skip to main | skip to sidebar
My Open Kimono


















 WHEN THE FISH GO FISHING
 
A good way to measure the health of the ad industry is to track the number of Mergers and Acquisitions taking place.

The good folks at GM Ryan International issue a monthly round up of M&A activity in the Media, Ad-Tech and ad world.  There were twenty-four acquisitions in March, pointing to healthy industry activity.

Although low to mid-market M&A activity could be losing a bit of steam this year, as cheap bank financing tightens dictated by fed activity, private equity firms appear to be sitting on capital they raised in the last two years.

The powder is dry.  Let's see what happens during this election year.

Nielsen acquires Pointlogic.
 
Outbrain acquires Revee.
 
Clickable acquires TalkWheel.
 
Merkle acquires Comet Global Consulting.
 
Condé Nast acquires Poetica.
 
SugarCRM acquires Contastic.
 
Rakuten Marketing acquires Manifest Commerce.
 
Sprinklr acquires Postano.
 
Salesforce acquires PredictionIO.
 
Contently acquires Docalytics.
 
Google acquires Pie.
 
ClickTale acquires FlightRecorder.
 
YouTube acquires BandPage.
 
Amazon acquires Emvantage.
 
ASICS acquires RunKeeper.
 
Web.com acquires Yodle.
 
Amazon acquires NICE.
 
Everalbum acquires Pout.
 
Time Inc. acquires Viant.
 
Microsoft acquires Groove.
 
LinkedIn acquires Connectifier.
 
Merkle acquires dbg.
 
Apple acquires LegbaCore.
 
Microsoft acquires SwiftKey.
Posted by Paul Benjou 0 comments Permalink
Labels: Acquisitions, Ad Industry, AdTech, Advertising, GM Ryan, M&A, Mergers













SOCIAL "NOT SO" SECURITY
 
The Internal Revenue Service today issued an alert to payroll and human resources professionals to beware of an emerging phishing email scheme that purports to be from company executives and requests personal information on employees.
 
The IRS has learned this scheme — part of the surge in phishing emails seen this year — already has claimed several victims as payroll and human resources offices mistakenly email payroll data including Forms W-2 that contain Social Security numbers and other personally identifiable information to cybercriminals posing as company executives.

“This is a new twist on an old scheme using the cover of the tax season and W-2 filings to try tricking people into sharing personal data. Now the criminals are focusing their schemes on company payroll departments,” said IRS Commissioner John Koskinen.

“If your CEO appears to be emailing you for a list of company employees, check it out before you respond. Everyone has a responsibility to remain diligent about confirming the identity of people requesting personal information about employees.”

IRS Criminal Investigation already is reviewing several cases in which people have been tricked into sharing SSNs with what turned out to be cybercriminals. Criminals using personal information stolen elsewhere seek to monetize data, including by filing fraudulent tax returns for refunds.

This phishing variation is known as a “spoofing” email. It will contain, for example, the actual name of the company chief executive officer. In this variation, the “CEO” sends an email to a company payroll office employee and requests a list of employees and information including SSNs.

The following are some of the details contained in the e-mails:
  • Kindly send me the individual 2015 W-2 (PDF) and earnings summary of all W-2 of our company staff for a quick review.
  • Can you send me the updated list of employees with full details (Name, Social Security Number, Date of Birth, Home Address, Salary).
  • I want you to send me the list of W-2 copy of employees wage and tax statement for 2015, I need them in PDF file type, you can send it as an attachment. Kindly prepare the lists and email them to me asap.
The IRS recently renewed a wider consumer alert for e-mail schemes after seeing an approximate 400 percent surge in phishing and malware incidents so far this tax season and other reports of scams targeting others in a wider tax community.

The IRS, state tax agencies and tax industry are engaged in a public awareness campaign — Taxes. Security. Together. — to encourage everyone to do more to protect personal, financial and tax data. See IRS.gov/taxessecuritytogether or Publication 4524 for additional steps you can take to protect yourself. 
Posted by Paul Benjou 0 comments Permalink
Labels: Cybersecurity, HR, Human Resources, IRS, Payroll, Social Security, SSN
















WASTE NOT, GROW NOT

What follows is authored by Bob Hoffman. It bears repeating here over and over again. Bob is author of the popular “Ad Contrarian” blog, named one of the world's most influential marketing and advertising blogs by Business Insider.  His recent book, "Marketers Are From Mars, Consumers Are From New Jersey" is a must read (buy it at Amazon). 

There's a restaurant in my neighborhood that's very popular.

You can go there any evening about 7 pm and I can predict with absolute certainty that every table will be occupied and there will be 80 people there. But I can never predict which 80 people it will be.

It's the same with toasters. I can tell you with absolutely certainty that tomorrow there will be 1,500 toasters sold in the United States. But I have no idea who will buy them.

Also tomorrow there will be about 500,000 t-shirts sold (I'm making these numbers up.) But who's going to buy them? No idea.

Marketers used to deal with these uncertainties in a reasonable but wasteful way. We would use experience and knowledge of the market to anticipate the type of person who would be most likely to eat at a restaurant, purchase a toaster, or buy a t-shirt. Then we would direct advertising at these types of people.

Because we used mass media, this media strategy had the disadvantage of being wasteful. Most people we reached would not be in the market for, say, a toaster.

But it also had three advantages: First, we would reach just about everyone who we thought would be looking for a toaster. Second, we reached an awful lot of people who we did not think were interested in a toaster, but were. And third, it reached just about everyone who would someday buy a toaster.

Advertising has changed. Now we believe we can predict exactly who will be buying a toaster tomorrow. We believe we can identify not just the most likely group of people, but the actual individuals.

All we have to do is follow them around the web and find out where they've been, collect the  data and soon we'll know when they're ready for a toaster.

The idea is to make individual targeting so precise that it replaces demographic likelihoods as the basis for media strategy.

So far this has been a spectacular failure. Each of us is currently inundated with dozens, if not hundreds, of online messages a day -- banner ads, emails, social messages, etc -- that are assumed by  marketers to be particularly relevant to us and reflective of our individual purchasing needs and behaviors. We pay almost no attention to any of them. They are essentially invisible.

The math tells the story. A generous number for display advertising is that it generates 8 clicks in 10,000 exposures. A generous number for Twitter interactions is 4 engagements in 10,000. It's hard to get much closer to zero.

We are thinking like direct marketers, not brand marketers. We are ineffectually using "precision targeting" to try to engage the perfect individual, and by eschewing mass media we are harming our brand in three ways.
1. We are not reaching those within our target segment who are not active on line or whose data we haven't mined.
2. We are not reaching the unexpected toaster buyers, of whom there are legions. 
3. We are not building a brand. Mass media advertising may be "wasteful" by the nearsighted standards of digital and direct marketers. However, some very wise people have pointed out that the nature of what we call "waste" may, in fact, be the very stuff that brands are built on.
Think about it this way. In 2002, Apple spent tens of millions of dollars in mass media to advertise the iPod. There were hundreds of millions of people who were exposed to iPod advertising who had absolutely no interest in an iPod. After 14 months, advertising had reached hundreds of millions of people, but Apple had sold 600,000 iPods.

Many marketers would call the enormous amount of money that Apple spent promoting the iPod to the uninterested "waste." But was it?

Today hundreds of millions of people who had no interest in an iPod own iPhones. Isn't it more than likely that the iPod advertising of 2002 had significant impact on the iPhone buyers of 2007 and beyond?
  • Didn't it make the Apple brand more appealing?
  • Didn't it raise interest in mobile devices, particularly Apple mobile devices?
  • Didn't it set the stage for the phenomenal success of Apple in the mobile device category, that made Apple the most successful company on Earth?
Or think about it this way. Why have almost all the brands in your supermarket been built with "wasteful" mass media advertising and none with the "precision targeting" of online advertising?

Understanding business is understanding that markets don't move in straight lines, people don't think in straight lines, advertising doesn't work in straight lines.

If you're a brand marketer and you want to grow, you have two choices. Be wasteful or be invisible.
Posted by Paul Benjou 0 comments Permalink
Labels: Ad Contrarian, Bob Hoffman, Marketing, Type A Group



















FROM A SECURITY PERSPECTIVE, IF YOU'RE CONNECTED, YOU'RE SCREWED

John Brennan, director of the notoriously secretive US Central Intelligence
Agency (CIA) has said that no one is safe from hackers only a few months after his personal email account was breached and the contents leaked online.

"The cyber environment can pose a very, very serious and significant attack vector for our adversaries if they want to take down our infrastructure, if they want to create havoc in transportation systems, if they want to do great damage to our financial networks," he said.

When asked whether other nations have the capability to 'turn off the lights' of the US he said: "I think fortunately right now those who may have the capability do not have the intent. Those who may have the intent right now I believe do not have the capability.
Posted by Paul Benjou 0 comments Permalink
Labels: CIA, Cybersecurity, Email Breach, Hackers












CLOUDY WITH A CHANCE OF HACKING

What do Apple, Amazon and Microsoft have in common? 

The answer: All three technology giants, considered the gold standard among cloud computing providers, have suffered the ignominy of being breached by hackers.

Apple’s “celebgate” incident exposed personal photos of its celebrity iCloud users and made unwelcome news headlines last year. 

UK technology provider Code Spaces was forced out of business last year after hackers tried to blackmail it and subsequently deleted crucial data from its Amazon Web Services-hosted cloud storage. 

In 2013, an expired SSL certificate in Microsoft’s Azure cloud service gave hackers the chance to bring down the Xbox Live and a raft of other cloud-hosted services.

Cloud security risks are rising, with attacks growing at 45% year-on-year globally, according to cloud security firm Alert Logic. In the next five years, $2 billion will be spent by enterprises to shore up their cloud defenses, according to Forrester Research. 

First time cloud users can be most at risk, simply because of unfamiliarity with the new environment and the added burden of having to grapple with a new way of managing users, data and security.
Credit:Rajesh Maurya, Fortinet / Financial Express
Posted by Paul Benjou 0 comments Permalink
Labels: Amazon. Apple, Azure, Cloud Computing, Cloud Services, Forrester, Microsoft, Xbox














HONEY, WHO'S WATCHING THE KIDS?

Security flaws have been discovered in smart toys and kids' watches

 Rapid7 researchers have unearthed serious flaws in two Internet of Things devices:

  • The Fisher-Price Smart Toy, a "stuffed animal" type of toy that can interact with children and can be monitored via a mobile app and WiFi connectivity, and
  • The HereO, a smart GPS toy watch that allows parents to track their children's physical location.

In the first instance, API calls from the toy were not appropriately verified, so an attacker could have sent unauthorized requests and extract information such as customer details, children's profiles, and more.

"Most clearly, the ability for an unauthorized person to gain even basic details about a child (e.g. their name, date of birth, gender, spoken language) is something most parents would be concerned about.



While names and birthdays are nominally non-secret pieces of data, these could be combined later with a more complete profile of the child in order to facilitate social engineering or other malicious campaigns against either the child or the child's caregivers."

In the second instance, the flaw allowed attackers to gain access to the family's group by adding an account to it, which would allow them to access the family member's location, location history, etc.

Rapid7 has been working with the companies to correct the problems.

This further highlights nascence of the Internet of Things with regard to information security. While many clever & useful ideas are constantly being innovated for market segments that may have never even existed before, this agility into consumers's hands must be weighed against the potential risks of the technology's use,

Consumer brands must pay greater attention to application security when building smart devices. When a toy becomes connected to the Internet, a child is exposed to a potentially hostile environment. Regulations have not yet caught-up with the need for good application security.



Excerpt from Help Net Security, authored by Zeijka Zora
Posted by Paul Benjou 0 comments Permalink
Labels: Child Safety. Rapid7, Cybersecurity, Help New Security. Fisher Price, HereO, internet of Things, IoT, Toys











LOOK WHO'S LURKING AT YOUR FRONT DOOR 

Here’s the physical security that the Wi-Fi enabled, Internet of Things Ring smart doorbell gives you:

1) automatic activation and notification on your mobile phone when people come close to your home or loiter around it, and 2) a CCTV camera and high-quality intercom to talk to whomever comes knocking, even if you’re miles away.

Here’s the physical hole it was putting in your Wi-Fi: somebody could easily pop it off your front door (it’s secured with two standard screws), flip it over, retrieve the Wi-Fi password, and Presto! own your network.

To set it up, you have to connect the Ring to your Wi-Fi router, which means that you have to give it the password.The set-up button is connected to a back plate that attaches the doorbell to the wall providing power from an AC source. After you set it up, you attach it to the house with two screws.

If thieves are more interested in intruding into your Wi-Fi network than grabbing a $200 doorbell, they can turn it over and press the setup button, which sets the doorbell’s wireless module and creates an access point that’s simple to connect to.

In sum, an attacker can gain access to a homeowner’s wireless network by unscrewing the Ring, pressing the setup button, and accessing the configuration URL, all without any visible form of tampering..

Pen Test Partners, the company that found the vulnerability, did however, hand out kudos to Ring for responding to the vulnerability alert “within a matter of minutes,” with a firmware update released to fix the issue just two weeks after it was disclosed privately.

Internet of Insecure Things?

From kettles to intruder alarms, baby monitors, and drug pumps, anything that is part of the Internet of Things needs security built in right from the start.


Excerpt from Naked Security by Sophos, LLC  by Lisa Vaas
Posted by Paul Benjou 0 comments Permalink
Labels: Cybersecurity, internet of Things, IoT, Pen Test Partners, Ring, Ring Doorbell


YOUR PAYPAL ACCOUNT IS WORTH $6.43

Online criminals are more interested in getting their hands on stolen Uber, PayPal and even Facebook accounts, than credit card numbers and other personally identifiable information.

 The price of these stolen identifiers on the underground marketplace, or “the Dark Web,” shows the value of credit cards has declined in the last year, according to security firm Trend Micro.

Last week, stolen Uber account information could be found on underground marketplaces for an average of $3.78 per account, while personally identifiable information, such as Social Security Numbers or dates of birth, ranged from $1 to $3.30 on average – down from $4 per record in 2014, reported CNBC.

Furthermore, PayPal accounts – with a guaranteed balance of $500 –were found to have an average selling price of $6.43. Facebook logins sold for an average of $3.02, while Netflix credentials sold for about 76 cents.

By contrast, U.S.-issued credit card information, which is sold in bundles, was listed for no more than 22 cents each,
“It’s an incredible underground ecosystem. There is a high level of competition for these criminal buyers and there are a lot of different types of forums. It’s incredibly diverse, but incredibly mature,”Said Ed Carbera, Trend Micro’s vice president of cyber security strategy.
Cyber criminals will often use stolen Uber credentials to book “ghost rides,” in which they create a fake driver account and charge nonexistent rides to stolen accounts, experts say.
Another way fraudsters leverage this information is to simply build a fuller picture of a victim for identify theft.

“They are doing their own market research or where they can find the data that’s most valuable in the criminal underground and they develop their attacks accordingly,” said Cabrera.

Meanwhile, Forrester research analyst Andras Cser adds these incidents highlight the need of these service providers to be more cognizant of sudden changes in user’s account behavior.

“If a user suddenly takes a cross country ride versus following their usual movements, that should spark an alert,” notes Cser

To address the issue of fraudulent transactions, Uber is reportedly testing its version of two-step authentication, which would require users to enter additional credentials when logging in from an unknown device.

The time has come to move away from passwords.

“Firms should be looking at behavioral biometrics solutions to authenticate users — how the user actually behaves, how they hold a phone, how big their fingers are and how hard they press the touch screen."
Posted by Paul Benjou 0 comments Permalink
Labels: Biometrics, CNBC, Facebook, Forrester, Hackers, Netflix, PayPal, The Dark Web, Trend Micro, Uber
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

About Me

My photo
Paul Benjou
http://about.me/paulbenjou
View my complete profile

More.About.Me

about.me/paulbenjou

Subscribe To My Open Kimono

Posts
Atom
Posts

Berkshire Humane Society

Berkshire Humane Society
Please Donate

TWITTER UPDATES

Twitter Updates

    follow me on Twitter

    Favored Links

    • The Ad Contrarian
    • MediaPost

    Blog Archive

    • ▼  2025 (1)
      • October (1)
    • ►  2023 (1)
      • October (1)
    • ►  2018 (2)
      • April (1)
      • January (1)
    • ►  2017 (1)
      • November (1)
    • ►  2016 (13)
      • March (4)
      • February (4)
      • January (5)
    • ►  2015 (6)
      • September (2)
      • August (3)
      • July (1)
    • ►  2013 (9)
      • April (2)
      • March (3)
      • February (3)
      • January (1)
    • ►  2012 (24)
      • December (1)
      • October (4)
      • August (1)
      • July (2)
      • June (3)
      • May (1)
      • April (4)
      • March (3)
      • February (3)
      • January (2)
    • ►  2011 (34)
      • December (1)
      • November (3)
      • October (3)
      • September (2)
      • August (3)
      • July (2)
      • June (3)
      • May (5)
      • April (7)
      • March (1)
      • February (4)
    • ►  2010 (67)
      • December (1)
      • November (7)
      • October (3)
      • September (5)
      • August (5)
      • July (7)
      • June (6)
      • May (6)
      • April (9)
      • March (6)
      • February (6)
      • January (6)
    • ►  2009 (81)
      • December (6)
      • November (9)
      • October (4)
      • September (8)
      • August (8)
      • July (9)
      • June (7)
      • May (6)
      • April (9)
      • March (7)
      • February (4)
      • January (4)
    • ►  2008 (65)
      • December (6)
      • November (6)
      • October (5)
      • September (7)
      • August (7)
      • July (5)
      • June (4)
      • May (5)
      • April (5)
      • March (6)
      • February (5)
      • January (4)
    • ►  2007 (38)
      • December (3)
      • November (4)
      • October (4)
      • September (5)
      • August (4)
      • July (5)
      • June (5)
      • May (3)
      • April (1)
      • March (1)
      • February (1)
      • January (2)
    • ►  2006 (40)
      • December (2)
      • November (3)
      • October (4)
      • September (4)
      • August (5)
      • July (4)
      • June (5)
      • May (6)
      • April (5)
      • March (2)

    NEWS SOURCES

    • Ad Age
    • Ad Contrarian
    • AdFreak
    • Adweek
    • AP News
    • Bloomberg
    • BusinessWeek
    • CNET News
    • Financial Times
    • Hollywood Reporter
    • Huffington Post
    • Mediapost
    • New York Times
    • NY Times Media
    • Slate
    • Twitter
    • Village Voice
    • Wall Street Journal
    • Washington Post Media
    • Wired

    BlogCatalog

    Marketing Blogs - BlogCatalog Blog Directory
     

    3D CLOUD

    Global Visitors to My Open Kimono

    zoom