Edizione del 03.07.2026
Apple Hide My Email Flaw Exposes Users’ Real Email Addresses
A reported vulnerability in Apple’s iCloud+ Hide My Email service allows an attacker with only a relay alias to uncover the user’s real email address, defeating a privacy feature widely used to mask identity. Researcher Tyler Murphy of EasyOptOuts said he disclosed the issue to Apple in June 2025, and multiple outlets reported that 404 Media independently verified the flaw by recovering a reporter’s actual Apple ID email from a newly created alias. Public reporting says the issue requires no account compromise, special access, or social engineering, raising risks of phishing, spam correlation, account linkage, and exposure of personal details through people-search services.
Apple reportedly acknowledged the bug in 2025 and later told Murphy that a system change had addressed it, but follow-up testing found the deanonymization still worked more than a year after disclosure. Murphy said volunteer testing showed all tested aliases were reversible, though the full scope across the user base remains unclear, and exact exploitation details were withheld while Apple continued investigating. As of the reports, Apple had not issued a public advisory or CVE, and separate coverage noted that Apple’s planned migration of masked addresses to the
Apple reportedly acknowledged the bug in 2025 and later told Murphy that a system change had addressed it, but follow-up testing found the deanonymization still worked more than a year after disclosure. Murphy said volunteer testing showed all tested aliases were reversible, though the full scope across the user base remains unclear, and exact exploitation details were withheld while Apple continued investigating. As of the reports, Apple had not issued a public advisory or CVE, and separate coverage noted that Apple’s planned migration of masked addresses to the
@private.icloud.com domain could make Hide My Email aliases easier for websites and apps to identify and block.ChocoPoC RAT Spread Through Trojanized GitHub PoC Exploit Repositories
A malware campaign dubbed ChocoPoC used fake or trojanized GitHub proof-of-concept exploit repositories for newly disclosed CVEs to infect cybersecurity researchers, penetration testers, and bug hunters. Researchers at Sekoia and YesWeHack said the visible exploit code often appeared benign, while the real payload was introduced through malicious PyPI dependencies including
Once activated, ChocoPoC provided remote shell and Python execution, stole browser credentials and files, uploaded data, enumerated processes, and collected host details such as network configuration and shell history. The malware was designed to evade casual review and simple sandboxing by delaying activation until the PoC was run, while also using DNS-over-HTTPS to resolve infrastructure and
frint and skytext. The package chain decrypted and executed code that fetched the final Python-based remote access trojan from a Mapbox dataset, and investigators linked at least seven repositories to the operation. The activity appears to have relied largely on compromised accounts to publish the poisoned packages and repositories, with skytext alone drawing roughly 2,400 downloads, mostly on Linux systems.Once activated, ChocoPoC provided remote shell and Python execution, stole browser credentials and files, uploaded data, enumerated processes, and collected host details such as network configuration and shell history. The malware was designed to evade casual review and simple sandboxing by delaying activation until the PoC was run, while also using DNS-over-HTTPS to resolve infrastructure and
91.132.163.78 for larger uploads. Investigators said related activity may date back to late 2025 through earlier packages such as slogsec and logcrypt.cryptography, raising concern that compromises of researcher workstations could create downstream supply-chain risk for trusted security tooling and frameworks.Pegasus Infected European Parliament Spyware Investigator’s iPhone
Citizen Lab found that the iPhone of former European Parliament member Stelios Kouloglou was infected twice with NSO Group’s Pegasus spyware, in October 2022 and March 2023, while he served on the Parliament’s PEGA Committee investigating spyware abuse across Europe. Researchers said the attacks used a zero-click exploit against an Apple iPhone vulnerability that had been patched but not installed on the device, potentially giving the operator access to private messages, location data, photos, and even ambient audio without any user interaction.
The infections occurred during sensitive PEGA work, including hearings and draft reporting on alleged spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain, intensifying concerns that commercial spyware was used against a lawmaker scrutinizing its misuse. Citizen Lab did not name the government behind the operation, but said the same Pegasus-linked email address and infrastructure overlapped with an earlier cluster targeting Russian- and Belarusian-speaking journalists and opposition figures, strongly suggesting a common operator with cross-border reach; Kouloglou has said he believes he was targeted because of his committee role and plans to sue NSO Group.
The infections occurred during sensitive PEGA work, including hearings and draft reporting on alleged spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain, intensifying concerns that commercial spyware was used against a lawmaker scrutinizing its misuse. Citizen Lab did not name the government behind the operation, but said the same Pegasus-linked email address and infrastructure overlapped with an earlier cluster targeting Russian- and Belarusian-speaking journalists and opposition figures, strongly suggesting a common operator with cross-border reach; Kouloglou has said he believes he was targeted because of his committee role and plans to sue NSO Group.
PamStealer macOS Infostealer Uses Fake Maccy Apps and PAM Password Validation
Researchers have identified PamStealer, a previously unseen macOS malware family distributed through fake websites impersonating the legitimate Maccy clipboard manager. The infection begins with a trojanized disk image and a compiled AppleScript lure that tells users to press Command-R in Script Editor, a step that executes malicious code while sidestepping macOS
PamStealer stands out for validating stolen passwords locally through macOS Pluggable Authentication Modules (PAM), repeatedly prompting victims until the correct password is entered before exfiltration. Researchers said the malware is environment-aware, targets Apple Silicon systems, avoids analysis environments, and excludes devices tied to several Eastern European locales and time zones. It also delays Full Disk Access prompts, establishes persistence, and hides app bundles by impersonating Finder or Software Update components, while displaying decoy error messages to make victims think the fake application simply failed to launch.
com.apple.quarantine protections. The malware then deploys a Rust-based second stage that downloads additional payloads, steals browser data, clipboard contents, iCloud Keychain information, and login credentials, and sends the data to attacker-controlled infrastructure over encrypted command-and-control channels.PamStealer stands out for validating stolen passwords locally through macOS Pluggable Authentication Modules (PAM), repeatedly prompting victims until the correct password is entered before exfiltration. Researchers said the malware is environment-aware, targets Apple Silicon systems, avoids analysis environments, and excludes devices tied to several Eastern European locales and time zones. It also delays Full Disk Access prompts, establishes persistence, and hides app bundles by impersonating Finder or Software Update components, while displaying decoy error messages to make victims think the fake application simply failed to launch.
Anthropic Publishes Claude Fable 5 Cyber Safeguards and Jailbreak Severity Framework
Anthropic said it has globally re-deployed Claude Fable 5 with updated cybersecurity controls and released new technical details on how the model handles cyber-related prompts. The company said the system uses safety classifiers to sort requests into prohibited, high-risk dual-use, low-risk dual-use, and benign categories rather than blocking all security activity, allowing some defensive and educational use while aiming to stop harmful assistance. Anthropic said prohibited requests include malware development, ransomware, wipers, data exfiltration, defense evasion, offensive infrastructure such as
Anthropic also published an early draft Cyber Jailbreak Severity (CJS) framework, developed with Glasswing, to rate AI jailbreaks from
C2, destructive attacks, and cyber-physical sabotage, and that the model applies a larger safety margin than earlier versions to reduce dangerous outputs even if that increases false positives.Anthropic also published an early draft Cyber Jailbreak Severity (CJS) framework, developed with Glasswing, to rate AI jailbreaks from
CJS-0 to CJS-4 based on capability gain, breadth of impact, ease of weaponization, and discoverability. The company said the framework is intended to create a shared vocabulary for assessing jailbreak risk across industry and government, particularly for cases involving high-uplift vulnerability discovery or exploit generation. Anthropic invited external feedback through a dedicated contact channel and launched a HackerOne bug bounty program for researchers to report potential cyber jailbreaks affecting Fable 5.