LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
ai

Meta Sued Over Training Data for Its AI and Face-Recognition Systems

The proposed class action alleges Meta illegally harvested people’s Facebook and Instagram photos to train its AI image-generation models and to build its unreleased “NameTag” face recognition feature.

zeroday.news ·

A proposed class-action lawsuit has been filed against Meta in federal court in Chicago, alleging that the company illegally used photos from Facebook and Instagram to train its AI image-generation models and to develop an unreleased face-recognition feature called "NameTag." The lawsuit claims that Meta violated privacy laws in Illinois and California by extracting biometric information from individuals' photos without their knowledge or consent.

The complaint, filed by parents and their children in Illinois and California, specifically targets Meta's generative AI models, Emu and Muse Image. Meta's Chief Product Officer, Chris Cox, has previously stated that the company trained Emu on extensive quantities of Facebook and Instagram images and text, referring to these platforms as a "data advantage" for its AI systems. The lawsuit contends that this training process involved the unlawful harvesting of biometric data from individuals appearing in the images. Muse Image, released this summer, had previously drawn criticism for allowing users to generate images based on other people's public Instagram accounts, a feature Meta subsequently removed, acknowledging it "missed the mark."

The lawsuit also focuses on "NameTag," an unreleased face-recognition system intended for Meta's smart glasses. Code for NameTag was reportedly embedded in the Meta glasses AI companion app, which has been downloaded over 50 million times. While the feature was not enabled for users, analysis indicated it was designed to convert faces captured by the glasses into biometric signatures and compare them against "faceprints" stored in a database on the user's phone. This database was configured to receive updates from Meta.

The complaint alleges that these faceprints may have been derived from Facebook and Instagram images. This claim is supported by reports of Meta employees stating NameTag could recognize individuals through their Meta connections or public Instagram accounts, as well as a company patent describing face matching against profile photos and other images held by Meta. Meta previously stated in June that it was "not building a central face database" and declined to comment on whether NameTag would be opt-in or how faceprints would be retained.

A Meta spokesperson issued a statement calling the lawsuit "without merit" and a "misrepresentation" of their work. The company asserted transparency regarding its use of user information to develop and enhance AI products. Regarding NameTag, Meta stated that "nothing has shipped to consumers and no final decision has been made on what to do here, if anything," adding that any rollout would be "thoughtful" and "with full transparency," reiterating that they are "not building a universal face database."

The plaintiffs in the case are Francisco Alvarez and his son, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter. The proposed class includes individuals in Illinois, California, and across the United States whose images were uploaded to Facebook or Instagram or submitted to Meta’s generative AI systems through prompts, dating back to September 4, 2021. The complaint estimates the national class could number in the millions.

Under Illinois’ Biometric Information Privacy Act (BIPA), the plaintiffs are seeking $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent violation, or actual damages if greater, in addition to injunctive relief. The California claims seek additional damages and other forms of relief.

This is not the first instance of Meta facing legal challenges concerning its handling of biometric data. In 2020, the company agreed to a $650 million settlement in an Illinois class action related to an earlier face-recognition system. In November 2021, Meta announced the shutdown of that system and the deletion of over a billion faceprints. In 2024, Meta also agreed to pay Texas $1.4 billion to resolve separate allegations of unlawful biometric data collection from users.

The day after a June 4 report detailing NameTag, Meta reportedly removed the associated code from its app. While Meta argued the feature never existed because it was not available to consumers, analysis and testing by independent researchers indicated a technically functional face-recognition system had been included in an app downloaded by tens of millions. Meta CTO Andrew Bosworth described the reporting as "incredibly misleading" and "absolutely dishonest," though he later discussed NameTag on a podcast, suggesting it could recognize people a glasses wearer had previously met and asked the device to remember, calling it a "great feature." Meta has consistently described NameTag as an exploratory concept rather than a consumer product.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]