AUTO-UPDATED

This Week in Security: Windows 10 Gets Another Year, SmartTV Botnets, Hiding Payloads, and LastPass Customer Leak

A recent analysis reveals that nearly half of the apps on LG smart TVs contain proxy software, while other critical security updates and vulnerabilities impact global technology platforms.

Key Points

  • Researchers found that 50% of LG smart TV apps utilize proxy software, potentially turning devices into network nodes without explicit user consent.
  • Microsoft extended Windows 10 security support until October 2027, requiring some users to sync OneDrive or pay a fee to access updates.
  • Russian hacker groups are targeting Signal users with phishing campaigns designed to steal remote backup authentication tokens from high-profile individuals.
  • Security researcher Sasha Romijn demonstrated that injecting malicious payloads into WiFi SSIDs and TLS certificates can compromise hosting providers and OpenWRT devices.
  • A breach at LastPass marketing partner Klue exposed customer contact information, though the company confirmed that primary password vaults remain secure.
  • New vulnerabilities in Apple AirDrop and Google Quick Share allow nearby attackers to trigger denial-of-service crashes across iOS, macOS, Windows, and Android devices.

Why it Matters

These developments highlight the persistent risks associated with insecure IoT ecosystems and the increasing sophistication of targeted phishing and injection attacks. Users and administrators must remain vigilant, as even trusted services and hardware can serve as entry points for unauthorized data access or system disruption.
Hackaday Published by Mike Kershaw
Read original