Your Menstrual Tracker Could Be Monitoring You

Your Menstrual Tracker Could Be Monitoring You

Hours of San Francisco Police Department drone video footage made public online reveals a new phase of exceedingly detailed—and impactful—urban surveillance. In parallel, the San Francisco City Attorney’s Office issued cease-and-desist notices to Apple and Google this week, demanding the tech giants remove 13 AI nudifying “face-swap” applications from their app stores that predominantly target women and girls.

Since WIRED initially reported in June on Meta’s NameTag facial recognition feature, company leaders have provided unclear and contradictory statements regarding its existence. We stepped back to clarify both the claims and the actual facts surrounding this very real system.

In a presentation on Thursday, President Donald Trump persisted in promoting unverified and thoroughly discredited claims of interference in the 2020 US election. He even promised significant revelations in a collection of documents uploaded to the White House website, but the documents did not support his claims—and in some instances directly undermined Trump’s assertions.

As the use of AI tools rapidly grows and their functions enhance, the tech giant Anthropic has continued its efforts to encourage US states to impose regulations on AI. Commenting on AI transparency requirements established in California and New York last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, expressed to WIRED this week, “The transparency-oriented safety legislation of 2025 was an important initial step, but as AI systems’ capabilities advance rapidly, policy reactions must keep pace.”

And there’s additional news. Each week, we compile the security and privacy updates we haven’t examined in-depth ourselves. Click the headlines to access the complete stories. And remain cautious out there.

The astrology-themed period tracker Stardust transmits users’ reproductive health information—birth control type, pregnancy status, moods, and specific symptoms like tender breasts and stomach cramps—to a data firm not specified in its privacy policy, according to the BBC, which first disclosed a Mozilla Foundation review of six popular trackers conducted in collaboration with Harvard’s Berkman Klein Center.

Stardust received a score of 2 out of 10, the lowest among the options. Mozilla researcher Shoshana Wodinsky discovered that the app connects with third-party trackers as soon as it opens, prior to any user input; upon logging a symptom, the details were sent to analytics firm RudderStack alongside a persistent user ID, with no option within the app to disable this data sharing. RudderStack is designed to direct data to destinations that Mozilla could not monitor. Stardust also provides Facebook with an ad identifier linking in-app activities to the platform’s existing profiles. The company informed TechCrunch that it has never been compelled to comply with a legal demand for user data.

Euki, a nonprofit-operated tracker, achieved a perfect score of 10: no account required, health information remains on the phone, and users can establish a PIN, organize automatic deletion, or display a decoy screen if someone attempts to force access to the phone. Its sole vulnerability is an in-app browser for educational content that loads the standard web trackers, but it resets identifiers after each visit.

Russia’s FSB has historically been recognized for its highly advanced cyber-espionage tactics, leaving disruptive cyber-attacks to its counterparts in the GRU military intelligence agency. However, sanctions from the EU and UK this week, along with advisories from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, attributed a cyberattack against the Polish electric grid to Center 16 of the FSB, marking a rare instance of the Kremlin agency executing a cyberattack that nearly resulted in outages in the country’s electricity and water services. The attack, which Polish officials stated came “very close” to causing a blackout, was originally linked by cybersecurity firms Dragos and ESET to Sandworm, also known as Unit 74455 of the GRU, a more common suspect in infrastructure breaches due to its active involvement in Russia’s ongoing cyberwar against Ukraine. However, the Polish computer emergency response team at the time disputed that attribution and linked the attack to the FSB, a conclusion now backed by a broad consensus among Western governments. The event implies that the FSB may be adopting some of the reckless, highly aggressive behaviors—and targeting—characteristic of its GRU colleagues.

For years, the Russian cybersecurity firm Kaspersky has been alleged to possess connections to the Russian government, as suggested by US officials who prohibited the use of the company’s products within the US government and subsequently by all American clients. Yet tangible proof of those ties has been limited. Now Reuters reveals that Denis Obrezko, a Russian individual facing hacking allegations in Boston and purported member of a hacker group named Void Blizzard or Laundry Bear, worked at Kaspersky for two years. His tenure at the company preceded his employment at another cybersecurity firm, Yutek-NN, where he allegedly participated in the group’s hacking operation that compromised data and communications from multiple NATO nations and at least 11 US firms, according to US prosecutors.

Hackers Distribute Claude Code Breach with Additional Malware

Hackers Distribute Claude Code Breach with Additional Malware

An investigation by WIRED utilizing records from the Department of Homeland Security this week uncovered the identities of paramilitary Border Patrol agents who often employed force against civilians during Operation Midway Blitz in Chicago last autumn. Several of the agents, according to WIRED, also participated in similar operations in various states across the US.

Customs and Border Protection might want to consider safeguarding its sensitive facility information. Through simple Google searches, WIRED found flashcards created by users on the online learning site Quizlet that included gate codes for CBP facilities and more.

In an unusual decision, Apple this week issued “backported” patches for iOS 18 to safeguard millions of users still utilizing the older operating system from the DarkSword hacking method that was discovered being used in the wild. Found in March, DarkSword enables attackers to compromise iPhones that simply visit a website containing the takeover tools. Apple first encouraged users to upgrade to the latest version of its OS, iOS 26, but eventually released the iOS 18 patches as DarkSword continued to proliferate.

The US-Israel conflict with Iran entered its second month this week, with Iran issuing threats to initiate attacks on over a dozen US companies, including major tech firms like Apple, Google, and Microsoft, which operate offices and data centers in the Gulf region. The perilous conflict, with no clear resolution in sight, continues to devastate the global economy as shipping crews remain stuck in the Strait of Hormuz, a vital trade passage. Meanwhile, some are starting to ponder what might occur if US strikes inflict significant damage on Iran’s nuclear sites.

And that’s not everything! Each week, we compile the security and privacy updates we didn’t delve into more comprehensively. Click on the headlines to read the complete stories. And stay safe out there.

Earlier this week, a security expert pointed out that Anthropic inadvertently made the source code for its well-known vibe-coding tool, Claude Code, public. Instantly, individuals began sharing the code on the developer platform GitHub. But be cautious if you wish to download some of those repositories: BleepingComputer warns that some of the individuals posting are actually hackers who have embedded a piece of infostealer malware within the lines of code.

Anthropic, for its part, has been actively working to eliminate copies of the leak (malware-laden or otherwise) by sending out copyright takedown requests. The Wall Street Journal <a href="https://www.wsj.com/tech/ai/anthropic-races-to-contain-leak-of-code-behind-claude-ai-agent-4bc5acc7?gaa_at=eafs&gaa_n=AWEtsqe0YqHxbezGhAXCQMkTM704xLIzPtDKH78qcGbyQlXZjxZuAmm8TxwV4QxfOvM%3D&gaa_ts=69