惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
A
About on SuperTechFans
Vercel News
Vercel News
B
Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
The Cloudflare Blog
Jina AI
Jina AI
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
Hacking tool with possible US origins targets outdated iP...
Suhasini Srinivasaragavan · 2026-03-04 · via Enterprise – Silicon Republic

iPhone users should update their device to the latest iOS version to protect against such exploits.

Outdated iPhones are being targeted by a new and powerful exploit kit called ‘Coruna’, with potential nation-state origins.

According to Google Threat Intelligence Group (GTIG), Coruna targets iPhone models running iOS versions from 13.0 up to 17.2.1.

iVerify said Coruna is a significant example of spyware tech going from commercial surveillance vendors to nation-state actors, and then to mass-scale criminal operations, while also linking the exploit toolkit’s origins to the US government.

The exploit kit infects outdated iPhones visiting certain websites. It does not contain any specific targeting or one-time links, according to iVerify, meaning anyone who visited such a website while running a vulnerable iOS version could get infected, and also get re-infected multiple times.

“This is not typical for targeted attacks used by nation-states, but rather e-criminal groups,” noted iVerify.

The toolkit is “highly sophisticated, took millions of dollars to develop, and it bears the hallmarks of other modules that have been publicly attributed to the US government”, iVerify co-founder Rocky Cole said in a statement.

“This is the first example we’ve seen of very likely US government tools – based on what the code is telling us – spinning out of control and being used by both our adversaries and cybercriminal groups,” he added. iVerify also said that this is the first time mass exploitation against iOS devices has been observed amongst the public.

According to GTIG, Coruna’s threat lies in its comprehensive collection of iOS exploits, with the most advanced tools using non-public exploitation techniques and mitigation bypasses.

In one instance, GTIG observed that the toolkit was used by a suspected Russian espionage group to target Ukrainian users, while later, it was being used by a financially motivated threat actor operating from China.

How the toolkits are shared is unclear, GTIG said, while noting the possible existence of an “active market for ‘second-hand’ zero-day exploits”.

The Coruna exploit kit is only effective against older iOS versions, and iPhone users should update their device to the latest iOS version to protect against such exploits.

GTIG suggests using ‘Lockdown Mode’ in cases where the iPhone model is old and cannot update to the latest version. However, for most regular consumers, the highly restrictive Lockdown Mode is unnecessary.

Last month, Amazon Web Services highlighted how commercial AI is being used by “unsophisticated” criminals to scale cyberattacks on enterprises.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.