Period Tracker App May Be Collecting User Data Without Consent
Russian state‑backed cyber actors are shifting from high‑profile data theft to targeting critical infrastructure, analysts say, after a series of attacks on power grids and water treatment facilities in the United States. The new focus, described by a senior security researcher, exploits known vulnerabilities in industrial control systems, allowing attackers to plant malware that can disrupt operations without triggering immediate alarms. The shift comes amid heightened geopolitical tensions and a growing perception that infrastructure sabotage could yield more strategic leverage than traditional espionage.
In a separate incident, the U.S. Department of Homeland Security (DHS) was repeatedly unaware that its own systems had been compromised, according to a recent audit. The audit revealed that the agency’s intrusion detection tools failed to flag multiple intrusion attempts over several months, raising questions about the effectiveness of its cybersecurity posture. Meanwhile, a data breach at a popular AI‑powered music generator exposed how the platform scraped user‑generated content from the web, revealing potential privacy violations and prompting calls for stricter data‑handling regulations. These events underscore a broader trend of evolving cyber threats and the need for robust defensive measures across both public and private sectors.