VMware posts strong 2019 financial results citing AWS partnership and ‘tech breaking out of tech’

VMware has closed off its 2019 fiscal year with record annual revenues, solid upticks across the board and considerable strength on its partnership with Amazon Web Services (AWS).

Revenue was $2.59 billion (£1.96bn) across the quarter, at a 16% uptick on this time last year, while for the fiscal year it was $8.97bn, a yearly increase of 14%. License revenues were at $1.2bn, or 47.5% of overall quarterly revenues, compared with 52.5% for service revenues. For the fiscal year, ‘services’ comprised 57% of total revenues, a slight dip from the previous year’s 59%.

“We were very pleased with this terrific quarter and fiscal 2019,” said VMware CEO Pat Gelsinger in an earnings call following publication of the results. “At VMware, we believe that software has the power to transform business and humanity. We understand that our products, operations and people collectively have an impact in the world, and we strive to generate positive global impact through all that we do.

“Customers look to VMware for solutions across hybrid cloud, multi-cloud, modern apps, networking and security and digital workspace to help enable their digital transformations,” Gelsinger added. “We demonstrated good Q4 results across our hybrid cloud and SaaS portfolio as we strategically focused on expanding that offering.

“We’ve remained committed to growing this business as customers continue to turn to us for the best solutions that span private and public clouds.”

With that statement in mind, one of the key highlights of the quarter focused around VMware’s continued partnership with AWS. The companies keep cropping up in each other’s events; AWS CEO Andy Jassy took to the stage at VMworld in Las Vegas back in August, while Gelsinger returned the favour at re:Invent in November to all but bring the house down with the announcement of AWS Outposts.

Outposts, AWS said at the time, aims to deliver a ‘truly consistent hybrid experience’ by bringing AWS services, infrastructure and operating models to ‘virtually any’ on-premises facility. VMware’s partnership is a key part of making this happen. According to RightScale’s 2019 State of the Cloud report, issued earlier this week, 12% of organisations polled said they were using Outposts right out of the gate, with a further 29% interested in deploying.

Gelsinger said the most recent quarter saw a $20 million deal brokered with VMware Cloud on AWS, with new customers including Freddie Mac, Nant Media Holdings and the United States Air Force Field Enterprise Data Center.

The other major news VMware issued over the past three months was the planned acquisition of Kubernetes provider Heptio. At the time, Heptio co-founder Craig McLuckie said the two companies’ visions were ‘uncanny’, with VMware seeing the deal as an opportunity to build a cloud-independent Kubernetes control plane for customers. “We will accelerate efforts to make Kubernetes the standard for customers building and running their applications across clouds, and continue to drive the open source community’s development of this critical platform,” added Gelsinger.

Gelsinger described the state of the industry currently as ‘tech breaking out of tech’ in response to an analyst question around divergence between various infrastructure providers. This is a theme which this publication has covered frequently, both in the rise of multi-cloud projects organisations are taking on as well as exploring the next wave of cloud services, whether they be serverless and containers, or quantum and machine learning.

“There’s going to be winners and losers,” Gelsinger explained. “We’ll continue to see lots of questions on cloud, private and public cloud, and how hybrid cloud transitions. We clearly are going to see these normal cycles of over[supply] and undersupply as people are building up rapidly in different geos. We’re no longer dependent on any geo or any individual product, but the real breadth of our portfolio is nicely rewarding us across the broad landscape of, we believe, a good tech market [that] is going to continue well into the future.

“There will be winners and losers inside of that because there is so much change going on in the marketplace with these powerful trends,” Gelsinger added. “I’ve talked about the superpowers: cloud, mobility, AI and edge and IoT, and all of those will have different effects of who’s going to be the winners and losers inside of it.”

You can read the full VMware fourth quarter and fiscal year 2019 results here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Microsoft launches cloud-native security management tool Azure Sentinel


Adam Shepherd

1 Mar, 2019

Microsoft has announced a new inbuilt security information and event management (SIEM) tool for its Azure cloud customers, which promises to use AI to slash the number of alerts that security teams need to respond to.

The new tool, dubbed ‘Azure Sentinel’, will help infosec professionals monitor and defend their cloud environments by collating all of their security logs and threat data in one place. As well as information from Office 365 and Azure, customers will be able to process data from partners such as F5 Networks, Cisco, Palo Alto Networks, Symantec, Fortinet and more, including partners outside the security sector.

Unsurprisingly, Microsoft is touting the speed and scale that the cloud can offer as one of the biggest benefits of this service, promising it allows customers to «invest your time in security and not servers». In a blog post announcing the new product, the corporate vice president of Microsoft’s Cybersecurity Solutions Group Ann Johnson boasted that early adopters of the product have seen up to 90% reductions in ‘alert fatigue’ – although she neglected to mention how this was measured.

«Azure Sentinel is the product of Microsoft’s close partnership with customers on their journey to digital transformation,» Johnson wrote «We worked hand in hand with dozens of customers and partners to rearchitect a modern security tool built from the ground up to help defenders do what they do best – solve complex security problems. Early adopters are finding that Azure Sentinel reduces threat hunting from hours to seconds.»

While other companies like Splunk and Sumo Logic have previously unveiled cloud-based SIEM tools, Microsoft says that it’s the first major cloud provider to offer one as an integrated part of its portfolio.

Azure Sentinel is currently available in preview via the Azure portal; the product is currently free to use, with future pricing to be announced at a later date. Microsoft has also said that there may be additional charges for automation workflows, machine learning model customisation and data ingestion, importing Office 365 data will be free.

The company also announced a tool that allows customers to call in the cavalry in the event of a security crisis. Microsoft Threat Experts, a new capability which will be introduced to Windows Defender ATP, allows customers to call on the expertise of Microsoft’s own security specialists, who will scour your (anonymised) security data to identify the most pressing threats to your organisation.

Customers can apply to join the service through their Windows Defender ATP settings and once approved, can access it via a button in the console labelled ‘Ask a Threat Expert’.

Workplace by Facebook hits two million paid users


Clare Hopping

1 Mar, 2019

Facebook has revealed its paid Workplace enterprise communications platform is now being used by two million people worldwide, a little over two years after its launch.

The social network said more than 150 large companies (with more than 10,000 employees) have signed up to its corporate collaboration tool, offering workers a centralised place to communicate with each other.

Its biggest customers are Nestle, Vodafone, GSK, Telefonica, AstraZeneca, Delta Airlines and NAB (National Australia Bank).

“We believe this rapid uptake is because Workplace creates lasting business value, increasing the impact teams can have on their organization and customers,” the company said.

“Team members can work smarter, make better decisions, and take decisive action – all empowered by more social communication and information sharing.”

All of this is provided on a platform that’s familiar to employees using regular Facebook tools. With Facebook Workplace, teams can connect in exactly the same way as people can connect with friends online, using enhanced business-centric tools such as groups, chat and video calls.

The service costs from $3 per user, per month, although it also offers a 90-day free trial and for life for registered non-profits and staff of educational institutions, as part of Facebook’s mission to make collaboration a necessity.

Facebook hasn’t revealed how many additional customers it has using its free service or its educational or NGO customers on its Workplace for Good programme, which offers free subscriptions.

Facebook only started charging Workplace users in October 2017, which would appear to have been a move to get companies to get familiar with the service before it decided to make money off them.  

RightScale State of the Cloud 2019: Azure gains again, cost optimisation key, PaaS explodes

Microsoft Azure continues to eat into Amazon Web Services’ (AWS) dominance in the enterprise market, while managing cloud spend and governance continues to be the primary concern, according to the 2019 RightScale State of the Cloud report.

The study, a yearly benchmark assessing cloud adoption and which polled almost 800 executives with a relatively even spread between enterprise and SMB respondents, found cloud cost management was the primary concern for the third consecutive year. For the enterprise sector, optimising costs (84% this year, 80% in 2018) and governance (84% this year, 77% in 2018) are notably on the rise.

The study noted how organisations may be wasting more than even they expect on their services – hence the need for optimisation. Survey respondents estimated they wasted 27% of their uptake this year, yet Flexera – which bought RightScale last year – assesses it to be nearer 35%.

It’s fair to say that using the biggest cloud vendors can be a complex experience with the sheer number of features available. Yet organisations are not helping themselves, with only a handful of companies polled using automated policies to shut down unused workloads, or rightsizing instances. Indeed, less than half (47%) of AWS users are aware of and utilise AWS Reserved Instances, while Azure’s Reserved Instances (23%) pales further into insignificance.

Exploring the cloud behemoths (above), Azure adoption grew from 45% to 52% year on year overall, with Azure’s adoption figures now looking at 85% of AWS’ – up from 70% the year before. For enterprise-specific figures, Azure has risen to 60% while AWS remains flat at 67%. Google remains clear in third position. VMware on AWS Cloud saw growth of 50% across the board, while all other providers surveyed – including Oracle, IBM and Alibaba – saw enterprise gains.

One of the key areas where organisations are becoming increasingly comfortable is emerging platforms. Gartner has already noted this week how the industry is almost at the tipping point where platform as a service (PaaS) offerings will become cloud-dominated, and this is reflected in the RightScale report. Serverless saw a 50% growth year on year, with 36% of overall respondents using it, while machine learning, containers-as-a-service, and IoT are also quick to grow.

Containers, meanwhile – and Kubernetes in particular – are seeing particularly strong adoption rates. 57% of respondents say they regularly use Docker, while Kubernetes has 48% adoption among respondents, up almost double from the previous year (27%). For enterprises, Docker (66%) and Kubernetes (60%) are even further entrenched. Of the big cloud offerings, only Azure Container Service saw noticeably greater adoption, with AWS (44%) ahead of Azure (28%) and Google (15%).

As previously the overriding theme, with so many sectors to cover, is one of hybrid IT and multi-cloud (below); making the most out of your stack and finding the correct avenues for particular workloads. If anything, the release of AWS Outposts – with the nod to VMware’s rise already seen in the report – helped truly legitimise, and normalise, this thinking. The report noted how private cloud growth was there, if a little slow; 12% of those polled are already using Outposts out of the gate with a further 29% interested in the future. VMware vSphere, at a flat 50%, remains the primary tool.

Ultimately, these figures should make for solid reading across the industry. Yet Flexera and RightScale will perhaps be keener than most. As this publication put it when the acquisition was announced in October, the two companies’ proposed marriage, around Flexera’s IT and software asset management (SAM) portfolio, and RightScale’s cloud complexity problem solving, should be a happy one.

“The data is consistent with what we are hearing from our C-level customers: managing the rapid increase in cloud use requires new capabilities for cost optimisation and IT governance,” said Jim Ryan, CEO of Flexera. “With multi-cloud as the strategy of choice, most enterprises are already spending over $1m a year in public cloud. As a result, optimising costs is the top cloud priority for the third year in a row, and governance is the top challenge.”

You can read the full report here (email required).

Picture credits: RightScale, used under CC BY

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Gartner says tipping point in cloud PaaS is almost complete – with $20bn market revenue in 2019

An interesting if brief note from the analysts at Gartner this week: according to their forecasts, almost half of today’s platform as a service (PaaS) service offerings are cloud-only, with a $20 billion (£15.02bn) market revenue by the end of this year.

The analyst firm’s landscape details more than 550 PaaS offerings from 360 vendors across 21 market segments. 48% of these offerings are cloud-only, with 90% only operating within a single PaaS market segment. In terms of the overall market, the move to $20bn this year will go up to $34 billion by 2022.

These figures make for interesting reading when looking through the record books. As far back as 2012, Gartner said PaaS market revenue would hit almost $3bn by 2016. Things have accelerated since then, although as part of a wider market acceleration. Gartner figures from April last year predicted the overall public cloud market would overtake the $300bn mark by 2021 with a whopping 21% growth in 2018 alone. PaaS comprised only 8% of the total public cloud market however.

Naturally, the nature of what the PaaS market comprises is changing. In November 2013, Laurent Lachal, then a senior cloud computing analyst at Ovum, said the market will ‘remain confused’ as PaaS evolved in the coming two to five years. “PaaS offerings will mature and expand the depth and breadth of their features,” he wrote at the time. “For example, as part of the expansion of the scope of their ecosystem services, in the next two years PaaS offerings will increasingly provide not only business-level services but also application-level ecosystem services.”

According to Gartner’s latest focus, the latest abstraction for platform services and applications are blockchain, digital experience, serverless, and artificial intelligence and machine learning.

“Although many organisations anticipate a long-term retention of on-premises computing, the vendors of nearly half of the cloud platform offerings bet on the prevailing growth of cloud deployments and chose the more modern and more efficient cloud-only delivery of their capabilities,” said Yefim Natis, research vice president and distinguished analyst at Gartner.

“Cloud computing is one of the key disruptive forces in IT markets that is getting mainstream trust.”

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Hackers target Elasticsearch clusters in fresh malware campaign


Rene Millman

27 Feb, 2019

Security researchers have observed a spike in attacks from multiple threat actors targeting Elasticsearch clusters, in what is believed to be attempts to place malware on victims’ machines.

Attackers appear targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker’s payloads, according to a blog post by researchers at Cisco Talos. Researchers found that both malware and cryptocurrency miners were being left on target machines.

Researchers explained that because Elasticsearch is typically used to manage very large datasets, the repercussions of a successful attack on a cluster could be devastating due to the amount of data present.

Hackers have been consistently deploying two distinct payloads with the initial exploit, always using CVE-2015-1427. The first payload invokes wget to download a bash script, while the second payload uses obfuscated Java to invoke bash and download the same bash script with wget.

“This is likely an attempt to make the exploit work on a broader variety of platforms,” said researchers.

Researchers also saw a second hacker exploiting CVE-2014-3120, using it to deliver a payload that is derivative of the Bill Gates distributed denial-of-service malware. “The reappearance of this malware is notable because, while Talos has previously observed this malware in our honeypots, the majority of actors have transitioned away from the DDoS malware and pivoted toward illicit miners,” said researchers.

A third hacker was observed to download a file named «LinuxT» from an HTTP file server using exploits targeting CVE-2014-3120. hosts that attempted to download the «LinuxT» sample also dropped payloads that executed the command «echo ‘qq952135763.'»

“This behaviour has been seen in elastic search error logs going back several years,” said researchers.

Honeypots set up by researchers also detected additional hosts exploiting Elasticsearch to drop payloads that execute both «echo ‘qq952135763′» and «echo ‘952135763,’» suggesting that the attacks are related to the same QQ account.

“However, none of the IPs associated with these attacks have been observed attempting to download the «LinuxT» payload linked to this attacker. Additionally, unlike other activity associated with this attacker, these attacks leveraged the newer Elasticsearch vulnerability rather than the older one,” said researchers.

Researchers said that these Elasticsearch vulnerabilities only exist in versions 1.4.2 and lower, so any cluster running a modern version of Elasticsearch is unaffected by these vulnerabilities. “Given the size and sensitivity of the data sets these clusters contain, the impact of a breach of this nature could be severe,” warned researchers.

Organisations using Elasticsearch are urged to patch and upgrade to a newer version of Elasticsearch if at all possible.

MWC 2019: VMware says telcos must move 5G infrastructure into the cloud to stay ahead


Connor Jones

27 Feb, 2019

VMware made many announcements at MWC 2019 and they all centred around one common theme: network virtualisation.

«If a telco wants to progress in the future, they need to think software-defined,» said Gabriele di Piazza, VP products & solutions for telco at VMware. «More and more communication service providers (CSPs) are turning to VMware to lead their transformation ahead of 5G rollout.»

It thinks that there needs to be a shift away from hardware-defined architecture, towards a fully virtualised one which will enable telcos to beat competitors to market with fully automated, scalable infrastructure.

Traditional data centre models will be a thing of the past and phones will transmit to masts and that data will be sent to the cloud, where the network is managed virtually in a SlaaS configuration – we’re noticing a pattern here.

VMware calls it a ‘telco cloud’ which will exist alongside the traditional public, private, hybrid and edge clouds. The network function virtualisation (NFV) platform on its telco cloud will enable better management of a network and improved efficency of services.

Features and applications can be applied to the cloud environment such as machine learning-driven technology that can spot issues and vulnerabilities and automatically patch them without having to physically attend a data centre and make a repair.

«With the current demands placed on carrier networks reaching new levels and 5G on the horizon, there’s no room for error when it comes to network infrastructure,» said Piazza. «Near real-time solutions are the key to identifying and fixing issues in order to keep networks humming. Networks need unified monitoring, automation and assurance across physical and virtualized networks to deliver the highest levels of performance, scalability and resiliency.»

Among the vast amount of announcements the company made at this year’s MWC which included its telco cloud, NFV virtual cloud platform, it also announced some key business partnerships that aim to strengthen 5G network management on the whole.

Building on a relationship dating back to 2012, VMware announced it’s teaming up with Ericsson to test, validate and optimise the biggest network functions in VMware’s cloud.

This makes both firm’s offerings more appealing as Ericsson becomes one of the prime chargers in the 5G infrastructure scene, it benefits from having its applications available on the VMware cloud and having them tested for assurance by the pair of them.

It will make it easier for telcos to access and manage the Ericsson services they need while knowing that they’re safe and optimised as they reside in the cloud.

VMware also announced that it will be servicing T-Systems as its managed services provider using its Workspace One multi-cloud platform.

When the company hires a new employee, that employee’s work device, say a phone, can be delivered to them on their first day pre-loaded with every application they need to function in the office.

One of the main issues with the current workplace is those presented, ironically, by security products, said Adam Rykowski, VP product management for Workspace One.

Multi-factor authentication can be an issue for new starters or when working remotely because users would have to log in to every service, of which there could be up to 30-40 which is hugely laborious and time-consuming.

Using Workspace One, all the apps the employee needs reside in the cloud and can be accessed using a single sign-on that VMware applies to all relevant apps.

Bare metal flaw allows hackers to put backdoors into cloud servers


Rene Millman

27 Feb, 2019

A new flaw has been discovered by security researchers that could enable hackers to install backdoors on the firmware of bare-metal cloud servers that stay active even when the customer using the hardware has been re-assigned elsewhere.

Called “Cloudbourne”, the vulnerability was first discovered by researchers at the Eclypsium Research Team, who detailed their findings in a blog post. They found that hackers could plant backdoors and malware in the firmware of a server, or in its baseboard management controller (BMC), with relative ease.

These BMCs enable remote management of a server for initial provisioning, operating system reinstall and troubleshooting. Cloudborne exploits a flaw in the hardware’s reclamation process when moving clients on and off a bare metal server.

While physical servers are dedicated to one customer at a time, they don’t stay that way forever,” said researchers. “Servers are provisioned and reclaimed over time and naturally move from customer to customer.”

The firmware of the hardware is not reflashed in the reclamation process, allowing backdoors to persist. A hacker uses a known vulnerability in Supermicro hardware to rewrite the BMC and gain direct access to the hardware.

Researchers said that hackers “could spend a nominal sum of money for access to a server, implant malicious firmware at the UEFI, BMC, or even component level, such as in drives or network adapters. Then the attacker could release the hardware back to the service provider, which could put it back into use with another customer.”

They added that given a BMC’s ability to control the server, any compromises to that firmware can provide access to powerful tools for an attacker to exploit.

“Given the nature of the applications and data hosted on bare-metal offerings, this opens up the possibility for high-impact attack scenarios,” they said.

These scenarios include application disruption, where a malicious implant at the BMC level could permanently disable a server; data theft, as it provides attackers with another very low-level way of stealing or intercepting data; and ransomware attacks, as attackers would naturally have the ability to take hold of valuable assets.

The backdoor could also compromise other parts of cloud infrastructure. For example, hackers could send malicious IPMI commands over system interfaces from the host without the commands being authenticated.

“Since there is no authentication performed when using system interfaces, the only barrier to running arbitrary code within the BMC is whether the BMC itself performs cryptographically secure signature verification of the firmware update image before applying the update. Unfortunately, not all BMCs perform this check, and even when they do, malware can exploit vulnerabilities in the BMC firmware to bypass it,” noted researchers.

Researchers said that as firmware underlies even the host operating system and the virtualization layers of a server, any implants would naturally be able to subvert any controls and security measures running at these higher layers.

Quickbooks launches MTD suite for small businesses


Clare Hopping

27 Feb, 2019

Quickbooks has made its Making Tax Digital suite widely available for small businesses and accountants, which includes software that will allow users to continue to file VAT using spreadsheets.

The updated tools will ensure that anyone filing a VAT return using the tools will be compliant with the government’s new digital tax legislation, set to come into force on 1 April.

The platform comprises tools such as SmartCheck, a pilot software that identifies common mistakes in VAT returns, and Smart Notifications, which notifies accounting professionals when their clients need to file for VAT, advising on due dates and making sure the tasks are scheduled so the deadline isn’t missed.

“Accounting professionals and small businesses are looking to the software industry to make MTD easy,” Shaun Shirazian, head of product Europe, said.

“After conducting numerous pilots, through listening to the feedback of our customers and by working closely with HMRC, we have optimized and iterated QuickBooks and built a best-in-class solution ready for the MTD generation that is available to QuickBooks users.”

A major new feature included in all QuickBooks Online subscriptions is the Quickbooks Bridging Software, which allows small businesses to use spreadsheets to file their VAT return using Quickbooks. The hope is that this will make it easier for businesses already using spreadsheets to file their return to comply with new regulations – something that is likely to be welcome among smaller businesses.

“As digital tax is embraced, our next challenge is to help small businesses and accounting professionals put digital at the heart of their business to help them supercharge productivity, run and grow their business.”

Quickbooks has also launched a helpline for small businesses to check they’re compliant with the new Making Tax Digital legislation. It will also serve accounting professionals using Quickbooks to file returns for both themselves and clients.

A handful of new products will also be made available for SMBs and those that are self employed, including Receipt Capture, which can take photographs of receipts and automatically import the required data. 

Sauce Labs doubles down on EU growth with Frankfurt data centre


Clare Hopping

27 Feb, 2019

Sauce Labs has launched a virtual data centre in Germany and expanded its London office to keep up with European data demands, the company has announced.

It’s a reflection of the company’s success in the EMEA region and, after doubling its European workforce, it now needs office space to support its rapid growth.

“Since establishing itself in Europe more than two years ago with the acquisition of TestObject, Sauce Labs has continually made strong investments in the region, and today’s announcement is just the latest example of our commitment to customers in EMEA,” said Hannes Lenke, vice president of New Ventures and general manager, Germany, Sauce Labs.

The company now has grown its local enterprise customers to more than 100 and achieved year-on-year recurring revenue increases of 60%, demonstrating a hunger for digital transformation in the UK and beyond, despite challenging economic conditions.

Businesses are increasingly searching for a robust continuous app testing platform so they can get services to market faster and Sauce Labs believes it’s able to offer this with the introduction of an additional facility in Europe.

“Now anchored by our new data center in Frankfurt, Sauce Labs continues to be at the forefront of empowering organisations in Europe to quickly and reliably scale both the volume and velocity of their tests, enabling them to successfully move forward with their digital initiatives while meeting mounting compliance requirements.”

The new Frankfurt-based data centre will offer European businesses a platform to test devices, alongside its existing European real device data centre, significantly boosting its resources.

The company also announced the appointment of Joe Pynadath, as vice president of sales for the EMEA region and Karolin Beck as vice president of EMEA marketing.