Full Breakdown
Privacy and Cybersecurity Risks Highlighted in Recent Tech News
7/19/2026, 11:16:57 AM
Privacy Concerns with Stardust Period Tracker
The astrology-themed app Stardust transmits users’ reproductive-health details—including birth-control type, pregnancy status, moods and symptoms such as tender breasts and stomach cramps—to analytics firm RudderStack the moment the app opens, according to a Mozilla Foundation audit cited by the BBC. The data are also linked to Facebook via an ad identifier. The app provides no in-app mechanism to disable this sharing, and users cannot delete the persistent identifier.
Notable Cybersecurity Incidents
- A cyberattack attributed to Center 16 of Russia’s Federal Security Service (FSB) targeted Poland’s electric and water utilities, nearly causing a blackout. Initial analyses by Dragos and ESET linked the attack to the GRU’s Sandworm unit, but the Polish computer-emergency response team later identified the FSB as the source, a view now supported by Western governments.
- Denis Obrezko (spelled “Obrevko” in another report), a Russian national facing hacking charges in Boston, allegedly worked for Kaspersky, the FSB, and later Yutek-NN, participating in a campaign that stole data from NATO governments and at least 11 U.S. companies.
- The Department of Homeland Security’s Homeland Security Information Network (HSIN) was breached twice in mid-2023; analysts initially dismissed the activity as false positives before confirming a real intrusion that altered files, hijacked a web server and deleted logs.
Official Statements & Responses
- “The transparency-focused safety bills of 2025 were a really important start, but as the capabilities of AI systems continue to advance quickly—the policy responses need to match.” — Cesar Fernandez, Head of US State and Local Government Relations, Anthropic
- “The offenses charged cannot be related to the individual’s role or responsibilities during the employment at Kaspersky.” — Kaspersky spokesperson (statement to Reuters)
- “Its exposure risks national security.” — Mark Warner, Senate Intelligence Committee vice chair (statement)
- “The company told TechCrunch it has never received a legal demand for user data.” — Facebook (statement)
Criticism & Opposition
Mozilla researcher Shoshana Wodinsky highlighted that Stardust pings third-party trackers before any user input, violating expectations of privacy. Euki, a nonprofit-run tracker, received a perfect privacy score for keeping health data on-device and offering PIN protection, underscoring industry alternatives.
Conflicting Reports & Gaps
Sources differ on the spelling of the Boston-based hacker’s surname (“Obrezko” vs. “Obrevko”). Attribution of the Polish grid attack also varies: early reports named the GRU’s Sandworm unit, while later consensus points to the FSB’s Center 16. Details on the full scope of the HSIN breach and the exact data accessed by Suno’s intruders remain limited.
