BERLIN - Security researchers have uncovered a critical flaw in Linux-based Lenovo webcams that enables attackers to deploy a BadUSB payload remotely, transforming the camera into a keystroke injector, a phishing hub, or - in one unsettling proof-of-concept — a karaoke machine. The root of the problem lies in a neglected firmware update channel that accepts unsigned instructions without verification. Once compromised, the webcam can masquerade as a USB keyboard, execute malicious commands, or, as demonstrated at last week’s DEF CON, belt out an off-key rendition of “Sweet Caroline” mid-video call. While the novelty of a hijacked webcam crooning Neil Diamond might elicit laughter, experts warn the exploit’s true potential is far more dangerous. Attackers could harvest...