Home networks are full of gadgets that outlive their support and quietly collect data. Attackers favor the ones that are easy to reach, rarely updated or tied to a valuable account. Here are ten devices that draw that attention, each paired with the sign an owner can notice.
1. Linksys WRT54G: Frozen In Time

The FBI’s IC3 advisory puts the risk in a single line: once a router is end of life, the maker is no longer releasing software updates or security patches. This blue-and-black box has been discontinued for a very long time, and plenty of examples still serve Wi-Fi in American homes.
The tell is the label on the box itself. A model that stopped receiving updates years ago belongs in the advisory’s category no matter how reliably it still works, and a router that appears to run perfectly can be the very one that criminals prefer to borrow for their own traffic.
2. AirPort Extreme: Retired Base Station

Apple left the router business years ago, which places its AirPort Extreme base station squarely in the IC3 category: hardware the manufacturer no longer actively supports or patches. The unit often sits on a shelf or desk and keeps working, so nothing prompts an owner to question it.
The tell is the missing maker. When the company behind a device has exited the product line, security fixes stop arriving, and the unit’s quiet reliability becomes part of the problem. Replacement, rather than a settings tweak, is the sensible answer for any router in that position.
3. AirPort Express: Small White Extender

The small white plug-in sibling of the base station is still used as a Wi-Fi extender and an AirPlay box long after support ended. That is the exact profile the FBI warns criminal proxy networks hunt for: older equipment, still connected, with no maker issuing fixes for it.
Its size works against it, because a unit tucked behind furniture or plugged into a hallway outlet is easy to forget entirely. Nobody checks a device they never see, and the tell here is simply age: gear that has outlived its support deserves an owner’s attention before it draws anyone else’s.
4. Cable modem: Warning Signs Listed

The FBI advisory also names what an owner should look for on any of this gear, in its own words: overheating devices, problems with connectivity, and changes to settings the administrator does not recognize. A cable modem sits at the front door of the whole home network, so those signs matter there as much as on any router.
The tell is a change that nobody made. A box running hot, dropping connections or showing configuration entries that no household member recalls is behaving differently from the day it was installed. Any of those signs justifies checking the device, and an unexplained settings change is the clearest of the three.
5. Amazon Echo: Voice History Trail

The Echo smart speaker sends voice requests to Amazon’s servers, and the recordings stay in the Alexa app’s voice history until somebody deletes them. That makes the account behind the speaker the more valuable target, since the history holds a running record of what was said in the room.
The tell is already on a phone screen. Opening the voice-history section shows exactly what the speaker has kept, and anything there that a household member does not recall asking is worth noticing. Reviewing and clearing that list is an ordinary habit, and it shrinks what a stolen login could expose.
6. Chromecast: Open To The Network

The Chromecast dongle accepts cast commands from anything on the same Wi-Fi, so anyone who reaches that network, or an exposed port, can put video on the television. Its convenience comes from being open to nearby devices, and that same openness is what makes it a tempting nuisance target.
The tell is a screen that changes without anybody pressing a button. A video that starts on its own, or a stream nobody chose, suggests that something else on the network has taken control. A guest who joined the Wi-Fi is a more common explanation than a stranger, but either way the network deserves a look.
7. Roku: Watching The Watcher

Roku’s streaming players and televisions collect information about what gets watched, and that data feeds advertising. The setting worth examining is the one governing this tracking, rather than anything on the remote control or the screen. The exposure here is mostly about data collection, not about an intruder taking over the hardware.
The tell is the privacy menu. Few owners open it after setup, so the defaults tend to stay in place for years. A quick visit shows what the device is permitted to gather and share, and changing it takes only a few moments with the remote in hand.
8. Roomba: Floor Plan Collector

A mapping robot vacuum builds and stores a floor plan of the inside of the house, which is a different class of data from a camera pointed at a doorstep. Roomba models that map are not simply cleaning machines; they hold a layout of rooms, furniture and routes that the household never set out to record.
The tell is the map in the companion app. Its detail shows how much the vacuum has learned about the home, and the account holding it is the real prize. Deleting saved maps, and protecting the login with a strong password, limits what a breach of that account could reveal.
9. Ring Video Doorbell: Account Over Hardware

The Ring doorbell uploads its clips to the cloud instead of keeping them on the device, so the account, not the hardware on the door frame, is what an attacker wants. A person who gets into that login can see footage without ever going near the house.
The tell lives in the app rather than on the door. An unfamiliar login, an unknown device in the account’s list or a notification that nobody expected points to someone else holding the credentials. Because the weakness sits in the account, a strong, unique password and a second sign-in step matter more than the camera’s position.
10. Baby monitor: Nursery Weak Spot

Internet-connected baby monitors are reachable from outside the house by design, which is why the default password on the camera is the single most consequential setting in the nursery. A camera left on its factory login can be found and viewed by strangers, a long-running concern with this device category.
The tell is an unexpected movement. A lens that turns on its own, a light that switches on or an unfamiliar voice from the speaker suggests someone else is connected. Changing the factory password at setup, and checking the app for unknown viewers, addresses the weakness that matters most.
More from Morning Overview
- NTSB report details how a family of four died when their plane’s nose suddenly pitched up
- Doctors warn a silent liver disease now affects one in three American adults
- Common allergy, bladder and sleep pills tied to sharply higher dementia odds
- The second-largest U.S. reservoir just fell to its lowest level ever recorded