Hours of San Francisco Police Department drone video footage made public online reveals a new phase of exceedingly detailed—and impactful—urban surveillance. In parallel, the San Francisco City Attorney’s Office issued cease-and-desist notices to Apple and Google this week, demanding the tech giants remove 13 AI nudifying “face-swap” applications from their app stores that predominantly target women and girls.
Since WIRED initially reported in June on Meta’s NameTag facial recognition feature, company leaders have provided unclear and contradictory statements regarding its existence. We stepped back to clarify both the claims and the actual facts surrounding this very real system.
In a presentation on Thursday, President Donald Trump persisted in promoting unverified and thoroughly discredited claims of interference in the 2020 US election. He even promised significant revelations in a collection of documents uploaded to the White House website, but the documents did not support his claims—and in some instances directly undermined Trump’s assertions.
As the use of AI tools rapidly grows and their functions enhance, the tech giant Anthropic has continued its efforts to encourage US states to impose regulations on AI. Commenting on AI transparency requirements established in California and New York last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, expressed to WIRED this week, “The transparency-oriented safety legislation of 2025 was an important initial step, but as AI systems’ capabilities advance rapidly, policy reactions must keep pace.”
And there’s additional news. Each week, we compile the security and privacy updates we haven’t examined in-depth ourselves. Click the headlines to access the complete stories. And remain cautious out there.
The astrology-themed period tracker Stardust transmits users’ reproductive health information—birth control type, pregnancy status, moods, and specific symptoms like tender breasts and stomach cramps—to a data firm not specified in its privacy policy, according to the BBC, which first disclosed a Mozilla Foundation review of six popular trackers conducted in collaboration with Harvard’s Berkman Klein Center.
Stardust received a score of 2 out of 10, the lowest among the options. Mozilla researcher Shoshana Wodinsky discovered that the app connects with third-party trackers as soon as it opens, prior to any user input; upon logging a symptom, the details were sent to analytics firm RudderStack alongside a persistent user ID, with no option within the app to disable this data sharing. RudderStack is designed to direct data to destinations that Mozilla could not monitor. Stardust also provides Facebook with an ad identifier linking in-app activities to the platform’s existing profiles. The company informed TechCrunch that it has never been compelled to comply with a legal demand for user data.
Euki, a nonprofit-operated tracker, achieved a perfect score of 10: no account required, health information remains on the phone, and users can establish a PIN, organize automatic deletion, or display a decoy screen if someone attempts to force access to the phone. Its sole vulnerability is an in-app browser for educational content that loads the standard web trackers, but it resets identifiers after each visit.
Russia’s FSB has historically been recognized for its highly advanced cyber-espionage tactics, leaving disruptive cyber-attacks to its counterparts in the GRU military intelligence agency. However, sanctions from the EU and UK this week, along with advisories from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, attributed a cyberattack against the Polish electric grid to Center 16 of the FSB, marking a rare instance of the Kremlin agency executing a cyberattack that nearly resulted in outages in the country’s electricity and water services. The attack, which Polish officials stated came “very close” to causing a blackout, was originally linked by cybersecurity firms Dragos and ESET to Sandworm, also known as Unit 74455 of the GRU, a more common suspect in infrastructure breaches due to its active involvement in Russia’s ongoing cyberwar against Ukraine. However, the Polish computer emergency response team at the time disputed that attribution and linked the attack to the FSB, a conclusion now backed by a broad consensus among Western governments. The event implies that the FSB may be adopting some of the reckless, highly aggressive behaviors—and targeting—characteristic of its GRU colleagues.
For years, the Russian cybersecurity firm Kaspersky has been alleged to possess connections to the Russian government, as suggested by US officials who prohibited the use of the company’s products within the US government and subsequently by all American clients. Yet tangible proof of those ties has been limited. Now Reuters reveals that Denis Obrezko, a Russian individual facing hacking allegations in Boston and purported member of a hacker group named Void Blizzard or Laundry Bear, worked at Kaspersky for two years. His tenure at the company preceded his employment at another cybersecurity firm, Yutek-NN, where he allegedly participated in the group’s hacking operation that compromised data and communications from multiple NATO nations and at least 11 US firms, according to US prosecutors.
