Your LG TV is spying on you, even with no internet connection.
According to @GamersNexus, LG Smart TVs can scan local networks, identify content, and record/transcribe audio in standby.
They also found webOS flaws that could enable remote code execution. https://t.co/3m6sklywkj
Switzerland's great migration away from US Tech begins. 🎉🇨🇭
The Swiss Federal Government has launched its pilot program aiming to replace MS 365 on 3,000 workstations with openDesk, a German open source alternative.
The Swiss are taking a step in the right direction, to achieve #DigitalSovereignty and control of their digital infrastructure.
Find out which other European countries are taking steps to distance themselves from US tech: https://t.co/dXAy3vQFTq
‼️ Microsoft Paint and Photos embed GUIDs as invisible watermarks in locally generated AI images. Even though you are using 'local AI', both apps send your prompt to Microsoft's servers, which moderate it and return a unique identifier that gets baked into the image.
‼️ Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Alibaba's anti-abuse scripts use a fingerprinting technique with a hidden audio graph on the homepage — a sawtooth tone pushed through the browser's audio engine, then measured on the way out. CPU, OS and browser each process it slightly differently, and that variation results in a fingerprint they can track you with.
Gain is set to zero, so nothing is audible. But the audio graph stays wired to the system audio output, so the browser keeps processing live audio. Tab mute can't stop it, there's no media element to mute.
Some browsers like Firefox have already flattened the fingerprint itself. For example 99.24% of Firefox users return one of just three values. It doesn't stop the audio graph from running though.
⚠️ Android car head units are getting malware through built-in updaters.
Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Full details: https://t.co/Ni0SgNldLm
🚨 Watch out: Attackers are exploiting VMware vCenter for persistence.
After exploiting CVE-2026-59310, they planted a malicious cron job running reverse_ssh to maintain access. Researchers identified up to 361 victim IPs across 47 countries.
Read more: https://t.co/lcWSQUy1Qx
‼️ New research shows passkey protections can be bypassed without breaking FIDO2 cryptography.
Three demonstrated paths:
• Replay Windows-exposed assertions against Entra ID
• Recover synced passkey private keys from Google Password Manager
• Use Windows Hello keys from a compromised session
See how each works: https://t.co/LuV6SQccEs
🚨 Malicious VS Code extensions steal wallet data and developer secrets.
Solidity Pro targets crypto wallet vaults, API keys, SSH keys, and source-control tokens. Some versions wait hours or days before activating, after quick automated scans have already moved on.
Read: https://t.co/1KLv2HyQJm
"The log partition size on this vCenter Server is smaller than the recommended 50 GB", increase the disk space of /storage/log to 50GB on vCenter 8.0 https://t.co/OtMXZAWFTI
vcf-security-and-compliance-guidelines/security-advisories/vmsa-2026-0006 at main · vmware/vcf-security-and-compliance-guidelines · GitHub https://t.co/BUNTi7xjhL