U.S. military branches have disabled advertising trackers on government-issued phones and computers following reports that location data from these trackers was being used to target American forces in the Middle East.
The decision came after military officials discovered that ad tracking technology was exposing personnel locations to potential adversaries. Documents released through letters show multiple military branches took coordinated action to remove or disable tracking mechanisms on issued devices.
Advertising trackers—typically embedded in apps and websites to monitor user behavior for targeted advertising—can reveal precise location information when combined with other data sources. In conflict zones, this information poses a direct security risk to deployed troops.
The move reflects growing awareness within the defense community about the vulnerabilities created by commercial technology on military networks. While the military has long restricted certain consumer apps and services on government devices, advertising trackers often operate invisibly within legitimate applications.
The exact scope of the vulnerability and whether adversaries successfully exploited location data before the trackers were disabled remains unclear. The action underscores the ongoing tension between security and the prevalence of tracking technology in modern digital infrastructure.
A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.
The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.
Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.
Hewlett Packard Enterprise has released a patch for a critical remote code execution vulnerability in ArubaOS-CX, its network operating system used in enterprise switches and wireless controllers.