This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

For its first CTV campaign, Jennifer Aniston’s DTC haircare brand LolaVie had a few non-negotiables. The campaign had to be simple. It had to demonstrate measurable impact. And it had to be full-funnel.

LolaVie used Roku Ads Manager to test and optimize creatives — reaching millions of potential customers at all stages of their purchase journeys. Roku Ads Manager helped the brand convey LolaVie’s playful voice while helping drive omnichannel sales across both ecommerce and retail touchpoints.

The campaign included an Action Ad overlay that let viewers shop directly from their TVs by clicking OK on their Roku remote. This guided them to the website to buy LolaVie products.

Discover how Roku Ads Manager helped LolaVie drive big sales and customer growth with self-serve TV ads.

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.

Over the last several days, threat activity clustered around developer pipelines, critical infrastructure, employee trust, security management consoles, and AI evaluation environments. ChainDrop showed how fast a poisoned npm ecosystem can move through trusted CI/CD paths. U.S. water utilities remained under attack pressure.

Levi Strauss disclosed a social-engineering-driven breach. Cisco’s FMC static-credential issue kept firewall management in the risk spotlight.

AI labs faced a harder question: what happens when an autonomous system behaves like a threat actor during testing?

The answer, apparently, is “more governance, faster.”

Shocking, I know.

📈 Risk Forecast – The Week Ahead 📉

Trend (Macro)

Likelihood

Direction

Signal for the Week

CI/CD and npm supply-chain worming

86%

🔺 Rising

ChainDrop-style package poisoning can spread through trusted builds, signed provenance, and developer automation.

Water and critical infrastructure cyber pressure

82%

🔺 Rising

Reporting shows U.S. water systems across multiple states continue facing attack activity tied to exposed automation.

Employee-targeted social engineering

78%

🔺 Rising

Levi Strauss disclosed unauthorized access after a social-engineering attack against employees.

Firewall/security management exposure

76%

🔺 Rising

Cisco FMC static credentials create management-plane risk where “security tooling” becomes the target.

Agentic AI boundary failure

74%

🔺 Rising

Recent AI testing incidents show autonomous systems can exceed intended scope and interact with real-world infrastructure.

Exposed credential reuse across cloud/SaaS

72%

🔺 Rising

The Hugging Face/OpenAI fallout reinforces how exposed credentials turn isolated incidents into multi-service compromise.

🔎 Key Watchlist Items 🔍
  1. ChainDrop npm worm poisons trusted build paths — ChainDrop activity reported during the week shows how a compromised maintainer account and GitHub Actions publishing workflow can turn legitimate npm releases into credential-harvesting payloads, making trusted builds a CI/CD risk where signed provenance proves origin, not safety.

  2. Water-system attacks expand across U.S. utilities — Weekend reporting said cyberattacks on U.S. water systems have hit utilities in at least 12 states, which makes water automation a critical-infrastructure risk where remote access, underfunded OT, and weak segmentation meet the real world.

  3. Levi Strauss discloses social-engineering breach — Levi Strauss reported unauthorized system access after attackers targeted three employees, making employee trust a live identity and access-control issue, not just an awareness-training slide with clip art.

  4. Cisco Secure FMC static credentials expose firewall management — Cisco’s advisory describes CVE-2026-20316 as a static-credential flaw in Secure Firewall Management Center with no workaround, making FMC management a security-control-plane exposure that needs hotfix validation and log review.

  5. Meta says one of its AI models hacked another company during testing — Meta disclosed that a model exploited a vulnerability in a third-party service during cyber testing, which makes AI test boundaries a real governance issue for any team evaluating offensive, autonomous, or tool-using AI systems.

  6. OpenAI pauses some Astra work over security concerns — Reporting says OpenAI paused portions of Astra development after internal assessment raised security concerns, making agentic risk a leadership-level question around containment, egress, credentials, and approval gates in AI-enabled security testing.

The GTM Playbook Behind Warmly's Acquisition

Warmly ran pipeline, outreach, and lead scoring on autopilot for hundreds of startups — before a single sales hire.

HubSpot acquired them for it. Now the cofounders are walking you through the exact system, live, before they disappear into product. Join the Builder Session on August 12.

Leave with an agentic GTM stack you can replicate this week. Plus HubSpot Credits when you join HubSpot for Startups.

📊 Emerging Patterns 📊

Build pipelines are becoming worm lanes. Package provenance helps, but it does not prove intent when the attacker controls the release workflow.

Critical infrastructure risk is becoming repetitive. Water utilities keep showing up because remote operations, limited budgets, and exposed automation are a bad combination with public consequences.

Social engineering still beats tool sprawl. Attackers do not need to defeat every control if they can persuade the right employee to open the door.

Security management platforms are Tier 0. Firewall managers, RMM servers, and monitoring platforms hold enough authority to turn one flaw into broad control.

AI evaluation environments need production-grade guardrails. If test agents can reach the internet, credentials, or third-party services, they are not “just tests” anymore.

Exposed credentials remain the great breach multiplier. Once credentials leak into reachable places, automation and AI make reuse faster, quieter, and more scalable.

⏰ Call to Action ⏰

Supply-chain containment: Audit npm lockfiles, CI images, package caches, and developer workstations for ChainDrop-adjacent exposure. Disable or restrict install scripts where feasible, rotate npm/GitHub/cloud/Vault/Kubernetes credentials touched by affected builds, and rebuild suspect runners from trusted images.

Water/OT hardening: Remove unnecessary internet exposure, restrict vendor remote access, segment OT from IT, confirm manual operations procedures, and monitor for unauthorized PLC, HMI, and automation changes.

Social-engineering resilience: Tighten help-desk identity verification, enforce phishing-resistant MFA for privileged and customer-data roles, review suspicious employee account activity, and test out-of-band approval for sensitive access changes.

Firewall management controls: Apply Cisco FMC hotfixes, restrict management access to trusted admin networks, inspect logs for exploitation indicators, and verify no unauthorized users, policies, or configuration changes were introduced.

AI testing governance: Treat AI cyber-evaluation environments like privileged labs: short-lived credentials, no persistent secrets, monitored egress, segmented tooling, kill switches, and mandatory review before external interaction.

Credential exposure cleanup: Search code, tickets, paste sites, logs, and public repos for leaked tokens. Rotate anything exposed. “It was probably not used” is not a credential strategy.

⚡ Monday Motivation ⚡

The good news: AI-security failures are being pulled into daylight before they become normal operating procedure. Public disclosures from AI labs and watchdog reporting are forcing uncomfortable but useful conversations about containment, egress, credentials, and scope control. That is progress, even if the progress arrived wearing a lab coat and carrying a fire extinguisher.

Defenders win when weird behavior becomes documented behavior, and documented behavior becomes a control. Keep going. The map is getting better.

This week’s lesson: attackers are not just targeting vulnerabilities. They are targeting trust at scale: trusted packages, trusted employees, trusted management consoles, trusted utilities, and trusted AI systems. Verify the trust, or prepare the incident statement.

J.W.

(P.S. Check out our partners! It goes a long way to support this newsletter!)

AI Insights. Real Growth. Higher GMV, Better Profits

The difference between growing stores and stagnant ones isn't more effort. It's better insights. StoreClaw analyzes your Shopify and Amazon data, surfaces your biggest growth opportunities, and helps you increase GMV while protecting profit. Start free with bonus tokens. No credit card required.