Your Menstrual Tracker Could Be Monitoring You

Your Menstrual Tracker Could Be Monitoring You

Hours of San Francisco Police Department drone video footage made public online reveals a new phase of exceedingly detailed—and impactful—urban surveillance. In parallel, the San Francisco City Attorney’s Office issued cease-and-desist notices to Apple and Google this week, demanding the tech giants remove 13 AI nudifying “face-swap” applications from their app stores that predominantly target women and girls.

Since WIRED initially reported in June on Meta’s NameTag facial recognition feature, company leaders have provided unclear and contradictory statements regarding its existence. We stepped back to clarify both the claims and the actual facts surrounding this very real system.

In a presentation on Thursday, President Donald Trump persisted in promoting unverified and thoroughly discredited claims of interference in the 2020 US election. He even promised significant revelations in a collection of documents uploaded to the White House website, but the documents did not support his claims—and in some instances directly undermined Trump’s assertions.

As the use of AI tools rapidly grows and their functions enhance, the tech giant Anthropic has continued its efforts to encourage US states to impose regulations on AI. Commenting on AI transparency requirements established in California and New York last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, expressed to WIRED this week, “The transparency-oriented safety legislation of 2025 was an important initial step, but as AI systems’ capabilities advance rapidly, policy reactions must keep pace.”

And there’s additional news. Each week, we compile the security and privacy updates we haven’t examined in-depth ourselves. Click the headlines to access the complete stories. And remain cautious out there.

The astrology-themed period tracker Stardust transmits users’ reproductive health information—birth control type, pregnancy status, moods, and specific symptoms like tender breasts and stomach cramps—to a data firm not specified in its privacy policy, according to the BBC, which first disclosed a Mozilla Foundation review of six popular trackers conducted in collaboration with Harvard’s Berkman Klein Center.

Stardust received a score of 2 out of 10, the lowest among the options. Mozilla researcher Shoshana Wodinsky discovered that the app connects with third-party trackers as soon as it opens, prior to any user input; upon logging a symptom, the details were sent to analytics firm RudderStack alongside a persistent user ID, with no option within the app to disable this data sharing. RudderStack is designed to direct data to destinations that Mozilla could not monitor. Stardust also provides Facebook with an ad identifier linking in-app activities to the platform’s existing profiles. The company informed TechCrunch that it has never been compelled to comply with a legal demand for user data.

Euki, a nonprofit-operated tracker, achieved a perfect score of 10: no account required, health information remains on the phone, and users can establish a PIN, organize automatic deletion, or display a decoy screen if someone attempts to force access to the phone. Its sole vulnerability is an in-app browser for educational content that loads the standard web trackers, but it resets identifiers after each visit.

Russia’s FSB has historically been recognized for its highly advanced cyber-espionage tactics, leaving disruptive cyber-attacks to its counterparts in the GRU military intelligence agency. However, sanctions from the EU and UK this week, along with advisories from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, attributed a cyberattack against the Polish electric grid to Center 16 of the FSB, marking a rare instance of the Kremlin agency executing a cyberattack that nearly resulted in outages in the country’s electricity and water services. The attack, which Polish officials stated came “very close” to causing a blackout, was originally linked by cybersecurity firms Dragos and ESET to Sandworm, also known as Unit 74455 of the GRU, a more common suspect in infrastructure breaches due to its active involvement in Russia’s ongoing cyberwar against Ukraine. However, the Polish computer emergency response team at the time disputed that attribution and linked the attack to the FSB, a conclusion now backed by a broad consensus among Western governments. The event implies that the FSB may be adopting some of the reckless, highly aggressive behaviors—and targeting—characteristic of its GRU colleagues.

For years, the Russian cybersecurity firm Kaspersky has been alleged to possess connections to the Russian government, as suggested by US officials who prohibited the use of the company’s products within the US government and subsequently by all American clients. Yet tangible proof of those ties has been limited. Now Reuters reveals that Denis Obrezko, a Russian individual facing hacking allegations in Boston and purported member of a hacker group named Void Blizzard or Laundry Bear, worked at Kaspersky for two years. His tenure at the company preceded his employment at another cybersecurity firm, Yutek-NN, where he allegedly participated in the group’s hacking operation that compromised data and communications from multiple NATO nations and at least 11 US firms, according to US prosecutors.

Leading Motion Detectors and Camera-Free Domestic Safety Devices

Leading Motion Detectors and Camera-Free Domestic Safety Devices

Kini consistently excels as a dependable monitoring tool. It accurately senses when drawers and cabinets are opened and offers notifications even with logging turned off. The log captures timestamps, yet the manufacturer, Kinisium, assures users that no data is compiled. Kini’s Stasis mode aids in monitoring inactivity, which is beneficial for overseeing medication access or recording when someone enters a space. IFTTT compatibility enables automation, and a webhook function permits alerting custom URLs.

When evaluating motion sensors, the Eve Motion Sensor is notable, although incorporating it into alert systems necessitates a smart hub and automation configuration. It is dependable for both indoor and outdoor settings.

Aqara presents the FP2 Presence Sensor, which can identify zones and multiple individuals. While it is generally precise, it may find it challenging to count persons accurately. Its more economical alternative, the FP300, also offers presence recognition along with monitoring light, temperature, and humidity.

The Switchbot Presence Sensor is an affordable choice but needs a hub for alert functions and experiences a slight delay upon detection.

For external applications, the Philips Hue Outdoor Motion Sensor seamlessly integrates with existing Hue systems, delivering effective detection with few false alerts. It can be configured to initiate notifications and actions during particular times, enhancing security. For indoor uses, the Philips Hue Indoor Motion Sensor and Contact Sensor provide reliability and customizable alert triggers.

Smart lighting systems present another option for motion detection. The Wiz SpaceSense utilizes Wi-Fi, though its performance relies on light positioning. Similar to SpaceSense, Philips Hue’s MotionAware employs Zigbee, requiring a subscription for alerts, yet activates lights without additional costs.

For more cohesive solutions, modular security systems such as SimpliSafe, ADT, Vivint, Eufy, and Arlo offer extensive setups with various sensors to customize home security according to individual requirements.

How to Secure Your Username on WhatsApp as They Will Be Available Soon

How to Secure Your Username on WhatsApp as They Will Be Available Soon

WhatsApp is poised to launch a highly awaited feature this year: usernames. With over 3 billion users, the messaging platform aims to provide a more privacy-oriented way for individuals to connect without needing to disclose their phone numbers. Username reservations will begin this week, and users will receive notifications within the app when the feature becomes available. You can check your app under Settings, then Account, and look for the Username tab if it is enabled. Options include creating a new username or importing one from Instagram or Facebook. WhatsApp offers a username generator, but you can select whatever suits you best.

As stated by Alice Newton-Rex, WhatsApp’s vice president of Product, “Usernames are intended to give you control over who can see your phone number in the first place.” This optional feature enables you to choose and modify your username without aligning it with other account handles. Crafted with privacy in consideration, there is no public list of usernames available for search. Users can enhance their security by requiring a unique four-digit key for access to their contacts.

These usernames are optional, yet Newton-Rex predicts that a significant number of users will embrace this privacy-centric feature. While comparable to competitors, Newton-Rex notes that “Signal usernames are probably a good comparison,” implying that WhatsApp’s strategy parallels theirs. Signal launched usernames in 2024, and various messaging apps continue to investigate connection methods that do not rely on phone numbers, such as Germ DM’s “burner cards” for diverse group connections.

Vital Details Regarding the US Prohibition on Routers Manufactured Abroad

Vital Details Regarding the US Prohibition on Routers Manufactured Abroad

In March, the Federal Communications Commission prohibited the introduction of new consumer internet routers manufactured outside the US, referencing national security issues. Current routers in American residences or presently available for purchase remain unaffected, but all newly crafted consumer routers require approval. Manufacturers can seek exceptions, and some have been authorized, meaning there’s no necessity to dispose of your existing router, and numerous mesh systems are still purchasable in stores.

Updated May 2026: Further details on software and component modifications, the inclusion of mobile hotspots in the ban, and Conditional Approval granted to certain firms are provided.

Why Are Routers Made Abroad Prohibited?

The FCC indicated that malicious entities have taken advantage of security vulnerabilities in routers made abroad to target American households, disrupt networks, facilitate espionage, and promote intellectual property infringement. Routers that are foreign-made played a role in the Volt, Flax, and Salt Typhoon cyberattacks, which focused on crucial US infrastructure. These routers are included on the Covered List, representing an unacceptable threat to US national security. As noted by Bogdan Botezatu, director of Threat Research at Bitdefender, the prohibition aims to bolster cybersecurity in US homes amidst geopolitical tensions, emphasizing that consumer routers represent a strategic risk if compromised on a broad scale. He states that Internet of Things devices, including routers, are a vulnerability across the internet.

Which Routers Are Prohibited?

The prohibition solely targets the sale of new Wi-Fi routers and mobile Wi-Fi or hotspot devices aimed at consumers, excluding existing FCC-approved routers or phones with hotspot functionalities. Previously acquired routers are not impacted and can be sold, utilized, and updated until March 1, 2027. Any new router produced outside the US must receive FCC approval before being brought in, marketed, or sold within the US, affecting US firms with overseas production.

What Does Foreign-Made Entail?

The prohibition pertains to “consumer-grade” routers designed or produced outside of the US or by companies not owned by US entities. Key players like Netgear, TP-Link, Asus, Amazon’s Eero, Google’s Nest, Synology, Linksys, and Ubiquiti fall into this category, as do most routers provided by internet service providers in the US. Manufacturers can request Conditional Approval from the Department of Defense and the Department of Homeland Security.

What is Conditional Approval?

To obtain Conditional Approval, companies are required to disclose their corporate structure, provide details on the manufacturing and supply chain, and outline a US manufacturing and onshoring strategy. This facilitates the ongoing sales and updates for both existing and new devices for a period of 18 months, which includes firmware updates, superseding the March 1, 2027, firmware waiver deadline. New devices will still undergo the standard FCC approval procedure.

Companies With Conditional Approval

Three companies have been granted Conditional Approval: Netgear, Adtran, and Eero, with permissions extending until October 2027. The Department of Defense, Homeland Security, and FCC have not clarified the reasons for these companies receiving approvals. The Consumer Technology Association (CTA) has requested clearer guidelines, raising concerns about software updates and component modifications.

What About Software Updates?

The FCC waiver permits all authorized routers to access software and firmware updates until March 1, 2027. After this date, it is uncertain what will occur should companies not secure Conditional Approval. Joshua Marpet from Finite State points out that routers that cease to receive updates present security hazards. Older devices frequently involved in cyberattacks typically do not receive further updates.

What About Components Made Abroad?

The international supply chain often faces component substitutions in routers, prompting worries. The CTA has advocated for additional waivers where security is not significantly compromised. The FCC clarified that a router manufactured in the US is not classified as ‘covered’ due to foreign components unless the component is a modular transmitter. Companies must demonstrate non-foreign production without precise regulations for documentation.

Netgear Has Approval

Netgear disclosed its Conditional Approval through a letter from the CEO. Although based in the US, its routers are produced in countries like Vietnam and Taiwan. The company has advocated for enhancing US cybersecurity and strategic competition with China. Netgear’s stock saw an increase following the announcement of the ban.

Will TP-Link Be Banned?

TP-Link, holding an estimated 35% of the US market share, must seek Conditional Approval or establish US manufacturing to market new routers. Investigations by US agencies and a lawsuit by the Texas attorney general highlight concerns regarding TP-Link’s connections to China. TP-Link asserts that it is headquartered in the US and manufactures in Vietnam, with its CEO applying for Trump’s Gold Card program for residency.

Will Asus Be Banned?

Asus mainly manufactures routers in Taiwan and China and must pursue Conditional Approval for new router sales. The ban has not influenced its stock price on the Taiwanese Stock Exchange.

Are Any Routers Manufactured in the US?

Some Starlink Wi-Fi routers, part of Elon Musk’s SpaceX operations, are created in Texas, although many components originate from East Asia. The security framework is considered more crucial than the manufacturing site.

How Will the Router Ban Impact Ordinary Folks?

The immediate consequence may be minimal, with numerous

Elon Musk's XChat App Looks More Like Facebook's Messenger Than Signal

Elon Musk’s XChat App Looks More Like Facebook’s Messenger Than Signal

Elon Musk utilized Friday to share critiques of rivals after the debut of the XChat app, a standalone messaging service for X users. “Signal, WhatsApp, Telegram, and iMessage all have significant security issues,” stated a message Musk shared, asserting that “XChat is the sole secure, encrypted messaging application.” Encryption specialists I consulted voiced measured skepticism regarding XChat’s implementation and supported other platforms like Signal.

A primary worry concerning XChat is that users are required to link an existing X account for login. “I’m somewhat wary of that since more data points equate to more tracking,” remarks Maria Villegas Bravo from the Electronic Privacy Information Center. She perceives Musk’s earlier criticisms of other apps as self-serving.

When Musk initially presented XChat as an upgraded, encrypted version of X direct messages, security professionals raised concerns about the storage of users’ cryptographic keys on X’s servers. “Considering XChat’s track record of security flaws, I would hesitate to use it until it undergoes a comprehensive audit,” states Cooper Quintin from the Electronic Frontier Foundation.

Musk aims for the discussion to zero in on which encrypted messaging app reigns supreme. However, after trying XChat, it feels more akin to Facebook’s Messenger. Rather than launching an elegant, new application, Musk revealed a straightforward extension of his social media platform that features encrypted messaging.

When the XChat team disclosed the app’s launch, the initial release date on Apple’s App Store was set for April 17 but was postponed several times before its surprise launch on April 24. The appropriate app did not consistently appear in searches, with a Russian-language app called “XChat App” briefly ascending Apple’s download rankings. “Scam app,” cautioned one user review.

Upon XChat’s eventual launch, access was initially restricted to the U.S., leaving U.K. users feeling disappointed. “UK should be live soon; had one issue,” wrote X’s head of product, Nikita Bier. Bier attributed the confusion early downloaders faced during the onboarding process to Apple.

After downloading XChat, I found it challenging to locate contacts to message. None of my top iMessage contacts possess X accounts, emphasizing XChat’s niche attraction. After revisiting my old DMs, I revived a few conversations. Following my messages, a pop-up confirmed, “This conversation is now end-to-end encrypted.” Despite this, no responses were received, just some emoji reactions.

Your Images Might Be Disclosing Your Location. Here's How to Stop That

Your Images Might Be Disclosing Your Location. Here’s How to Stop That

Capture an image with any digital camera or smartphone, and it’s not only the pixels that are recorded. The photo also contains metadata, referred to as EXIF (Exchangeable Image File Format) data, which reveals information about when it was captured, the device utilized, and the camera configurations. If your smartphone or camera is equipped with a GPS chip and monitors your location, this is also subtly embedded in the photograph. This can aid in reminiscing about memories captured in specific places but may not be suitable if you intend to share images while keeping your home address confidential. It’s important to reflect on the metadata linked to any photograph you distribute beyond your private use, and eliminate location data if needed.

How to Inspect Photo Metadata

Photo metadata can offer various benefits, including location tagging. Google Photos and Apple Photos facilitate the organization of your library based on the locations where images were captured. Attempt to search for a location in these applications to observe the outcomes. You can access photo metadata in multiple ways. In Google Photos for Android, select an image, tap the three dots in the upper right corner, and pick About. If there’s location information, it will be displayed on a map. In Google Photos on the web, open an image and click the info icon in the upper right to see the metadata. On iOS, use Apple Photos by opening an image and tapping the info icon at the bottom. If location details are present, they will show on a map. In Apple Photos on the web, double-click an image to open it, and the info icon is located at the top right.

This data can be accessed on Windows and macOS, though it shows GPS coordinates rather than a map. In Windows, right-click on an image in File Explorer, select Properties, and go to the Details tab. On macOS, right-click an image in Finder, choose Get Info, and GPS coordinates will be displayed in the dialog if they are available.

John Solly: The DOGE Agent Charged with Scheming to Shift Social Security Information to His New Position

John Solly: The DOGE Agent Charged with Scheming to Shift Social Security Information to His New Position

John Solly, a software developer and previous member of the Department of Government Efficiency (DOGE), is allegedly reported to have informed colleagues that he had kept critical Social Security Administration (SSA) data on a USB drive with plans to present it to his new employer, as per sources. Since October, Solly has held the position of chief technology officer for Leidos’ health IT sector, which possesses substantial contracts with SSA. Solly’s online footprint has been erased this week. Through his legal representation, Solly refutes any accusations of misconduct. Leidos has found no proof that supports the whistleblower’s allegations. Solly was a member of a 12-person DOGE team at SSA, contributing to various projects. A report, not specifying Solly or Leidos, was submitted to the SSA’s Inspector General, claiming that a former DOGE employee had taken SSA data to possibly use at a private-sector firm, anticipating clemency for any illegal acts. Solly asserts that he did not partake in the alleged conduct. Leidos stands as a prominent SSA contractor, continuing to gain substantial contracts despite cuts under DOGE’s initiatives.