Apple has long marketed itself as the privacy-first tech giant. So why is it making a change to Hide My Email that will make it easier for websites to block anonymous sign-ups - and harder for you to stay private online? Read more in my art

Apple is changing its Hide My Email feature, a move that privacy advocates argue will diminish its effectiveness. The company plans to shift newly generated aliases from the "@icloud.com" domain to "@private.icloud.com" later this summer.
Hide My Email allows users to create unique, random email addresses that forward messages to their primary inbox. This feature is designed to protect users' personal email addresses from spam, marketing lists, and data brokers by allowing them to sign up for services without revealing their real email. Users can also delete aliases if they wish to stop receiving emails from a particular service.
The core privacy benefit of the previous system was that "@icloud.com" aliases were indistinguishable from regular iCloud email addresses. This made it difficult for websites or apps to determine if an email address belonged to a genuine Apple user or someone using the privacy feature. However, the new "@private.icloud.com" domain explicitly identifies an address as a Hide My Email alias.
This change means that websites and applications that wish to block anonymous sign-ups can now easily reject any email address ending with "@private.icloud.com." This could render the feature less useful for users seeking to sign up anonymously for services that may discourage or block such registrations.
Existing Hide My Email addresses will continue to function as before. However, any new aliases created after the change will be issued on the new domain.
The announcement has drawn criticism from some Apple users, particularly on platforms like Reddit, where users expressed disappointment that the feature's utility for anonymous sign-ups would be significantly reduced.
It is important to note that Hide My Email does not guarantee complete anonymity. Earlier this year, it was reported that Apple provided law enforcement with the account details of a Hide My Email user who allegedly sent threatening messages. This incident serves as a reminder that the feature's privacy protections are not absolute and can be subject to legal requests.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.