Your Menstrual Tracker Could Be Monitoring You

Your Menstrual Tracker Could Be Monitoring You

Hours of San Francisco Police Department drone video footage made public online reveals a new phase of exceedingly detailed—and impactful—urban surveillance. In parallel, the San Francisco City Attorney’s Office issued cease-and-desist notices to Apple and Google this week, demanding the tech giants remove 13 AI nudifying “face-swap” applications from their app stores that predominantly target women and girls.

Since WIRED initially reported in June on Meta’s NameTag facial recognition feature, company leaders have provided unclear and contradictory statements regarding its existence. We stepped back to clarify both the claims and the actual facts surrounding this very real system.

In a presentation on Thursday, President Donald Trump persisted in promoting unverified and thoroughly discredited claims of interference in the 2020 US election. He even promised significant revelations in a collection of documents uploaded to the White House website, but the documents did not support his claims—and in some instances directly undermined Trump’s assertions.

As the use of AI tools rapidly grows and their functions enhance, the tech giant Anthropic has continued its efforts to encourage US states to impose regulations on AI. Commenting on AI transparency requirements established in California and New York last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, expressed to WIRED this week, “The transparency-oriented safety legislation of 2025 was an important initial step, but as AI systems’ capabilities advance rapidly, policy reactions must keep pace.”

And there’s additional news. Each week, we compile the security and privacy updates we haven’t examined in-depth ourselves. Click the headlines to access the complete stories. And remain cautious out there.

The astrology-themed period tracker Stardust transmits users’ reproductive health information—birth control type, pregnancy status, moods, and specific symptoms like tender breasts and stomach cramps—to a data firm not specified in its privacy policy, according to the BBC, which first disclosed a Mozilla Foundation review of six popular trackers conducted in collaboration with Harvard’s Berkman Klein Center.

Stardust received a score of 2 out of 10, the lowest among the options. Mozilla researcher Shoshana Wodinsky discovered that the app connects with third-party trackers as soon as it opens, prior to any user input; upon logging a symptom, the details were sent to analytics firm RudderStack alongside a persistent user ID, with no option within the app to disable this data sharing. RudderStack is designed to direct data to destinations that Mozilla could not monitor. Stardust also provides Facebook with an ad identifier linking in-app activities to the platform’s existing profiles. The company informed TechCrunch that it has never been compelled to comply with a legal demand for user data.

Euki, a nonprofit-operated tracker, achieved a perfect score of 10: no account required, health information remains on the phone, and users can establish a PIN, organize automatic deletion, or display a decoy screen if someone attempts to force access to the phone. Its sole vulnerability is an in-app browser for educational content that loads the standard web trackers, but it resets identifiers after each visit.

Russia’s FSB has historically been recognized for its highly advanced cyber-espionage tactics, leaving disruptive cyber-attacks to its counterparts in the GRU military intelligence agency. However, sanctions from the EU and UK this week, along with advisories from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, attributed a cyberattack against the Polish electric grid to Center 16 of the FSB, marking a rare instance of the Kremlin agency executing a cyberattack that nearly resulted in outages in the country’s electricity and water services. The attack, which Polish officials stated came “very close” to causing a blackout, was originally linked by cybersecurity firms Dragos and ESET to Sandworm, also known as Unit 74455 of the GRU, a more common suspect in infrastructure breaches due to its active involvement in Russia’s ongoing cyberwar against Ukraine. However, the Polish computer emergency response team at the time disputed that attribution and linked the attack to the FSB, a conclusion now backed by a broad consensus among Western governments. The event implies that the FSB may be adopting some of the reckless, highly aggressive behaviors—and targeting—characteristic of its GRU colleagues.

For years, the Russian cybersecurity firm Kaspersky has been alleged to possess connections to the Russian government, as suggested by US officials who prohibited the use of the company’s products within the US government and subsequently by all American clients. Yet tangible proof of those ties has been limited. Now Reuters reveals that Denis Obrezko, a Russian individual facing hacking allegations in Boston and purported member of a hacker group named Void Blizzard or Laundry Bear, worked at Kaspersky for two years. His tenure at the company preceded his employment at another cybersecurity firm, Yutek-NN, where he allegedly participated in the group’s hacking operation that compromised data and communications from multiple NATO nations and at least 11 US firms, according to US prosecutors.

Leading Motion Detectors and Camera-Free Domestic Safety Devices

Leading Motion Detectors and Camera-Free Domestic Safety Devices

Kini consistently excels as a dependable monitoring tool. It accurately senses when drawers and cabinets are opened and offers notifications even with logging turned off. The log captures timestamps, yet the manufacturer, Kinisium, assures users that no data is compiled. Kini’s Stasis mode aids in monitoring inactivity, which is beneficial for overseeing medication access or recording when someone enters a space. IFTTT compatibility enables automation, and a webhook function permits alerting custom URLs.

When evaluating motion sensors, the Eve Motion Sensor is notable, although incorporating it into alert systems necessitates a smart hub and automation configuration. It is dependable for both indoor and outdoor settings.

Aqara presents the FP2 Presence Sensor, which can identify zones and multiple individuals. While it is generally precise, it may find it challenging to count persons accurately. Its more economical alternative, the FP300, also offers presence recognition along with monitoring light, temperature, and humidity.

The Switchbot Presence Sensor is an affordable choice but needs a hub for alert functions and experiences a slight delay upon detection.

For external applications, the Philips Hue Outdoor Motion Sensor seamlessly integrates with existing Hue systems, delivering effective detection with few false alerts. It can be configured to initiate notifications and actions during particular times, enhancing security. For indoor uses, the Philips Hue Indoor Motion Sensor and Contact Sensor provide reliability and customizable alert triggers.

Smart lighting systems present another option for motion detection. The Wiz SpaceSense utilizes Wi-Fi, though its performance relies on light positioning. Similar to SpaceSense, Philips Hue’s MotionAware employs Zigbee, requiring a subscription for alerts, yet activates lights without additional costs.

For more cohesive solutions, modular security systems such as SimpliSafe, ADT, Vivint, Eufy, and Arlo offer extensive setups with various sensors to customize home security according to individual requirements.

CISA Calls on US Agencies to Tackle Security Vulnerabilities Within 3 Days in Light of AI Threats

CISA Calls on US Agencies to Tackle Security Vulnerabilities Within 3 Days in Light of AI Threats

With the rise of new AI models facilitating swift software vulnerability identification and possible misuse by cybercriminals, the US Cybersecurity and Infrastructure Security Agency (CISA) released a directive on Wednesday requiring quicker software patch implementation for federal agencies. This directive provides a timeline for bug fixes based on priority, demanding a three-day response for critical issues.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, highlighted the necessity of prioritizing high-risk vulnerabilities. This directive is framed within ongoing efforts from both private and public sectors to evaluate the implications of AI-enhanced cybersecurity threats.

“Prioritizing vulnerable assets is essential at this time due to AI developments empowering threat actors to locate and exploit weaknesses,” Butera remarked. He underscored the urgency of prompt patching to avert widespread automated exploitation.

The guidelines for patch prioritization consider factors such as public visibility of a system, inclusion in CISA’s Known Exploited Vulnerabilities Catalog, automation of exploit techniques, and the extent of access obtainable if exploited. Vulnerabilities that fit all criteria must be resolved within three days, alongside a forensic assessment to ascertain any system breaches.

This directive supersedes earlier CISA directives from 2019 and 2021 that established a protocol for addressing critical bugs within 15 days and other issues within 30 days. CISA has previously observed how quickly threat actors capitalize on vulnerabilities, frequently on the day they are revealed.

Although there have been notable advancements in federal cybersecurity, challenges like funding and priorities can sometimes lead to delays. Butera clarified that the directive was crafted considering these obstacles, establishing feasible timelines.

Advancements in AI are transforming the vulnerability detection arena, necessitating more rapid patching. Nevertheless, researchers indicate a need for systemic strategies to eliminate categories of vulnerabilities. Emily Long, CEO of Edera, stated, “CISA’s directive only tackles part of the issue,” stressing the importance of frameworks that restrict attacker access following a breach.

Butera acknowledged, “The directive initially mitigates AI capabilities, but additional efforts are essential.”

Hackers Distribute Claude Code Breach with Additional Malware

Hackers Distribute Claude Code Breach with Additional Malware

An investigation by WIRED utilizing records from the Department of Homeland Security this week uncovered the identities of paramilitary Border Patrol agents who often employed force against civilians during Operation Midway Blitz in Chicago last autumn. Several of the agents, according to WIRED, also participated in similar operations in various states across the US.

Customs and Border Protection might want to consider safeguarding its sensitive facility information. Through simple Google searches, WIRED found flashcards created by users on the online learning site Quizlet that included gate codes for CBP facilities and more.

In an unusual decision, Apple this week issued “backported” patches for iOS 18 to safeguard millions of users still utilizing the older operating system from the DarkSword hacking method that was discovered being used in the wild. Found in March, DarkSword enables attackers to compromise iPhones that simply visit a website containing the takeover tools. Apple first encouraged users to upgrade to the latest version of its OS, iOS 26, but eventually released the iOS 18 patches as DarkSword continued to proliferate.

The US-Israel conflict with Iran entered its second month this week, with Iran issuing threats to initiate attacks on over a dozen US companies, including major tech firms like Apple, Google, and Microsoft, which operate offices and data centers in the Gulf region. The perilous conflict, with no clear resolution in sight, continues to devastate the global economy as shipping crews remain stuck in the Strait of Hormuz, a vital trade passage. Meanwhile, some are starting to ponder what might occur if US strikes inflict significant damage on Iran’s nuclear sites.

And that’s not everything! Each week, we compile the security and privacy updates we didn’t delve into more comprehensively. Click on the headlines to read the complete stories. And stay safe out there.

Earlier this week, a security expert pointed out that Anthropic inadvertently made the source code for its well-known vibe-coding tool, Claude Code, public. Instantly, individuals began sharing the code on the developer platform GitHub. But be cautious if you wish to download some of those repositories: BleepingComputer warns that some of the individuals posting are actually hackers who have embedded a piece of infostealer malware within the lines of code.

Anthropic, for its part, has been actively working to eliminate copies of the leak (malware-laden or otherwise) by sending out copyright takedown requests. The Wall Street Journal <a href="https://www.wsj.com/tech/ai/anthropic-races-to-contain-leak-of-code-behind-claude-ai-agent-4bc5acc7?gaa_at=eafs&gaa_n=AWEtsqe0YqHxbezGhAXCQMkTM704xLIzPtDKH78qcGbyQlXZjxZuAmm8TxwV4QxfOvM%3D&gaa_ts=69

How 'Handala' Emerged as the Symbol of Iran's Cyber Counteractions

How ‘Handala’ Emerged as the Symbol of Iran’s Cyber Counteractions

In the wake of the extensive airstrike operations conducted by the United States and Israel over Iran in late February, the cybersecurity sector anticipated retaliatory cyber offensives targeting Western entities. Tuesday night saw such an incident unfold in the US: a data breach at the medical technology company Stryker, believed to have ties to Iran, disabled tens of thousands of computers and disrupted global operations. The Iranian hacking collective Handala took responsibility for the breach.

A pronouncement on Handala’s website characterized the cyber operation as a reaction to the American Tomahawk missile assault that claimed the lives of 165 civilians at a girl’s educational institution in Iran and the ongoing hacking actions of the US and Israel. This pronouncement marks the beginning of a new phase in cyber warfare.

Once relatively unknown, Handala—named after a character created by Palestinian artist Naji al-Ali—is regarded by cybersecurity analysts, particularly in Israel, as a façade for Iran’s Ministry of Intelligence. Renowned for its data-deletion and hack-and-leak strategies, its targets have included the Albanian government and Israeli organizations.

In light of escalating existential threats, Iranian hackers, chiefly Handala, are encouraged to use every intended tool and network access against the US and Israel, stated Sergey Shykevich from the cybersecurity firm Check Point. Shykevich identifies Handala as the most active and prominent group in this vengeful campaign.

While hacking collectives often inflate their achievements, Handala has claimed numerous victims, predominantly in Israel, throughout the recent hostilities. Merging chaotic hacktivist tactics with governmental capabilities, the group acts as a primary cyber-retaliation entity for Iran, according to Justin Moore from Palo Alto Networks’ Unit 42.

Despite the chaos it generates, Handala’s operational coherence is doubtful, according to Rafe Pilling from Sophos’ X-Ops team. The group attempts swift access and infliction of damage in reaction to airstrikes that reportedly impact Iran’s cyber capabilities. Currently, Handala seems to be exploiting any available opportunity without an evident strategic framework.