Tech

Security Roundup: FSB Linked to Polish Grid Attack, DHS Misses Intrusions, and Stardust Tracker Data Sharing Exposed

A series of security incidents highlight vulnerabilities in consumer health apps, critical infrastructure, and federal data networks, alongside revelations regarding AI music startup data scraping and former Kaspersky employee charges.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · original
Your Period Tracker Is (Probably) Spying on You
Mozilla audit reveals period tracker shares sensitive health data; Western governments attribute near-blackout cyberattack to Russian intelligence agency; US Homeland Security Department misidentifies active breaches.

A Mozilla Foundation audit has exposed significant privacy failures in the Stardust period tracker, revealing that the application transmits sensitive reproductive health data to third-party analytics firm RudderStack and Facebook. The app received a privacy score of two out of 10, the lowest among six popular trackers assessed in partnership with Harvard's Berkman Klein Center. Mozilla researcher Shoshana Wodinsky found that Stardust pings third-party trackers immediately upon opening, before any user input, logging symptoms such as mood and physical discomfort to RudderStack alongside a persistent user ID. The app provides no in-app mechanism to opt out of this data sharing, and RudderStack routes the information to destinations that Mozilla could not observe.

In international cybersecurity developments, Western governments have attributed a cyberattack on the Polish electric grid to Centre 16 of the FSB, Russia’s federal security service. This marks a departure from the agency’s traditional focus on cyberespionage, with the attack coming close to causing blackouts in Poland’s electric and water utilities. While initial attributions by firms such as Dragos and ESET pointed to the GRU’s Sandworm unit, the Polish computer emergency response team disputed this, a conclusion now supported by a broad consensus of Western governments including the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA.

Domestically, the US Department of Homeland Security (DHS) misidentified two separate intrusions into its Homeland Security Information Network (HSIN) as false positives. Analysts at the Federal Emergency Management Agency detected hacker activity in mid-May, including the hijacking of a legitimate web server, file alteration, and log deletion, but dismissed the findings. Weeks later, hackers returned and were again dismissed as a mirage. Senate Intelligence Committee Vice Chair Mark Warner noted that while HSIN houses only unclassified data, the information is highly sensitive and its exposure risks national security.

A breach of AI music startup Suno has exposed evidence of extensive data scraping from platforms including YouTube Music, Deezer, and PodcastIndex. Internal data reviewed by 404 Media indicates the scraping of 113,879 hours of YouTube Music audio, tens of thousands of hours from Pond5 and Deezer, and roughly one million hours of podcasts. The intrusion, executed via the Shai-Hulud worm compromising an employee account, also exposed customer data including emails, phone numbers, and Stripe payment records. Suno maintains that its training qualifies as fair use and stated the breach involved outdated code.

Former Kaspersky employee Denis Obrezko faces hacking charges in the US, with allegations linking his employment at the cybersecurity firm to prior work for Russian intelligence services. Obrezko allegedly worked at Kaspersky for two years before joining Yutek-NN, where he participated in hacking campaigns against NATO governments and US companies. Kaspersky stated that the offences charged cannot be related to his role at the company, while Obrezko has pleaded not guilty to the charges.

Continue reading

More from Tech

Read next: The Walrus warns of collapsing digital memory as AI erodes search reliability
Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers