Fetching from the wire…
Public story · 2026-09-08 · high
The sets also scanned home networks for phones and watches, feeding LG's ad-targeting business.
Why now: As of September 8, LG hadn't commented and the webOS bugs that made the capture possible are still under responsible disclosure.
A joint investigation by Gamers Nexus and Level1Techs used Wireshark to watch what LG's G5 and other OLED TVs send over a home network. With the screen off, the sets logged clean microphone audio in standby. When the network dropped, they cached that audio on the device and uploaded it once the connection came back.
The same packet captures showed the TVs scanning the LAN, pulling internal IP addresses and identifying nearby phones and smartwatches. None of this showed up in a settings menu or a privacy policy, researchers say. It showed up in traffic logs.
LG Ad Solutions sells access to 363 million addressable devices in the US. Phone identifiers and voice audio picked up off a home network are exactly the kind of signal that business runs on.
LG hasn't commented. The webOS remote-code-execution bugs that let researchers get this deep into the TV's behavior are still under responsible disclosure, so there's no patch timeline and no explanation of what happens to the audio after it uploads.
Each link below shares sources, entities, or timing with this story.
Attackers exploited CVE-2026-63077, the critical unauthenticated RCE in TeamCity On-Premises that JetBrains itself disclosed July 27, against an unpatched JetBrains-run server, reaching the Cadence cloud coding service. Because the PyCharm plugin syncs project files to Cadence...
GitHub published four advisories against omnigent-ai/omnigent v0.1.0, the meta-harness that runs Claude Code, Codex and Pi under policy and sandboxing. GHSA-jrrm-9hc7-2v3h at CVSS 9.0 lets any user with session edit rights overwrite a shared template agent via PUT /sessions/{i...
4.5.1, 3.21.10, and @nuxt/devtools 3.3.1 landed July 27. GHSA-279x-mwfv-vcqv is a critical DevTools RCE (development-only), but GHSA-9473-5f9j-94wq is a high-severity server-side RCE via server island props that affects production, alongside a route-rule authorization bypass a...
The Express server on port 3444 calls app.listen with no host argument so it binds all interfaces, sends Access-Control-Allow-Origin: *, requires no auth, and passes the prompt and agentName request-body fields into child_process.spawn with shell: true. Any host on your LAN, o...
SANS ISC honeypot data cited in Adversa's August MCP digest shows roughly 200 requests from 49 distinct source IPs hunting MCP endpoints over fourteen days in July. Spec 2026-07-28 hardened authorization with RFC 9207 issuer validation and header-based policy routing. Two acti...
Researchers from Zhejiang University, NUS, and NTU presented at IEEE S&P demonstrating that imperceptible audio perturbations embedded in podcasts, music, or YouTube videos can trigger AI voice assistants to execute commands: unlocking doors, transferring funds, exfiltrating d...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.