惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
B
Blog
L
LangChain Blog
Y
Y Combinator Blog
美团技术团队
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
量子位
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
C
Check Point Blog
D
Docker
小众软件
小众软件
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Nearly Half of Apps Across LG and Samsung TV’S are Sellin...
Abinaya · 2026-06-23 · via Cyber Security News

New research found that 2,058 of 6,038 apps across the LG webOS and Samsung Tizen ecosystems included residential proxy SDKs, effectively turning smart TVs into exit nodes for third-party internet traffic.

On screen, these apps look like harmless fish tanks, clocks, solitaire games, and puppies. However, under the hood, they operate as nodes in commercial residential proxy networks.

Smart TVs are ideal targets because they share home networks with other devices yet receive little security scrutiny, and their always-on nature allows abuse to go unnoticed for years without obvious signs like battery drain or visible background activity.

Spur emphasizes that this changes the consent equation; most users have no practical mental model for what it means to sell access to their residential IP. A single prompt navigated with a remote can disappear into the setup flow while the proxy keeps running indefinitely.

proxy SDK prevalence by smart TV paltform (source :Spur)
proxy SDK prevalence by smart TV platform (source: Spur)

The economic driver is straightforward. Many of these apps are designed to be quiet, ambient, or minimally interactive, where traditional advertising would ruin the experience.

LG & Samsung TV Apps Selling IP Addresses

By embedding a proxy SDK, developers can keep the app looking clean and ad-free while monetizing the TV’s connection in the background. In some cases, this trade-off is made explicit.

Spur highlights a Pac-Man app on Tizen that frames Bright Data’s SDK as the ad-free option; decline, and you keep an ad-supported game; accept, and the app uses your TV’s network connection for web indexing.

This creates a monetization fork where the choice is effectively between watching ads or letting the app turn your IP address into part of a proxy network.

The proxy can keep running after the app is closed, enabling hidden background activity (source :Spur)
The proxy can keep running after the app is closed, enabling hidden background activity (source :Spur)

Spur’s dataset also shows that this is not only a story of independent developers integrating third-party monetization. In many instances, the proxy company itself, or an entity using its name, appears to be the publisher.

Bright Data, Bright Data Ltd, and Bright SDK together account for 367 proxy-flagged apps in the sample. At the same time, Honeygain UAB, a subsidiary of Oxylabs, appears as a publisher on additional apps.

Spur argues that these look less like ordinary apps that happen to embed a monetization SDK and more like first-party proxy inventory: thin games, screensavers, and utilities produced at scale so the SDK has somewhere to run.

Monetization Choice: Watch Ads or Join the Proxy Network (source :Spur)
Monetization Choice: Watch Ads or Join the Proxy Network (source : Spur)

Amazon’s Device and System Abuse Policy explicitly bans apps that facilitate proxy services for third parties, and Roku has reportedly blocked Bright SDK and similar proxy services, with affected apps disappearing from its store after scrutiny.

LG and Samsung, by contrast, have not published equivalent restrictions, leaving a regulatory gap that allows these proxy-enabled apps to proliferate on webOS and Tizen.

Spur warns that once a TV app can act as a proxy, the risk extends beyond someone “borrowing” your public IP.

Because the app runs on the home network, any weakness or change in the proxy provider’s filtering and policy enforcement could turn that TV into a foothold for reaching internal systems such as routers, NAS devices, printers, cameras, and developer machines.

The investigation concludes that smart TV platforms need clear policies for residential proxy SDKs, prominent disclosures, and meaningful user controls.

At the same time, consumers must recognize that even “boring” TV apps can quietly enroll their home networks in commercial proxy infrastructure powered by companies identified in Spur’s research.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.