Hi everyone,

This week on Shared Security, we start with a story that sounds like a parody of modern tech: someone connects a new LG monitor, Windows automatically pulls down a vendor companion app, and the app immediately shows a McAfee ad.

Funny? A little. Annoying? Absolutely. But the bigger issue is that hardware setup has become a software delivery channel. What used to be “install the driver so the device works” has evolved into companion suites, startup apps, telemetry, promotions, trial-ware, and security-product upsells that users often did not knowingly ask for.

We also connect this to a Krebs on Security report about LG smart TV apps being used as residential proxy nodes. That takes the conversation beyond popups and into a bigger question: if your TV, monitor, printer, keyboard, and streaming box are all software platforms, how much visibility do you actually have into what they are doing?

The practical takeaway: after connecting new hardware, review what got installed, check startup apps, uninstall vendor utilities you do not need, and keep smart TVs or other embedded devices segmented away from the laptops and phones you use for sensitive work.

Quote from this week’s episode

Who gets to put software on your computer just because you connected a piece of hardware?
— Tom Eston

Tom’s take

What bothers me about this story is not just the McAfee ad. It is the way “hardware setup” has become a trusted path for software most people never really chose. Convenience is useful, but it should not become a blank check for vendor utilities, ads, telemetry, and startup apps.

Also worth your attention this week

  • Best-funded companies open the most phishing attachments. A new phishing-simulation benchmark is a useful security-awareness reality check: bigger budgets and more tooling do not automatically mean better human resilience. The takeaway for readers is to combine realistic training with safer defaults, fast reporting paths, and reduced blast radius when someone clicks. Source: Help Net Security — https://www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/

  • Chick-fil-A credential stuffing. A mainstream brand account-takeover story is a good reminder that password reuse still turns old breaches into current account compromise. Readers should use unique passwords, enable MFA or passkeys where available, and check stored payment cards and loyalty/reward balances. Source: SecurityWeek — https://www.securityweek.com/chick-fil-a-accounts-get-fried-in-credential-stuffing-attack/

  • Data broker rules are changing, but your rights depend on where you live. The Future of Privacy Forum’s data-broker regulatory brief is a concise policy backgrounder for why deletion, opt-out, registry, and sensitive-data protections vary so much by state. Useful reader angle: data-broker privacy is getting more attention, but it is still fragmented and location-dependent. Source: Future of Privacy Forum — https://fpf.org/blog/fpf-releases-new-issue-brief-on-u-s-data-broker-regulatory-landscape/

Listen / Watch

▶️ YouTube Version: https://youtu.be/E-lsZbkbmI8

We’d love your feedback

Have you had hardware install surprise software, ads, or vendor utilities you did not want? Drop a comment on YouTube or send us a note — we would love to hear what you have seen and how you handled it.

Thank you to our sponsors!

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT! Visit: https://slnt.com and use discount code "sharedsecurity" at checkout.

Closing

If you found this episode useful, subscribe to Shared Security, share it with someone who is tired of smart-device nonsense, and consider supporting the show through YouTube channel membership or by following us wherever you get your podcasts..

Stay safe, stay secure, and stay private.

Tom Eston
Founder and Host, Shared Security Podcast