LG spent this week admitting something its customers should never have had to find out from researchers: more than 42 percent of the apps in its webOS smart TV store were quietly turning living room televisions into residential proxy nodes. Someone, somewhere, could route their traffic through your TV without you ever knowing it happened. That’s not a hypothetical. That’s a feature that shipped, got approved, and sat in an official app store until someone went looking. It’s a good reminder that cybersecurity failures rarely start with a dramatic breach. They start with a device nobody thought to interrogate.
This week’s news cycle has three stories that look unrelated on the surface: LG banning proxy apps, a wave of fake GitHub repositories designed to poison AI coding assistants, and researchers confirming that ransomware is accelerating for boring reasons that have nothing to do with artificial intelligence. Put them next to each other and the pattern is obvious. Attackers aren’t getting more sophisticated. They’re getting better at finding the parts of your environment nobody is watching, and they’re patient enough to wait there.
LG’s App Store Turned Your Living Room Into a Proxy Farm
A residential proxy is valuable precisely because it looks legitimate. Traffic coming from a home IP address, on a home ISP, in a real neighborhood, sails past fraud filters and geo-blocks that would flag a data center IP in a heartbeat. That’s why criminal proxy networks pay for access to real consumer devices, and why smart TVs turned out to be such an attractive target. They’re always on, always connected, and almost nobody patches them or watches their outbound traffic.

LG’s fix, banning apps that turn a TV into a proxy node, is the right move. But it’s a reactive one, and it only happened after independent researchers did the work LG’s own app review process should have caught. If a smart TV vendor with a dedicated app store review team missed this for years, assume every other IoT device on your network, cameras, routers, streaming boxes, thermostats, is running software nobody has actually audited.
More than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third parties to route their internet traffic through a user’s TV.
For anyone responsible for a corporate or home network, the lesson isn’t “don’t buy smart TVs.” It’s that consumer IoT devices, guest networks, and BYOD gadgets are exit points you don’t control, and you should treat them that way. Segment them. Don’t let them sit on the same VLAN as anything sensitive.
Your Coding Assistant Just Recommended Malware
The second thread is arguably scarier because it targets the people building software, not just the people watching it. Researchers at Island uncovered roughly 7,600 malicious GitHub repositories tied to about 6,600 accounts, more than 800 of them dressed up as AI Skills or MCP servers. The campaign, dubbed FakeGit, peaked in April 2026 and specifically targeted the workflows developers now trust by default: AI agents pulling in integrations for Gmail, WhatsApp, and other everyday tools.
This matters because developers used to vet dependencies themselves. Now a growing number are letting an AI assistant search, recommend, and sometimes install packages on their behalf, and that assistant has no instinct for “this account was created two weeks ago and has a suspiciously polished README.” It just sees a repo that matches the query and a description that sounds right. Trust used to require a human to skim a changelog. Now it just requires a plausible-sounding name.
Combine that with CrowdStrike’s recent writeup on SANDWORM_MODE and the broader class of AI toolchain supply chain attacks, and a clear trend emerges: attackers have realized that poisoning the recommendation layer is more efficient than attacking any single target. Get a malicious package into an AI agent’s suggested results once, and it can get recommended to hundreds of developers who never independently vetted it.
Ransomware Doesn’t Need AI. It Needs Undefended Networks.
Meanwhile, Dark Reading’s reporting this week undercuts the assumption that ransomware’s growth is being driven by AI-assisted attackers. The real drivers are more mundane: the ransomware ecosystem has fragmented into more, smaller groups, new attackers keep entering, and a growing share of attacks are landing on organizations that were never well defended to begin with, not blue-chip targets with mature security operations.
That’s the throughline connecting all three stories. Nobody needed a breakthrough exploit or a novel AI capability to compromise 42 percent of a smart TV app store, to spin up 7,600 fake GitHub repositories, or to keep ransomware volume climbing. They needed unmonitored surface area and defenders who assumed something was safe because it came from an official store, a familiar platform, or a trusted-looking account.
None of this requires a bigger budget to fix. It requires actually looking at the parts of your environment you’ve been trusting by default:
- Inventory every IoT and smart device on your network, including personal ones on guest Wi-Fi, and put them on a segmented VLAN with no path to sensitive systems.
- Monitor outbound traffic for unusual destinations or volumes from devices that have no business generating them, smart TVs, printers, cameras.
- Require manual review of any package or repository an AI coding assistant recommends before it touches a build pipeline, especially anything under a few months old.
- Enforce brute-force lockouts and rate limiting on every exposed login, not just the ones that feel important, since fragmented ransomware crews are increasingly hitting whatever’s easiest to reach.
- Build threat detection rules around account age, repo provenance, and unusual outbound connections rather than relying solely on signature-based tools.
- Treat incident response planning as something that covers IoT and developer tooling, not just servers and endpoints.
Security hardening in 2026 isn’t about chasing the newest AI-powered threat. It’s defense in depth applied to the boring stuff: the TV in the break room, the repo a teammate cloned last Tuesday, the login page nobody’s rate-limited since it was stood up. Firewalls and threat-protection tools still matter, but only if they’re watching the whole network, not just the parts that feel like they matter.
Sources
- LG to Ban Residential Proxies from Smart TV Apps
- AI agents tricked into recommending malicious GitHub repositories
- Ransomware Is Accelerating, But It’s Not Because of AI
- Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
