LIVE · cybersecurity feed
Live wire
breach

Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

zeroday.news · 14d ago

A recent audit by the Mozilla Foundation, conducted in partnership with Harvard's Berkman Klein Center, has revealed significant privacy concerns with several popular period tracking applications, with one app, Stardust, scoring particularly low. The audit examined six widely used trackers, finding that most engaged in data sharing practices that could compromise user privacy.

Stardust, an astrology-themed period tracker, received a score of 2 out of 10. The audit found that the application transmits sensitive reproductive health information, including birth control type, pregnancy status, moods, and specific symptoms like tender breasts and stomach cramps, to a data firm not disclosed in its privacy policy. Mozilla researcher Shoshana Wodinsky observed that Stardust initiates third-party tracking immediately upon opening, even before a user inputs any data. Once a symptom is logged, these details are sent to the analytics firm RudderStack, along with a persistent user ID, without any in-app option to disable this sharing. RudderStack is designed to further route data to other destinations that Mozilla could not monitor. Additionally, Stardust provides Facebook with an advertising identifier, linking in-app behaviors to existing Facebook profiles. The company has stated to TechCrunch that it has never received a legal demand for user data.

In contrast, Euki, a period tracker operated by a nonprofit organization, achieved a perfect score of 10. This application does not require an account, and all health data remains stored locally on the user's phone. Euki offers robust privacy features, allowing users to set a PIN, schedule automatic data deletion, and even display a decoy screen if forced to open the app. Its only minor privacy consideration is an in-app browser for educational content, which loads standard web trackers, though it resets identifiers between visits.

The findings highlight a broader issue of data privacy within health and wellness applications, particularly those handling highly personal information. The audit underscores the importance of scrutinizing privacy policies and understanding data flow when using such tools.

breachai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in