This week's security news is dominated by a critical flaw in Apple's privacy-focused Hide My Email service, alongside developments in spyware, AI abuse, and hacking groups. A WIRED investigation also revealed Meta contractors posing as minors to test chatbots, and a researcher used Anthropic's Claude Opus 4.7 to hack a ticket site.
Apple's Hide My Email Flaw Exposes Users
Back in 2021, Apple launched its Hide My Email tool, which generates "unique, random email addresses" that forward incoming messages to a user's personal inbox, reducing the amount of information shared with online services. However, 404 Media reported this week that a vulnerability in the system has made it possible, for at least a year, for people's real email addresses to be uncovered.
Security researcher Tyler Murphy, who discovered the flaw in June 2025, told the publication: "Apple Hide My Email is leaking email addresses that are supposed to be hidden." He added, "In our limited tests with volunteers, 100% of Hide My Email addresses were exploitable."
The exact details of the vulnerability have not been revealed as the problem remains unpatched. In tests conducted by 404 Media and Murphy, a newly created Hide My Email address using the @icloud.com domain could be linked back to the real email address of its creator. Murphy originally reported the problem to Apple last summer and was told it had been "addressed" by March this year, but further testing showed the issue remained exploitable. Months ago, Apple told Murphy it was still investigating. Apple did not respond to requests for comment from the publication.
| Aspect | Detail |
|---|---|
| Discovered by | Tyler Murphy (June 2025) |
| Exploitability | 100% of tested addresses exploitable |
| Reported to Apple | Summer 2025; told "addressed" by March 2026, but still exploitable |
| Current status | Unpatched; Apple still investigating |
Politician Targeted with Pegasus Spyware
A politician on the European Parliament's PEGA Committee—created to investigate spyware abuses, including the notorious Pegasus malware—was targeted with Pegasus himself, according to new research findings released this week. This underscores the ongoing threat posed by commercial spyware to high-risk individuals.
Google Warns EU Rules Could Weaken Security
Top Google security staff warned this week that the pro-competition rule proposals in the EU could make Google Search and Android systems vulnerable to hacking and other abuse. The warning highlights the tension between regulation and security in the tech industry.
Scattered Spider Member Arrested, Others Plead Guilty
A nineteen-year-old has been arrested and extradited to the United States to face charges over their alleged involvement in the notorious Scattered Spider hacking group, the Department of Justice (DoJ) announced this week. Peter Stokes, an Estonian-US dual citizen, was arrested in Finland in April and has been charged with computer intrusion, conspiracy, and fraud.
It is alleged that Stokes, along with other members of the loose hacking collective, hacked into an unnamed "luxury jewelry retailer" and demanded an $8 million cryptocurrency ransom in May 2025. The company did not pay but still spent $2 million on the incident, according to a DoJ press release. In recent years, Scattered Spider, largely believed to be composed of young, English-speaking teenagers, has caused havoc worldwide by hacking and disrupting dozens of businesses. The arrest of Stokes follows two British Scattered Spider members, Thalha Jubair and Owen Flowers, recently pleading guilty to hacking Transport for London in 2024 and causing millions in damages.
Additional Security Highlights
A WIRED investigation revealed that Meta contractors posed as kids and teens to see how chatbots like Gemini and ChatGPT responded to prompts about high-risk subjects, including suicide, sex, and drugs. This raises questions about the safeguards in AI systems.
Meanwhile, a researcher realized he could use Anthropic's Claude Opus 4.7 to break into the website of Front Gate and issue tickets to almost any United States music festival, including Lollapalooza and Bonnaroo, demonstrating the potential for AI to be exploited for malicious purposes.
Finally, WhatsApp has announced it will soon roll out usernames to billions of people, allowing connection without sharing phone numbers and increasing privacy protections. However, officials in India have raised concerns about the feature's implications for regulation and law enforcement.
These stories collectively underscore the evolving threat landscape in cybersecurity, affecting enterprises, governments, and individuals alike. For enterprise technology decision-makers, the Apple Hide My Email flaw is a stark reminder that even privacy-focused tools can have critical vulnerabilities, while the Scattered Spider case highlights the persistent risk of financially motivated hacking groups targeting companies.