Apple has resolved a security vulnerability affecting its Hide My Email feature that could expose users' actual email addresses, raising concerns about the reliability of one of the company's privacy-focused services. The issue remained unresolved for more than a year before Apple implemented a server-side fix, prompting increased scrutiny from security researchers and legal action regarding the company's privacy claims. Hide My Email, available as part of the iCloud+ subscription, allows users to generate unique email aliases that forward messages to their primary inbox while masking their real email addresses. The feature is intended to prevent websites and online services from collecting or identifying users' personal email accounts. However, security researchers discovered that under certain conditions these aliases could be linked back to the corresponding email addresses, reducing the intended level of anonymity. the researchers found that exploitation required no privileged access or compromise of Apple systems. When emails sent to a Hide My Email alias were rejected as spam, the recipient's actual email address could be recorded in mail transfer logs maintained by third-party email providers. Since these events occurred before messages reached the user's mailbox, affected individuals had no practical way to determine whether their real email addresses had been exposed. Apple received a responsible disclosure regarding the vulnerability in June 2025 and, following an extended remediation process, implemented a server-side update on July 3, 2026, confirming that the identified security issue had been successfully addressed. Nevertheless, users are advised to treat aliases created before July 7, 2026 as potentially exposed through historical mail server logs. The incident highlights the importance of validating vendor privacy features, understanding the limitations of email forwarding services, and regularly reviewing security advisories to mitigate potential privacy risks.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...