Privacy
FTC Sues Hims & Hers, EU Chat Control Deadlock, and AI Abuse Rules
FTC lawsuit alleges Hims & Hers shared health data with advertisers; EU chat control talks stall; China drafts AI cyberbullying rules.
FTC Sues Hims & Hers Over Health Data Sharing and Deceptive Billing
The U.S. Federal Trade Commission filed a lawsuit against Hims & Hers on Wednesday, alleging the telehealth company shared users’ sensitive health information with online advertisers including Meta Platforms and Snap, despite promising privacy. The lawsuit, joined by Los Angeles County and Utah, also claims Hims & Hers engaged in deceptive billing and cancellation practices, charging users for prescriptions before they had a chance to consult with healthcare providers. According to the FTC, most customers do not receive a consultation and are charged soon after filling out an intake form, while the company makes it difficult to cancel subscriptions. Hims & Hers stock dropped around 12% following the news. Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection, said the agency will not hesitate to act on behalf of consumers deprived of their ability to keep their most sensitive health information private. Hims & Hers called the claims baseless in a post on X, stating the lawsuit is an effort to generate headlines at their expense. The company is one of the largest telehealth players in the weight loss drug market and also offers services for erectile dysfunction, hair loss, and mental health medications.
Audit Finds 56% of VPN Windows Clients Use Outdated OpenVPN Code
An audit of 32 Windows VPN clients in July revealed that 56% (18 of 32) use an OpenVPN version more than a year old, with 41% using configurations over two years old and 12.5% relying on code at least five years old. OpenVPN is an open-source protocol that encrypts and routes data between devices and VPN servers, forming the foundation for many commercial VPN services. VPN providers often update their apps while leaving the bundled OpenVPN component unchanged. Among the best VPNs, NordVPN, Windscribe, and Proton VPN use OpenVPN releases as recent as April 2026, while Turbo VPN and VyprVPN still use OpenVPN 2.4.7 from April 2019. OpenVPN has registered six CVEs in 2025 and six in 2024, though running an older version does not necessarily mean every vulnerability applies if the older build lacks a feature that caused the flaw. Experts note that security can be maintained through backported patches or configuration mitigations, but the real concern arises when no such measures are in place. VPN providers argue that adopting a new OpenVPN release requires months of compatibility testing and staged rollouts, and they are not obliged to adopt every upstream release. Proton VPN said it will begin phasing out OpenVPN support in its client apps while retaining the protocol on servers for legacy devices, calling OpenVPN slow and bloated compared to its Stealth and WireGuard protocols.
Updating your app might not keep you safe: How outdated OpenVPN code leaves VPNs exposed →
China Drafts Cyberbullying Rules Targeting AI-Generated Abuse
The Cyberspace Administration of China published draft rules on 29 July to combat cyberbullying, with measures explicitly covering abuse generated by artificial intelligence. The draft targets what regulators call cyberviolence, defined as the online spread of harassing, defamatory, or false information that harms a person, including AI misuse such as deepfaked images and synthetic text produced at volume. Under the draft, platforms would be required to build classifiers that detect cyberviolence, offer users a one-click protection feature that blocks incoming messages and comments, and maintain blacklists of repeat offenders. Platforms would also run early-warning systems to catch pile-ons before they escalate, with penalties up to account closure. The question-and-answer site Zhihu has already moved to curb anonymous accounts in anticipation of the rules. The draft is open for public comment before finalization. The same tools that detect abuse also identify speakers, giving authorities a fuller map of who is saying what, as much online abuse in China is posted from anonymous or pseudonymous accounts. Public anger after several high-profile cyberbullying cases has given authorities a popular mandate to act.
China drafts cyberbullying rules that reach AI-generated abuse →
Researchers Develop SAGA Tool to Trace AI-Generated Videos to Source
Researchers at the University of California, Riverside, in collaboration with YouTube and Google DeepMind, developed a tool called SAGA (Source Attribution of Generative AI Videos) that can trace fake videos back to the AI system that created them. The framework analyzes spatial details within individual frames and temporal relationships across entire video sequences, focusing on how visual information changes from frame to frame. A key innovation is Temporal Attention Signatures (T-Sigs), which visualize unique patterns associated with different video generators. By averaging patterns across many videos from the same AI system, SAGA generates a characteristic profile to distinguish one generator from another. The team tested SAGA on public datasets containing videos created by 19 different AI video generators, including both text-to-video and image-to-video models. The researchers found that SAGA could identify whether a video was real or AI-generated, determine whether it was created from text or an image, distinguish between different versions of AI models, and trace videos back to the team that developed the model. Doctoral student Rohit Kundu stated that the patterns are like fingerprints the generative model leaves behind, and that the critical need has shifted from whether a video is fake to what its source is.
Researchers Create Tool to Trace Fake Videos to the AI System That Made Them →
EU Chat Control Talks Stall as Fifth Round Ends in Deadlock
The European Commission first proposed chat control in 2021 as a temporary rule allowing platforms to scan for known abuse material. That temporary regime expired on 3 April, was rejected by Parliament’s civil liberties committee in March, then survived a fast-tracked vote on 9 July when a motion to reject it fell just short of the required majority, and will now run until April 2028. The permanent law, known as chat control 2.0, would include mandatory risk assessments, detection orders, and scanning of messages, with encrypted messages mentioned in early versions. Discussions between Parliament, the Council, and the Commission have continued since December 2025 without consensus, and the fifth round on 29 June ended in a deadlock over mandatory scanning. Negotiators will not meet again until September. Supporters point to Europol’s data logging over 20 million suspected abuse reports in 2024, while privacy regulators and rights groups counter that scanning messages before encryption would undermine encryption itself and risk false accusations at scale. Signal has said it would rather leave the EU than comply.
Is the EU’s ‘Chat Control’ the end of private messaging in Europe? →