and Microsoft Office versions 2013 and later.
Exploiting this vulnerability entails an attacker creating a specially crafted Microsoft Office document capable of executing remote code in the victim’s context. However, it is important to note that convincing the victim to open the malicious file is a prerequisite for a successful attack.
Microsoft has outlined certain mitigation steps to address this issue. Within existing attack chains, implementing the “Block all Office applications from creating child processes” attack surface reduction rule can thwart the exploitation of this vulnerability. For organizations unable to leverage this protection, an alternative approach involves configuring the FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION registry key to prevent exploitation. It is worth noting that while these registry settings can mitigate the vulnerability’s exploitation, they may impact normal functionality in certain use cases associated with these applications. To implement this approach, add the application names listed as values of type REG_DWORD with data 1 to the registry key.
Given Microsoft’s confirmation of active exploitation and the absence of available workarounds, it is crucial to prioritize updating systems to address this vulnerability promptly.
Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability (CVE-2023-35311) is another important zero-day vulnerability impacting Microsoft Outlook. It utilizes a network attack vector with low attack complexity, requiring user interaction but not elevated privileges. With a CVSS rating of 8.8, it is considered a significant vulnerability, although its severity could have been higher if user interaction was not required. It’s important to note that this vulnerability specifically allows bypassing Microsoft Outlook security features and does not enable remote code execution or privilege escalation. Therefore, attackers are likely to combine it with other exploits for a comprehensive attack. The vulnerability affects all versions of Microsoft Outlook from 2013 onwards.
To compromise a user, the attacker would need the user to click on a specially crafted URL. Notably, the attacker can bypass the Microsoft Outlook security prompt even in preview mode.
Given that this vulnerability is already being exploited and can be used in conjunction with other exploits, it is strongly recommended to apply the available update promptly.
Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability (CVE-2023-36874) is an important zero-day vulnerability that impacts the Windows Error Reporting Service. It can be exploited locally with low complexity and without requiring elevated privileges or user interaction. The vulnerability has a CVSS rating of 7.8, indicating its severity. However, it should be noted that this rating would be even higher if the vulnerability allowed remote attacks without requiring elevated privileges.
To exploit this vulnerability, an attacker needs to gain access to the system using other exploits or harvested credentials. The compromised user account must have the ability to create folders and performance traces on the computer, which is typically available to normal users by default. This vulnerability affects all versions of Microsoft Windows Server from 2008 onwards, as well as Windows 10 and later versions.
Successful exploitation of this vulnerability could grant the attacker administrative privileges, enabling them to escalate their privileges and perform various malicious actions.
Due to the ongoing exploitation of this vulnerability and its potential combination with other exploits, it is highly recommended to apply the available update as soon as possible.
Windows MSHTML Platform Elevation of Privilege Vulnerability
Windows MSHTML Platform Elevation of Privilege Vulnerability (CVE-2023-32046) is a critical zero-day security concern affecting the MSHTML platform in Windows. This vulnerability possesses a local attack vector with a low complexity of attack and does not require elevated privileges. However, user interaction is necessary for exploitation. It has received a CVSS rating of 7.8, indicating its severity. Note that the rating would have been higher if the vulnerability allowed remote attacks without requiring user interaction.
To exploit this vulnerability, a user must open a specifically crafted file. In an email attack scenario, an attacker may send the manipulated file to the user and deceive them into opening it. Similarly, in a web-based attack scenario, the attacker may host a website containing the specially crafted file intended to exploit the vulnerability.
It is crucial to understand that the attacker cannot compel users to visit the malicious website. Instead, they must convince users to click on a link, typically through enticing email messages or instant messages, and then persuade them to open the specifically crafted file.
It is important to note that the attacker would only acquire the rights of the user running the affected application. Therefore, if a user does not possess administrative rights on the computer, neither does the attacker.
Considering that this vulnerability is actively being exploited and has the potential to be combined with other exploits, it is strongly advised to promptly apply the available update.
Source: https://www.action1.com/patch-tuesday-july-2023/?vyj
- 0
- By Neel Achary
12, Jul 2023
Fitch Ratings revised up OQ’s Standalone Credit Profile (SCP) to “bbb-” while reaffirms its Long-Term Issuer Default Rating (IDR) at ‘BB’ with Positive Outlook
Muscat, 12 July 2023:
Fitch Ratings, the international credit rating agency, has upgraded OQ’s standalone credit profile (SCP) from “b+” to “bbb-” and reaffirmed the Long-Term Issuer Default Rating (IDR) at ‘BB’, with positive outlook, this represents a significant improvement as OQ is now rated as investment grade. It attributed the new rating to OQ’s ability to meet its long-term financial obligations.

Fitch highlighted the exceptional achievements of the OQ Group, including reducing its debt as part of the Balance Sheet Optimisation programme, which demonstrated a committed approach to financial discipline. The credit rating agency shed light on the improved EBITDA net leverage ratios, establishment of financial policy and increased hydrocarbon production among the significant achievements that contributed to the improved SCP.
OQ’s rating is further bolstered by its diverse operations across exploration, production, refining, marketing, petrochemical segments, with focus on energy transition going forward, as well as the key role of the company as a national champion for clean energy.
The positive recognition reflects the unwavering commitment to excellence and positions OQ as a strong player in the industry. The agency also emphasised OQ’s proactive management of its balance sheet, leveraging strong cash flow generation and proceeds from asset sales to prepay debt. This positive shift in financial performance is largely attributed to the successful execution of the Group’s projects and robust financial performance due to higher oil and gas prices.
12, Jul 2023
Powers Insurance & Risk Management Hires Giovanni Favazza
Favazza named Commercial Lines Risk Management Advisor at one of St. Louis’ largest family-owned insurance agencies.

(St. Louis, Mo., July 12, 2023) Powers Insurance & Risk Management, one of the largest family owned and operated independent insurance agencies in the bi-state region, recently hired Giovanni “Johnny” Favazza as Commercial Lines Risk Management Advisor. His responsibilities include generating new leads, as well as handling existing commercial accounts, in the property and casualty marketplace. Favazza will focus on enhancing business development by creating the most fitting insurance and risk management service solutions for each client.
Favazza grew up in his family’s business, Favazza’s Restaurant on the Hill. Prior to joining Powers, he worked as a Senior Account Executive at one of the largest insurance brokerages in Texas. He previously served as an Associate for a California-based investment advisory firm. Favazza earned his Bachelor of Business Administration degree in Managerial Finance from the University of Mississippi located in Oxford, Miss.
“Gio brings the strong analytical skills and detail-oriented credentials it takes to work in our fast-paced insurance environment,” said Powers Insurance & Risk Management’s president JD Powers. “He has already achieved extensive industry success, and we are excited to have him on our team so he can generate long-lasting benefits for our clients.”
Founded in 1991, Powers Insurance & Risk Management provides personal and business insurance, surety, risk management, and employee benefits. Founded in 2006, sister company Valley Insurance Agency Alliance is a cohesive family of over 160 independent insurance agencies in Missouri and Illinois that generates more than $600 million in written premium. VIAA is the regional founding member for SIAA – The Agent Alliance, a $12.5 billion national alliance. The companies are headquartered at 6825 Clayton Ave. For more information, call (314) 725-1414 or visit www.powersinsurance.com.
12, Jul 2023
Oxeye AppSec Platform Automatically Discovers Owncast & EaseProbe Security Vulnerabilities
Company Provides Recommended Remediation for Server-Side
Request Forgery (SSRF) and SQL-Server Injection Vulnerabilities
TEL AVIV – July 12, 2023 – Oxeye, the provider of an award-winning cloud-native application security platform, has uncovered two critical security vulnerabilities and is recommending immediate action be taken to mitigate risk. The vulnerabilities were discovered by the Oxeye AppSec Platform in Owncast (CVE-2023-3188) and EaseProbe (CVE-2023-33967), two open-source platforms written in Go.
The Oxeye AppSec Platform combines the functions of SAST, DAST and SCA into one tool to filter out vulnerabilities that cannot be exploited in modern distributed applications. Oxeye identifies all vulnerabilities, including those that cross microservices, then help AppSec & dev teams focus on critical vulnerabilities by finding and determining which vulnerable open source and third-party packages are loaded and used and filtering out those that are not; filtering vulnerabilities that cannot be accessed from the Internet (directly or indirectly); Refining further by adding infrastructure configuration data, and performing active validation by fuzzing the exploitable APIs.
Owncast Vulnerability
The first vulnerability was discovered in Owncast, an open-source, self-hosted, decentralized, single-user live video streaming and chat server written in Go. The vulnerability, labeled as an Unauthenticated Blind Server-Side Request Forgery (SSRF), could potentially allow unauthenticated attackers to exploit the Owncast server by forcing the Owncast server to send HTTP requests to arbitrary locations using the GET HTTP method. This vulnerability also allows the attacker to send the requests while specifying arbitrary URL paths and query parameters. The Owncast vulnerability has a high CNA CVSS severity rating of 8.3/10 and was identified during an extensive analysis conducted by Oxeye Security’s in-house custom SAST (Static Application Security Testing) solution for compiled Golang applications.
Upon examination, the security researchers at Oxeye Security determined that the Owncast server is susceptible to an unauthenticated SSRF attack, enabling malicious actors to force the server to send HTTP requests to arbitrary locations using the GET HTTP method. Additionally, attackers can manipulate the requests by specifying arbitrary URL paths and query parameters.
The vulnerable code resides within the GetWebfingerLinks function of Owncast, specifically in the following location: https://github.com/owncast/owncast/commit/f40135dbf28093864482f9662c23e478ea192b16 . As per the code analysis, user-controlled input passed through the “account” parameter is parsed as a URL, and subsequently, an HTTP request is issued to the specified host on line 32.
To address this critical SSRF vulnerability, Oxeye Security recommends the following remediation steps:
– Prohibit the HTTP client utilized by Owncast from following HTTP redirections to mitigate the potential exploitation of SSRF attacks.
– Implement restrictions to allow only authenticated users to trigger the vulnerable endpoint, thereby minimizing the risk of unauthorized access.
Oxeye Security has been proactive in reaching out to the Owncast development team and providing them with detailed information regarding the vulnerability and recommended remediation steps. Together with Owncast, Oxeye Security aims to ensure the prompt resolution of this security issue to safeguard the Owncast community and its users.
EaseProbe Vulnerability
Oxeye has also recently discovered multiple SQL-injection vulnerabilities in EaseProbe, a lightweight and standalone health/status checking tool written in Go. The vulnerabilities, categorized as Config-Based SQL-Injection, expose potential security risks for users of EaseProbe with a Critical NIST CVSS Security Score of 9.8/10. The vulnerable code is located in the MySQL / Postgres database client code:
· https://github.com/megaease/easeprobe/blob/main/probe/client/mysql/mysql.go#L174
· https://github.com/megaease/easeprobe/blob/main/probe/client/postgres/postgres.go#L203
During an extensive evaluation utilizing Oxeye Security’s in-house custom SAST (Static Application Security Testing) solution for compiled Golang applications, the security researchers identified significant vulnerabilities in EaseProbe. These vulnerabilities can be exploited by attackers who have control over the EaseProbe configuration, enabling them to read, delete, or modify all information stored in the databases configured for health checking. In certain circumstances, depending on the user privileges and the database engine, the attacker may also execute arbitrary system commands on the server hosting the database. The vulnerable code is located within the MySQL and Postgres database client code of EaseProbe.
By analyzing the EaseProbe configuration file, Oxeye Security demonstrated a practical exploitation scenario on a Postgres database. The attacker injects a malicious command “ls” to execute arbitrary system commands. The vulnerable database query is unsafely formatted with user-provided data, leading to the successful execution of the injected command.
To mitigate the risks associated with SQL-injection attacks, Oxeye Security recommends the following remediation measures:
– Properly sanitize all user input to prevent SQL-injection vulnerabilities. This can be achieved by implementing techniques such as prepared statements and parameterized queries, which treat user-provided input as values instead of executable code. If injection occurs in a query part that cannot be parameterized, strictly validate user input, considering the use of regular expressions or other appropriate methods.
– Ensure the application is regularly updated and patched to address any known vulnerabilities, as this can effectively mitigate the risk of exploitation.
Oxeye Security has taken immediate action by notifying the developers of EaseProbe about the discovered vulnerabilities. By collaborating with the EaseProbe team, Oxeye Security aims to expedite the resolution of these security issues to protect EaseProbe users from potential threats. Note: This problem has been fixed in EaseProbe v2.1.0.
If interested in learning more about how Oxeye can assist with cloud-native application security challenges, please visit https://www.oxeye.io/contact to contact us.
12, Jul 2023
LUMOS ULTRA FLY & FLY PRO: Now Available For Reservation On Prelaunch.Com
July 12, 2023 – Lumos, an award-winning smart helmet company, is excited to announce the launch of the reservation campaign for Lumos Ultra Fly & Fly Pro, revolutionary helmets with attachable lights that prioritize your visibility, protection, and comfort on Prelaunch.com: an innovative and first-ever market validation platform that uses eCommerce logic to measure potential customers’ real buying intents.

After meticulous development and refinement, Lumos introduces the Ultra Fly and Fly Pro helmets. Designed for the pragmatic commuter and the performance-focused road cyclist respectively, these helmets offer an innovative approach to visibility and safety.
Lumos Ultra Fly & Ultra Fly Pro offer an ingenious solution to low-light visibility and safety concerns without compromising on weight or comfort. Compatible with the Lumos Firefly lights, these helmets bring illumination to the forefront of safety, wrapped in a sleek and lightweight design.
Modular Design with Attachable Firefly Lights
Lumos Ultra Fly & Ultra Fly Pro helmets feature Firefly lights that are easily attachable, ensuring maximum visibility and safety on the road. The magnetic connection allows for one-handed, quick attachment or detachment, perfect for sudden lighting changes during rides.
Compatibility with Lumos Smart Safety System (LS3)
Lumos Ultra Fly & Ultra Fly Pro’s ability to attach a Lumos Firefly is compatible with the extended Lumos Smart Safety System (LS3). The LS3 allows riders to synchronize flashing patterns, turn signals, and brake lights between all Lumos Firefly lights, enhancing overall visibility and predictability.
Safety & Security
Lumos helmets have an integrated MIPS technology (Multi-directional Impact Protection System), a low-friction layer located between the EPS and inner helmet liner that reduces rotational impact forces. This allows you to ride with confidence and safeguard your head. The low-friction layer reduces rotational impact forces, protecting from serious injuries and brain damage in case of a crash.
Super-Lightweight
The Lumos Ultra Fly & Ultra Fly Pro are among the lightest helmets in their category. Weighing in at just 245g (8.6 oz) for the Ultra Fly and slightly more for the Ultra Fly Pro, these helmets ensure comfort and durability for extended wear.
Class-Leading Ventilation
With strategic vent placement – 11 vents in the Ultra Fly and 14 in the Ultra Fly Pro – these helmets optimize airflow and reduce drag, keeping you cool and comfortable on every ride.
Secure Your Eyewear with OptiGrip
Integrated into both Ultra Fly and Ultra Fly Pro helmets, Lumos’s innovative OptiGrip system offers a practical solution for cyclists to safely secure their sunglasses. With strategically placed vents designed to accommodate a range of eyewear styles, OptiGrip uses specially engineered friction materials to provide a firm grip. Now, riders can enjoy their cycling adventures without the worry of losing or damaging their eyewear.
Style & Convenience
Lumos helmets are designed with user comfort and style in mind. Featuring the FlexiFit System, they ensure an optimal fit for all head shapes, sizes, and hairstyles. The helmets are available in a range of colors to suit individual preferences.
The Lumos Ultra Fly is available in five color options: Stealth Black, Phantom White, Maverick Grey, Hyper Green, and Atomic Salmon.
The Lumos Ultra Fly Pro offers even more choices with six dynamic colorways: Shadow Black, Spectre White, Razor Grey, White Lime, Thunder Blue, and Daredevil Red. These color options allow cyclists to make a bold statement while ensuring their visibility on the road.
Lumos Ultra Fly
The ultimate commuter’s ally. This multi-purpose lightweight helmet is impressively budget-friendly without skimping on safety. Compatibility with a Lumos Firefly light ensures you stand out in low light conditions. A hassle-free adjustable fit system makes it a go-to choice for everyday riders who value safety and affordability.
Lumos Ultra Fly Pro
A game-changer for the committed road cyclist. This high-ventilation with MIPS-integrated helmet is engineered with more advanced ventilation with more and larger vents. It is fitted with a magnetic Fidlock buckle for one-handed operation, offering a seamless blend of safety, comfort, and style. Adding on the magnetic Lumos Firefly light amplifies visibility, while the advanced design elevates your ride, pushing performance to new heights.
Available on Prelaunch.com
The all-new Lumos helmets are currently in their pre-launch phase on the first-of-its-kind market validation platform Prelaunch.com. Customers are invited to place a $3 reservation deposit now to get a 35% discount when launched:
- Lumos Ultra Fly for $120 instead of $175
- Lumos Ultra Fly Pro for $140 instead of $215
The launch of Lumos on Prelaunch.com has declared a unique partnership between the two Companies. Prelaunch.com – a leading platform for market validation, has already registered 1000+ creators that use its proprietary technology to validate their ideas. Its extensive set of tools includes all the essential features a company requires to determine the potential success of a product.
The platform will thoroughly analyze and illustrate the data received whenever a user visits the page. Prelaunch.com’s current technology is powerful enough to register 35+ data points for every single visit. The data collected will help establish a deeper connection with the customers and advance the product to better serve their needs.
Contact details
Contact Name: Derek McLean
Contact Email: derek@lumos.prelaunch.com
12, Jul 2023
Pakka Limited Makes its Debut on the National Stock Exchange
Pakka Limited Makes its Debut on the National Stock Exchange with a New Identity, Marking a New Era for Regenerative Packaging Solutions
The company is undergoing rapid expansion as it took the wraps off its facility development plans in Guatemala and has also kick-started capacity expansion for its plant in Ayodhya, UP.

India, 12th July 2023: Yash Pakka Limited, a leading provider of regenerative packaging solutions for food products, has been listed on the National Stock Exchange (NSE) with a new identity of Pakka Limited (pronounced as Packa or पैका). The 42-year-old company envisions simplifying its brand identity and unifying its presence across all regions globally with this renaming. The change reflects the company’s commitment to its mission of transforming food packaging by providing regenerative solutions that contribute to a cleaner planet.
Present at the NSE listing were Mr. Pradeep V. Dhobale (Chairman), Ved Krishna (Vice Chairman), Mr. Jagdeep Hira (Managing Director), Mr. Himanshu Kapoor (Director) and Ms. Neetika Suryawanshi (Chief Financial Officer), along with marquee customers, investors, well-wishers, and team members. The company is targeting revenues of $1 billion (Rs. 8,250 crores) by FY30. The key drivers are to service new geographies with compostable packaging solutions, such as flexible packaging and moulded tableware with better Net Service Revenues (NSR) and with new strategic tie-ups for capacity enhancement driving this growth.
Mr. Ved Krishna, Vice Chairman, Pakka Ltd., said, “Today, we honour the legacy of fierce determination, innovation, and creative problem-solving by a name change— from now, we will be called Pakka. Pakka is a combination of “packaging” and “ka”— which means soul. Packaging with a soul means you get our best effort. While we have distributed globally for 20 years, for the first time we are setting up international production facilities. With this in mind, we need a name that is simple, universal, and relevant. And, of course, the double-K is a subtle nod to my father, KK Jhunjhunwala. As he often modeled: we are led by our convictions. We are grateful to so many of you who have been with us on this ride of building good business by doing good. We will continue to contribute to a cleaner planet. We look forward to creating a deeper impact together.”
Mr. Jagdeep Hira, Managing Director, Pakka, said, “Pakka lists on NSE with a new identity and mission to scale regenerative food packaging. Pakka has developed a compelling go-to-market strategy encompassing value-added products, new geographies; new strategic tie-ups for enhancing manufacturing capacity. We intend to sustainably scale up our business with a new offering of compostable flexible packaging and our existing successful offering of compostable tableware products under the brand name CHUK. Pakka is looking for outsourcing of moulded products to double our capacity and has found partners across India. We shall grow the Ayodhya unit to increase pulp production capacity by 30% and provide more value-added products for flexible packaging. Pakka is also working on global research tie-ups for compostable flexible packaging on several biomaterials.”
Pakka’s upcoming facility in Guatemala is expected to be operational by mid-2025 with a production capacity of 400 tonnes per day. The company plans to invest US$250 million to set up the world’s largest compostable flexible packaging and moulded fibre facility, based on bagasse fiber. Pakka has signed MOUs with Guatemala’s major sugar companies to procure sugarcane, which is the primary raw material used for the company’s products. Pakka is also expanding its capacity in India at its Ayodhya facility under the name Project Jagriti with an investment of ₹550 crores.
Pakka provides regenerative packaging at scale for Quick Service Restaurants (QSRs), food carry and food services across the world. The company has been developing compostable packaging solutions as alternatives for single use plastic. CHUK is aiming to become the preferred sustainability partner when it comes to food service packaging for large institutions. Large food service operators like Haldiram’s, Zomato’s Hyperpure, Wow Momos, Chai Point, A2B and Devyani International, are prominent brands that use CHUK products.
Pakka Ltd. posted the highest annual revenue of Rs. 419.9 crore in FY23 with the highest FY profit of Rs. 72.3 crore (EBIDTA of 23%) in FY23. It posted the highest exports of 27% of the total volume production as moulded tableware production was up by 24% — almost 50% of its installed capacity as of now.

12, Jul 2023
New Study Reveals Gender Inequity Continues to Persist for Employees Around the World
Coqual’s “Challenging Norms: A Global Analysis of Gender at Work” Finds Stark Differences Between Men and Women & Highlights the Unique Challenges of Transgender and Gender Diverse Professionals
NEW YORK, July 12, 2023 — Are corporations prepared for a gender revolution? Today, Coqual, a leading global think tank, released its new report, “Challenging Norms: A Global Analysis of Gender at Work,” that examines gender equity at work in eight markets: Australia, Brazil, Germany, India, Japan, South Africa, the United Kingdom, and the United States. The report finds that while there has been notable progress, achieving gender equity is still a challenge globally. Through an intersectional lens, the new research considers how race, class, caste, sexuality, and other identity characteristics complicate how gender is seen, experienced, and understood in employees’ daily lives.
The study employed Coqual’s rigorous mixed methodology with survey results from 5,481 full-time employed professionals who were at least 21 years old, as well as focus groups, Insights In-Depth® sessions and expert interviews. The new report delves into three primary areas: gender and career advancement (promotions, professional networks, etc.); gender and social environment (microaggressions, stereotypes, etc.); and gender and caregiving (childcare, eldercare, etc.) and addresses the challenges that women face regarding pay, career mobility, prejudice in the workplace, and outdated cultural gender norms.
The report also highlights the unique experiences of transgender and gender diverse (TGD) professionals and unveils a major generational shift in how respondents understand gender identity and expression. To conclude, Coqual provides data-driven solutions and a new framework for organizational change that leaders can use to develop and execute their DE&I goals.
“All around the world, professionals from historically marginalized gender identity groups are still required to navigate exclusionary, inequitable, and hostile workplace environments that make it difficult to achieve their full potential,” said Lanaya Irvin, CEO of Coqual. “Organizations must look beyond the binary and create more equitable workplaces through gender-inclusive policies, programs, and people management strategies. We hope this report helps leaders and allies create a braver, more gender-inclusive corporate landscape.”
“We are proud to sponsor this important study that provides insights, data and a new framework for companies to prepare for the future of the global workplace,” said Shane Lloyd, Head of Diversity, Inclusion, Belonging and Societal Impact, Baker Tilly. “Women, transgender, and gender diverse professionals all face different challenges, and Coqual’s new report provides actionable ways for companies to navigate the complexities of gender around the world.”
Data By Country:
United States
Women in the U.S. still face barriers to career advancement, as Coqual finds two-thirds of men (67%) say they have been promoted or considered for a promotion at their company in the last four years compared to only about half of women (53%). The study also highlights the importance of considering the intersection of race and gender, finding that 42% of Black women say they have often considered leaving their job in the past year. Additionally, the majority of transgender and gender diverse professionals (60%) say that gender non-conforming employees experience negative stereotypes and social interactions in the workplace, but only 39% of cisgender professionals agree. According to the report, nearly half of transgender and gender diverse professionals in the U.S. are often told that their gender non-conformity is just a phase (47%), more than half are misgendered (54%), and two in five (41%) are told that they make their colleagues uncomfortable because of their gender identity.
United Kingdom
Coqual finds that women in the UK perform significantly more childcare (65% vs. 54%) and housework (67% vs. 57%) on average than men. With so much time and energy expended on domestic labor, only 19% of women professionals say having children has helped their career compared to 46% of men who say the same. Coqual’s report finds that barely one in five women professionals (21%) say they are very satisfied with their work-life balance compared to 40% of men. Nearly half of UK women surveyed (48%) say they have experienced gender-based prejudice in the workplace compared to 37% of men.
Australia
Coqual reports the documented “motherhood penalty” and “fatherhood bonus” impacts Australian employees, finding that over half of women (54%) say that having children has hurt their career compared to 39% of men. Additionally, only a quarter (25%) of women say that having children has helped their career compared to 43% of men who say the same. Coqual’s research shows that younger professionals’ growing consciousness and understanding of gender issues may make them more keenly attuned to unacceptable behavior in the workplace. The study finds millennial and gen-Z professionals are over two and a half times (54%) as likely as baby boomer and silent generation respondents (20%) to say they have experienced prejudice related to their gender at work, while 39% of generation X respondents say the same.
Brazil
Coqual finds that in Brazil, the intersection of race and gender continues to disproportionately impact women’s lives in negative ways, as Preta (Black women) are 53% more likely to have experienced gender-based prejudice than Branca (White women). In Coqual’s sample of transgender and gender diverse professionals, 70% say they have experienced gender-based prejudice at work. Furthermore, about one in five transgender and gender diverse employees say colleagues often misgender them (23%) and tell them that their gender non-conformity is just a phase (19%) or that they make their colleagues feel uncomfortable because of their gender identity (23%).
Germany
The study finds that gender and heritage or country of origin are critical intersections to consider in Germany, which does not collect racial data at a national level. Coqual finds that more than half of women with non-German or multiple backgrounds (56%) say they have been passed over for promotions for colleagues who were less qualified compared to 19% of women with German backgrounds. Additionally, 41% of women born outside of Germany say that someone of their gender identity would never achieve a top position at their company. Underlying these feelings of career stall are frequent invalidations including facing dismissive stereotypes from colleagues significantly more often, such as being less credentialed (35%) and more junior than they are (32%).
India
The Hindu caste system continues to dictate Indian social structure in countless ways. Coqual gives particular attention to highlighting the experiences of lower caste women, finding that nearly half of lower caste women (49%) say their social class background often has a negative impact on their professional experience and 55% say they have often considered leaving their jobs in the past year. A staggering 71% of lower caste women say they often change what they share about their family to fit in at work. The hierarchical structure of Indian society places heavy expectations on women to be wives and mothers. More than half of both lower caste women (65%) and upper caste women (51%) say that having children has hurt their career compared to 30% of lower caste men and 40% of upper caste men.
Japan
Coqual finds a dramatic drop-off of women from entry-level to senior positions. Nearly three quarters of women in the sample (73%) hold entry level positions, 23% are from middle management, and only 4% hold senior management or C suite positions. In contrast, men in the sample have more equitable representation, with 40% in entry level positions, 45% in middle management, and 15% in senior management or C-suite positions. Eldercare is a growing focus in Japan. Cultural expectations around eldercare result in a burden of labor that inevitably falls on women.i At present, women agree significantly more than men that their eldercare responsibilities have hurt their careers (42% vs. 31%), and this discrepancy has the potential to worsen as seniors are predicted to make up more than a third (38%) of the population by 2060.ii Coqual finds that TGD professionals (52%) are significantly more likely than cisgender professionals (17%) to say they have been passed over for promotions for colleagues who were less qualified. Nearly half of LGB+ women surveyed (47%) say they have been passed over for a promotion in favor of someone who was less qualified.
South Africa
Race is a critical factor to consider when assessing the experiences of South African professionals. Coqual finds that White professionals hold disproportionate leadership representation, with 37% of White men and 21% of White women compared to 20% of Black men and 19% of Black women in senior-level positions. TGD professionals also continue to face challenges at work. Coqual finds over half (58%) of TGD professionals have experienced gender-based prejudice at work compared to 35% of cisgender professionals. Additionally, more than a third (38%) of TGD professionals say their gender often or always negatively affects their professional experience compared to 15% of cisgender professionals.
To address gender bias and challenges, company leaders must look beyond the binary and create more equitable workplaces. The report outlines Coqual’s new framework — Define, Refine, Reimagine, to provide tangible solutions and guide leaders in advancing gender equity in their workplaces.
Define, Refine, Reimagine
• Define: To cultivate a shared understanding of complex issues, companies must define the mission, vision, and purpose of any DE&I initiative. These efforts cannot succeed without clear definitions of key terms and leaders must become familiar with the ever-evolving language around gender identity. Key terms are especially vital with the growing interest and investment in company-wide self-identification campaigns. This first step requires an ongoing commitment to assessing sensibilities, sensitivities, and employee needs.
• Refine: Companies should continually assess the effectiveness of existing policies, programs, and procedures in generating equitable outcomes. Not every change has to be a radical one. While some efforts may need to be introduced for the first time, there are many existing efforts that can be refined rather than reinvented entirely. Companies can refine current efforts, norms, and policies to support career advancement for women and gender diverse professionals, as well as the daily demands of caregiving responsibilities for professionals around the world.
• Reimagine: The most successful companies proactively anticipate market trends and strategize accordingly, and Coqual suggests companies take the same approach when it comes to the needs of their employees. To prepare for the future of the global workplace, companies must reimagine leadership norms, gender, masculinity, and provide an infrastructure of support for TGD professionals.
Methodology: The primary sources of data for this research report consisted of a survey distributed across each of our eight markets; virtual focus groups; Insights In-Depth® sessions (a proprietary web-based tool used to conduct voice facilitated virtual focus groups); and one-on-one interviews. This report incorporates a mixed-methods analysis of quantitative and qualitative methods. Through our qualitative methods, we reached more than 100 professionals, experts, and practitioners across our eight markets. We then deployed a web-based survey using a criterion sampling approach to reach 5,481 respondents, who were at least 21 years old and currently employed full-time in professional occupations.
Lead Sponsor: Baker Tilly; Research Sponsors: Bristol Myers Squibb, Credit Suisse, Cushman & Wakefield, EY, Intel Corporation, Johnson & Johnson, L’Oréal, Morgan Stanley, The Walt Disney Company.
Research Advisors: Melanie Brewster, PhD, Professor of Psychology and Education at Teachers College, Columbia University; Sam H. L. Fouad, JD, Professor, Fundação Getulio Vargas’ Brazilian School of Public and Business Administration, Brazil; Tina Opie, PhD, Chief Vision Officer, Opie Consulting Group LLC; Visiting Scholar at Harvard Business School; Associate Professor of Management at Babson College; Kathleen McGinn, PhD, Cahners-Rabb Professor of Business Administration, Harvard Business School.
About Coqual: Coqual is a leading global, nonprofit think tank dedicated to helping leaders design diverse, equitable, and inclusive workplaces where every person belongs. Founded in 2004, Coqual provides in- depth research, thought leadership, and data-driven, actionable solutions for companies to address bias and barriers to inclusion for underrepresented populations in the workplace. Coqual’s cutting-edge research and advisory services focus on gender, race, ethnicity, disability, veteran status and LGBTQ identities, and others—as well as the intersections among these groups. For more information, visit www.coqual.org.
11, Jul 2023
Eclipse Hires Uniswap and dYdX Executive Vijay Chetty as Chief Business Officer
SAN FRANCISCO, CA, July 11, 2023 — Eclipse, a leader in customizable blockchain solutions, today announced the appointment of Vijay Chetty as their new Chief Business Officer. Chetty was formerly Head of Business Development at decentralized finance (DeFi) powerhouses Uniswap and dYdX. In this new role, Chetty will leverage his extensive knowledge and experience to propel Eclipse’s growth and market penetration.
Chetty is widely recognized in the DeFi sector for his leadership roles at Uniswap and dYdX, where he drove substantial growth and development for both platforms. He has been pivotal in navigating the intricate DeFi landscape, establishing valuable partnerships, and driving broader liquidity and adoption.
“We’re beyond excited to welcome Vijay to the Eclipse team,” said the Eclipse CEO, Neel Somani. “Given Vijay’s proven track record launching and scaling dYdX and Uniswap, he navigated the exact challenges that Eclipse solves. This marks the expansion of Eclipse’s DeFi offering in addition to the suite of growing use cases powered by our cross-ecosystem infrastructure.”
Eclipse enables highly scalable, customizable solutions for applications across multiple ecosystems. Eclipse’s technology provides optimized, modular blockchains called “rollups” for applications with unique infrastructure needs, including those in DeFi, gaming, decentralized physical infrastructure networks, and social.
Chetty shared, “I am incredibly excited to join the Eclipse team. The work they’re doing to enhance Ethereum scalability is groundbreaking. I look forward to contributing to the growth of Eclipse’s modular infrastructure, and to shaping the future of decentralized finance.”
Chetty’s leadership will play a critical role in driving the adoption of rollup technology in the wider crypto and blockchain ecosystem.
Eclipse’s mainnet is targeted for the second half of 2023 and is currently onboarding multiple cohorts of projects including Polygon, React Network, Injective, Zebec, Worlds, and more. To learn more about Eclipse’s customizable rollup solutions and deploy an optimized appchain, contact team@eclipse.builders.
11, Jul 2023
Dreamtime Learning Launches Community Program, Inspiring Growth and Learning for Children
India, 11th July 2023:Dreamtime Learning Community (DTC), founded by a disruptor in the Indian Education landscape, Lina Ashar, has launched two after-school community courses– “Game Changers” and “Mavericks”. With expert faculty and an inspired vision aimed at challenging established norms while equipping children for a rapidly changing future, DTC aims to partner with 100+ schools in its initiatives to elevate learners via its after-school enrichment programs.

‘Game Changers’ offers interdisciplinary teaching of language and literature, providing an immersive learning experience for students and leaving them brilliant communicators. ‘Mavericks’ focuses on exploring the wonders of science. It is designed in a way to quench student curiosity all while inspiring a lifelong quest for learning. Children between the ages of 5 – 10 Years are invited to enroll in the weekend program that spans 55 sessions in a three-month period. The first cohort is all set to start on the 5th of August, 2023. Further, DTC will be rolling out the program for learners across borders in South East Asia and the Middle East.
This community course provides students with the knowledge, abilities, and views required to navigate and positively impact the world. Further, this molds children into knowledgeable, proactive citizens in whom we can all take pride.

Applauding the new approach, Ms. Lina Ashar, Founder of Dreamtime Learning, said, “Transformation in education is essential today. Our community program bestows on this as it represents a unique opportunity for children to learn, grow and develop their identity. With advancements in teaching methodology and strong competition churning the education system, it is imperative to reshape the world by transforming education, which will further influence society. Our program will be a game changer for our students in building confidence, awareness and critical thinking skills. With this program, we are confident in building self-leader quality in our young minds, inspiring new ideas, challenging established norms, and promoting innovation”.
The programs encompass an array of captivating activities and experiential learning opportunities crafted to ignite children’s imagination, nurture creativity, and foster critical thinking skills. The primary objective of the program is to broaden horizons and cultivate a sense of curiosity in young learners. They also hope to connect students with community resources, esteemed experts, and mentors. Carefully curated, these activities seamlessly complement the core curriculum provided in schools, providing a well-rounded and comprehensive educational journey for participants.
DTC is keen on encouraging experts, and organizations to collaborate and provide young learners with valuable experiences, mentorship opportunities and prides itself in being a first of its kind after-school program in India and with the aspiration to make students future-ready, engaged citizens of tomorrow.
11, Jul 2023
Millennial Urban Comfort – ‘Real’ Value in a Changing World
– By Akash Pharande, Managing Director – Pharande Spaces
India has been witnessing a consistent rise in urbanization over the years. A survey by the United Nations projects that by 2030, over 40.76% of India’s population will live in urban regions. World Bank statistics from 2017 add weight to this estimate – in that year, about 34% of the country’s population already lived in cities.
India’s urbanization trend will continue, and by 2050, India will be among the leaders in global urbanization, along with China, Indonesia, Nigeria, and the United States. And India’s urban ethos is driven by young people – dual-income nuclear families and up-and-coming single professionals.
Data from Statistica, which shows the age distribution of India between 2011 and 2021, lean towards 67.51% in the 15-64 age group. In 2022, the median age of an Indian was 28.7 years, as opposed to 38.4 in China and 48.6 in Japan.
Simultaneously, the nuclear family is quickly taking over as the majority of Indian families today have broken away from their once-joint origins and are now defined by five or fewer individuals.
Nuclear Family – The Urban Phenomenon
Today’s millennials aspire to live lifestyles based on modern options. They want to be financially independent, select their life partners without being influenced by the older generation, raise their own kids in modern, urban settings, and send them to reputable schools and colleges.
The success of a modern nuclear family depends on maintaining a laser-like focus on earning power, job advancement, and savvy investments. As a reward for this focus, modern young Indians expect to live in security and comfort and look for homes that can deliver this comfort.
The Millennial Comfort Revamp
While the pursuit of comfort hasn’t changed over the generations, its definition certainly has. For India’s young urbanites today, a comfortable home is defined by adequate size, the right location, smart home features, and top-grade amenities and facilities.
Where their parents may have been happy to live in smaller homes near the city’s traditional office hubs, stretching their budgets to buy such homes, subjecting the family to chaotic, cramped inner-city living, a massive number of Indian millennials grew up in such limited environments and are determined to live better lives.
This orientation has, in recent years, caused developers to shift their focus from compact housing projects near the core areas to spacious townships and gated communities in the suburbs. These projects have everything that the previously popular ones lacked – greenery, sustainability features, technology-driven comfort and convenience, high-level security, and, most of all, enough space for the family to grow.
The always-crucial factor of location has also undergone a sea change. The inner city has fallen out of vogue. The preference of young Indian urbanites has gone from ‘central’ to ‘well-connected’. The metro system and ring roads have caused our cities to expand hugely in scope, making less expensive outlying areas even more desirable than the congested city centers.
Various reports by leading real estate consultants highlight the increased demand for bigger homes made affordable by their non-central locations and reliable by their developers’ reputation for quality.
Townships – New Urban Comfort Standard
With ultra-modern townships now being developed in non-central locations, high-grade comfortable living standards have become a very approachable goal. The previous mold has been broken, and an entirely new standard of urban comfort has been set. These projects have everything it takes to live spaciously.
Young Indians are buying into projects that support their desire for space, convenience, and safety both inside their homes and within the projects. Unlike in previous years, there is now a huge demand for on-site amenities that improve the quality of life. It’s no longer just about four walls but an integrated lifestyle.
The best-selling townships today feature spacious and well-designed living spaces, incorporating modern architectural and interior design principles. They prioritize functionality, aesthetics, and the efficient utilization of space, enhancing residents’ overall quality of life.
They also have advanced security systems, such as CCTV cameras, access control mechanisms, and security personnel, which create a safer living environment. Unlike the housing projects of yesteryears, these townships have highly efficient facilities management systems that tackle waste management, maintenance, repairs, and utility upkeep.
They have well-designed community spaces and recreational facilities such as parks, playgrounds, swimming pools, gyms, and community centers. These promote an active and healthy lifestyle, encourage social interaction among residents, and provide spaces for relaxation and leisure activities.
Tech-savvy millennials also expect technology that enhances their living experience. Smart home systems, such as automated lighting, temperature control, visitor monitoring, and appliance control, have increasingly become must-haves in the new urban comfort sphere.
Comfort with a Conscience
Finally, and perhaps most importantly, the Indian millennial’s concept of urban comfort also includes having an easier conscience. They expect sustainability features that address the mounting environmental concerns that are constantly in the news now.
Sustainable and energy-efficient features such as solar panels, energy-efficient appliances, rainwater harvesting systems, and green spaces reduce the project’s carbon footprint, lower utility bills, and result in a more environmentally friendly community.
Indeed, the concept of urban comfort has come a long way over the years. And indeed, it is a constantly evolving theme that will see rapid and regular changes in the years to come. Indian homebuyers expect a lot more from their homes than their parents did – and developers have little choice but to deliver ‘real’ value in a changing world.