LG has been abusing Microsoft's Windows Update infrastructure to push proprietary software onto users' machines without any consent dialog or opt-out mechanism. The software appears to be LG's monitor management utilities, but the delivery vector โ the OS update channel โ crosses a critical trust boundary. Windows Update is designed for OS security patches and driver updates, not third-party application distribution.
This isn't a driver. It's a full application suite being pushed through a channel users trust for security updates. The precedent this sets is deeply concerning.
C-Level Take: This is a supply chain integrity issue. If monitor manufacturers can push software through Windows Update, what stops a compromised update from becoming a distribution vector for malware? Enterprise IT: audit your Windows Update delivery history for non-Microsoft packages. This is the kind of incident that triggers regulatory scrutiny of Microsoft's update infrastructure governance.