CyberBeacon #62 – Misleading Health App Ads

Misleading health apps, AI-powered phishing, accidental insider threats, the return of digital piracy, and Meta’s accelerating AI ambitions—this...

blog

Misleading health apps, AI-powered phishing, accidental insider threats, the return of digital piracy, and Meta’s accelerating AI ambitions—this edition of the Aware Force Cyber Beacon examines the technology and security developments that deserve attention right now.

Read the full article for practical insights into how these trends affect employees, consumers, and organizations—and what security leaders should be preparing for next.

Misleading Health App Ads Are a Growing Problem; Regulators Are Starting to Act

Don’t believe the ads in your Facebook and Instagram feeds: health apps that promise to measure blood pressure, blood sugar, and blood oxygen through your phone camera are almost always misleading. Your phone can only detect pulse, and even that is not medical grade. Regulators in the US and UK are starting to crack down, but ads that run on social media are operating outside of regulations, which means the burden of skepticism still falls on you.

  • Blood pressure and blood oxygen readings from consumer devices are not accurate enough for clinical use. Apple and Google do have policies restricting misleading health claims in app store listings, but these ads run on Facebook, Instagram, and YouTube, which operate under different rules and are far less scrutinized. An app can comply with App Store guidelines and still run a misleading ad on social media.
  • iPulse, advertised on Facebook as measuring heart rate, blood pressure, blood sugar, and blood oxygen by placing your finger on the camera flash, only measures heart rate that way. Blood pressure, blood sugar, and other metrics must be entered manually by the user. The app is a logging diary, not a medical measurement device and is not worth a hefty subscription fee.
  • The UK’s Advertising Standards Authority ruled against P&L Studio, Novabeyond, and HealthTracker Apps last month for running ads that gave consumers the false impression their apps could measure blood pressure using a smartphone camera. All three companies acknowledged their apps only allow users to log readings from external devices, but their advertising implies otherwise.

https://www.pharmacynetworknews.com/business/128876312-asa-slams-blood-pressure-apps-for-misleading-public

https://www.latimes.com/live-well/longevity/story/wearable-health-data-metrics-accuracy

Article content

Physical Media Is Back and So Is a New Kind of Piracy

Right now, streaming is the dominant way consumers access movies and TV shows but rising costs and the need to subscribe to multiple platforms are pushing people back toward physical media and, in growing numbers, toward piracy. Most consumers do not understand that buying a digital movie is not actually buying it: digital “purchase” is a license — not ownership — and that access can be revoked.

  • Sony PlayStation’s recent decision to delete over 550 movie titles in September without refunds to consumers who purchased the titles has turned into flashpoint. Amazon Prime Video is currently facing a class-action lawsuit alleging it misleads consumers by using the word “buy” for content that can disappear from the platform at any time.
  • Physical media is gaining ground. 4K Blu-ray sales in the UK increased nearly 20% last year.  Physical media advocates are quick to point out that a 4K Blu-ray delivers lossless, uncompressed audio and video that streaming services (which compress data to fit through a broadband connection) cannot match.
  • Piracy is making a comeback, too, but it no longer looks like torrenting — the kind of illegal file sharing we saw 20 years ago. The new piracy is “piracy as a service,” meaning professional IPTV platforms that look like Netflix, cost $5 a month of less (such as jellyfin.org), and offer thousands of channels in 4K.

https://www.streamingmedia.com/Articles/Editorial/Short-Cuts/What-Industrialized-Illegal-Streaming-Is-Calling-the-Industry-in-2026-175618.aspx

https://www.inkl.com/news/weve-seen-an-increase-in-blu-ray-orders-of-10-000-i-spoke-to-a-blu-ray-and-vinyl-manufacturer-about-their-blu-ray-sales-and-its-given-me-even-more-hope-for-physical-medias-survival

https://www.pushsquare.com/news/2026/07/reaction-playstations-burned-through-the-last-remaining-goodwill-of-its-fans

Article content

Your Security Team Is Getting Better at Fighting Phishing. Attackers Are Getting Better Faster

AI-powered phishing is now a high or extreme threat: the new Osterman Research report commissioned by IRONSCALES notes: “Our October 2022 research doesn’t even talk about artificial intelligence. This one has its stamp on every page.”  Organizations now remediate phishing 16% faster per incident thanks to AI-powered defenses. But they are spending 9% more total annual hours on phishing anyway, because attack volume has grown faster than response efficiency.

The most dangerous phishing attacks now exploit trust rather than urgency. The most concerning attack types now are emails sent from compromised internal accounts (colleagues or company addresses that bypass skepticism entirely), links that pass security scans clean then turn malicious after delivery, and AI-generated messages that impersonate senior executives with no detectable errors. Multi-stage attacks that move from email to phone call to text message are close behind.

  • Finance, HR, and IT help desk staff are the highest-value targets.  Attackers are choosing victims based on access, not seniority. Finance teams handle wire transfers and payment changes. HR holds payroll and personnel data. Scammers target help desk agents with emails or calls pretending to be locked‑out employees or admins who need their password reset or MFA disabled.
  • Attackers start with one known company email, then guess the format (for example, [email protected]) and use LinkedIn to match names, titles, and departments. They pull job titles, team descriptions, and even reporting lines from profiles and public org charts to see exactly who handles finance approvals, payroll, and IT support. From there, they focus their phishing on those roles, sending “from the CEO/CFO” messages to finance, “payroll/W‑2” requests to HR, and “password reset” requests to help desk staff.
  • Employees must not list specific access rights or sensitive responsibilities in their LinkedIn titles or summaries (for example, “approves wire transfers,” “payroll admin for all staff,” or “MFA reset authority”).

https://www.ironscales.com

https://www.verizon.com/business/resources/reports/dbir

https://sprinto.com/blog/statistics/social-engineering

Article content

Shadow Apps, Phishing Clicks, and Misconfigured Cloud Files: The Accidental Insider Problem

Most cybersecurity breaches that start inside a company are not the work of a disgruntled employee stealing data. They’re the result of ordinary people clicking the wrong link, using an app the IT team does not know about, or sharing a file without thinking. The fix is not surveillance; it is making it easier to do the right thing than the wrong one and giving employees enough training that 21 seconds is not enough time for an attacker to win.

Without security awareness training, one in three employees are likely to click a malicious link or comply with a fraudulent request. Organizations that run awareness training cut that risk by more than 40% in 90 days, and by up to 86% within a year, making this one of the most cost-effective security investments a company can make.

Lessons our Aware Force team has learned in 10 years’ of delivering security awareness:

  • Content must be interesting: employees must want to read it.
  • Which means it must be structured to address them personally in addition to on the job.
  • Punishment is not on the table. You must create a culture of trust and encourage rapid communication.
  • That means having an easy way for employees to contact IT with questions that might feel elementary — but sometimes are tips to trouble unfolding.
  • Various formats work for different employees: some consume videos, others respond to infographics, some prefer text heavy treatments.
  • “Breaking cyber news” generates the heaviest readership.
  • The ultimate yardstick of success is how long they spend with the content.

https://sprinto.com/blog/statistics/social-engineering

Article content

Instagram’s AI Photo Tool Was Shut Down After 3 Days — But Meta Isn’t Backing Off

Meta is spending $145 billion on AI infrastructure this year; about twice the amount as last year. There’s been a big bump already. Last week, Instagram’s Muse Image tool was shut down three days after launch following massive user backlash. And the company has paused a program that tracked employees’ computer activity amid data privacy concerns and a staff backlash.  But there’s more in the pipeline.

Up next, perhaps: Meta filed a patent for an AI system that listens to you all day and tracks your emotional state. The system analyzes your words, tone, sighs, and laughter, logs them with your location and phone activity, and builds a daily and monthly mood profile stored on Meta servers. It can also pull in your eye movements, blink rate, and pupil size. No product has shipped yet, but the patent claims the idea.

More than 8 million businesses are now using Meta’s AI advertising tools — double the number from just four months earlier. Meta’s analysis of over 1 million ad campaigns found that every dollar spent on Meta advertising now generates over $4.00 in revenue.

Meta’s Business Agent, an AI that handles customer conversations across WhatsApp, Messenger, and Instagram DMs, rolled out globally last month. It can answer FAQs, recommend products, book appointments, and hand off to a human when needed, and it carries conversation context across all three platforms simultaneously.

https://9to5mac.com/2026/07/10/meta-removes-feature-that-let-users-generate-ai-images-from-public-instagram-posts/

https://www.cnbc.com/2026/07/07/meta-ai-muse-image.html

https://thehackernews.com/2026/07/meta-files-patent-for-ai-that-can.html

Get the latest insights in cybersecurity.
Subscribe to the Aware Force Cyber Blog

Insightful cyber news, fresh ideas for engaging your employees and more.

Search

Richard Warner is a recognized expert on human cyber risk and the founder/CEO of Aware Force, where he and his team create cybersecurity content tailored to each client’s culture that is engaging, relatable, and effective.

Leveraging his decades of experience as a prominent journalist and communicator with outlets including FOX and the GPB Television Network, Richard helps organizations worldwide transform human weak links into their strongest digital defense.

He is based in Atlanta and pioneers effective strategies for security culture and employee engagement.

Featured Posts