Your Menstrual Tracker Could Be Monitoring You

Your Menstrual Tracker Could Be Monitoring You

Hours of San Francisco Police Department drone video footage made public online reveals a new phase of exceedingly detailed—and impactful—urban surveillance. In parallel, the San Francisco City Attorney’s Office issued cease-and-desist notices to Apple and Google this week, demanding the tech giants remove 13 AI nudifying “face-swap” applications from their app stores that predominantly target women and girls.

Since WIRED initially reported in June on Meta’s NameTag facial recognition feature, company leaders have provided unclear and contradictory statements regarding its existence. We stepped back to clarify both the claims and the actual facts surrounding this very real system.

In a presentation on Thursday, President Donald Trump persisted in promoting unverified and thoroughly discredited claims of interference in the 2020 US election. He even promised significant revelations in a collection of documents uploaded to the White House website, but the documents did not support his claims—and in some instances directly undermined Trump’s assertions.

As the use of AI tools rapidly grows and their functions enhance, the tech giant Anthropic has continued its efforts to encourage US states to impose regulations on AI. Commenting on AI transparency requirements established in California and New York last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, expressed to WIRED this week, “The transparency-oriented safety legislation of 2025 was an important initial step, but as AI systems’ capabilities advance rapidly, policy reactions must keep pace.”

And there’s additional news. Each week, we compile the security and privacy updates we haven’t examined in-depth ourselves. Click the headlines to access the complete stories. And remain cautious out there.

The astrology-themed period tracker Stardust transmits users’ reproductive health information—birth control type, pregnancy status, moods, and specific symptoms like tender breasts and stomach cramps—to a data firm not specified in its privacy policy, according to the BBC, which first disclosed a Mozilla Foundation review of six popular trackers conducted in collaboration with Harvard’s Berkman Klein Center.

Stardust received a score of 2 out of 10, the lowest among the options. Mozilla researcher Shoshana Wodinsky discovered that the app connects with third-party trackers as soon as it opens, prior to any user input; upon logging a symptom, the details were sent to analytics firm RudderStack alongside a persistent user ID, with no option within the app to disable this data sharing. RudderStack is designed to direct data to destinations that Mozilla could not monitor. Stardust also provides Facebook with an ad identifier linking in-app activities to the platform’s existing profiles. The company informed TechCrunch that it has never been compelled to comply with a legal demand for user data.

Euki, a nonprofit-operated tracker, achieved a perfect score of 10: no account required, health information remains on the phone, and users can establish a PIN, organize automatic deletion, or display a decoy screen if someone attempts to force access to the phone. Its sole vulnerability is an in-app browser for educational content that loads the standard web trackers, but it resets identifiers after each visit.

Russia’s FSB has historically been recognized for its highly advanced cyber-espionage tactics, leaving disruptive cyber-attacks to its counterparts in the GRU military intelligence agency. However, sanctions from the EU and UK this week, along with advisories from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, attributed a cyberattack against the Polish electric grid to Center 16 of the FSB, marking a rare instance of the Kremlin agency executing a cyberattack that nearly resulted in outages in the country’s electricity and water services. The attack, which Polish officials stated came “very close” to causing a blackout, was originally linked by cybersecurity firms Dragos and ESET to Sandworm, also known as Unit 74455 of the GRU, a more common suspect in infrastructure breaches due to its active involvement in Russia’s ongoing cyberwar against Ukraine. However, the Polish computer emergency response team at the time disputed that attribution and linked the attack to the FSB, a conclusion now backed by a broad consensus among Western governments. The event implies that the FSB may be adopting some of the reckless, highly aggressive behaviors—and targeting—characteristic of its GRU colleagues.

For years, the Russian cybersecurity firm Kaspersky has been alleged to possess connections to the Russian government, as suggested by US officials who prohibited the use of the company’s products within the US government and subsequently by all American clients. Yet tangible proof of those ties has been limited. Now Reuters reveals that Denis Obrezko, a Russian individual facing hacking allegations in Boston and purported member of a hacker group named Void Blizzard or Laundry Bear, worked at Kaspersky for two years. His tenure at the company preceded his employment at another cybersecurity firm, Yutek-NN, where he allegedly participated in the group’s hacking operation that compromised data and communications from multiple NATO nations and at least 11 US firms, according to US prosecutors.

CISA Calls on US Agencies to Tackle Security Vulnerabilities Within 3 Days in Light of AI Threats

CISA Calls on US Agencies to Tackle Security Vulnerabilities Within 3 Days in Light of AI Threats

With the rise of new AI models facilitating swift software vulnerability identification and possible misuse by cybercriminals, the US Cybersecurity and Infrastructure Security Agency (CISA) released a directive on Wednesday requiring quicker software patch implementation for federal agencies. This directive provides a timeline for bug fixes based on priority, demanding a three-day response for critical issues.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, highlighted the necessity of prioritizing high-risk vulnerabilities. This directive is framed within ongoing efforts from both private and public sectors to evaluate the implications of AI-enhanced cybersecurity threats.

“Prioritizing vulnerable assets is essential at this time due to AI developments empowering threat actors to locate and exploit weaknesses,” Butera remarked. He underscored the urgency of prompt patching to avert widespread automated exploitation.

The guidelines for patch prioritization consider factors such as public visibility of a system, inclusion in CISA’s Known Exploited Vulnerabilities Catalog, automation of exploit techniques, and the extent of access obtainable if exploited. Vulnerabilities that fit all criteria must be resolved within three days, alongside a forensic assessment to ascertain any system breaches.

This directive supersedes earlier CISA directives from 2019 and 2021 that established a protocol for addressing critical bugs within 15 days and other issues within 30 days. CISA has previously observed how quickly threat actors capitalize on vulnerabilities, frequently on the day they are revealed.

Although there have been notable advancements in federal cybersecurity, challenges like funding and priorities can sometimes lead to delays. Butera clarified that the directive was crafted considering these obstacles, establishing feasible timelines.

Advancements in AI are transforming the vulnerability detection arena, necessitating more rapid patching. Nevertheless, researchers indicate a need for systemic strategies to eliminate categories of vulnerabilities. Emily Long, CEO of Edera, stated, “CISA’s directive only tackles part of the issue,” stressing the importance of frameworks that restrict attacker access following a breach.

Butera acknowledged, “The directive initially mitigates AI capabilities, but additional efforts are essential.”