惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Forbes - Security
Forbes - Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LangChain Blog
量子位
GbyAI
GbyAI
B
Blog RSS Feed
月光博客
月光博客
人人都是产品经理
人人都是产品经理
腾讯CDC
Recent Announcements
Recent Announcements
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The Cloudflare Blog
D
Docker
Cyberwarzone
Cyberwarzone
U
Unit 42
NISL@THU
NISL@THU
C
Check Point Blog
B
Blog
大猫的无限游戏
大猫的无限游戏
Cisco Talos Blog
Cisco Talos Blog
Recorded Future
Recorded Future
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
G
GRAHAM CLULEY
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 叶小钗
P
Proofpoint News Feed
F
Fortinet All Blogs
V
V2EX
T
Threat Research - Cisco Blogs
T
Threatpost
S
SegmentFault 最新的问题
Know Your Adversary
Know Your Adversary
雷峰网
雷峰网
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
博客园 - 司徒正美
P
Privacy & Cybersecurity Law Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
TaoSecurity Blog
TaoSecurity Blog
Latest news
Latest news
Apple Machine Learning Research
Apple Machine Learning Research
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Y
Y Combinator Blog
P
Privacy International News Feed
L
Lohrmann on Cybersecurity
AWS News Blog
AWS News Blog
G
Google Developers Blog
美团技术团队

The Register - Security: Research

www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Perplexity Comet browser hole was exploitable via cal invite DEF CON hackers 'fed up with government,' Jake Braun says DEF CON hackers 'fed up with government,' Jake Braun says Ransomware payments cratered in 2025 – attacks did not Ransomware payments cratered in 2025 – attacks did not Claude's collaboration tools allowed remote code execution AI takes a swing at online anonymity Fake 'interview' repos lure Next.js devs into running secret-stealing malware Threat intelligence supply chain is full of weak links AI agents abound, unbound by rules or safety disclosures RAT disguised as an RMM costs crims $300 a month Android malware taps Gemini to navigate infected devices Posting AI caricatures on social media is bad for security Payroll pirates conned the help desk, stole employee’s pay Microsoft boffins show LLM safety can be trained away For the price of Netflix, crooks can rent AI crime ops For the price of Netflix, crooks can rent AI crime ops Fast Pair, loose security: Bluetooth accessories open to silent hijack Fast Pair flaw exposes Bluetooth devices to hijacking A simple CodeBuild flaw put every AWS environment at risk A simple CodeBuild flaw put every AWS environment at risk DeadLock ransomware uses smart contracts to evade defenders Python libraries in AI/ML models can be poisoned w metadata OpenAI patches déjà vu prompt injection vuln in ChatGPT Fake Windows BSODs check in at Europe's hotels to con staff into running malware Hotel staff tricked into installing malware by bogus BSODs Your car’s web browser may be on the road to cyber ruin China's Ink Dragon hides out in European government networks Browser 'privacy' extensions have eye on your AI, log all your chats NCSC finds cyber deception tools work, if deployed right 10K Docker images spray live cloud creds across the internet 'Botnets in physical form' are top humanoid robot risk 'Botnets in physical form' are top humanoid robot risk Apache warns of 10.0-rated flaw in Tika metadata toolkit Novel clickjacking attack relies on CSS and SVG 'Exploitation is imminent' of max-severity React bug Swiss government bans SaaS and cloud for sensitive info Scattered Lapsus$ Hunters stress testing Zendesk weak spots HashJack attack shows AI browsers can be fooled with '#' New ClickFix attacks use fake Windows Updates to swipe creds Years-old bugs in open source took out major clouds at risk LLM-generated malware improving, but not operational (yet) 3.5B WhatsApp users' info scooped through enumeration flaw 3.5B WhatsApp users' info scooped through enumeration flaw 50k more ASUS routers pwned by evolving Beijing-linked op Overconfidence is the new zero-day as teams stumble through cyber simulations LLM side-channel attack could allow snoops to guess topic Landfall spyware used in 0-day attacks on Samsung phones MIT Sloan shelves paper about AI-driven ransomware Security hole slams Chromium browsers - no fix yet OpenAI Atlas Browser tripped up by malformed URLs Devs of VS Code extensions are leaking secrets en masse Chatbots that butter you up make you worse at conflict Tile trackers leak unencrypted Bluetooth data, say boffins Beijing's RedNovember hacked critical US, global orgs Lazarus RAT code resurfaces in North Korean IT-worker scams Suspected Chinese spies broke into 'numerous' enterprises Deepfaked calls hit 44% of businesses in last year: Gartner Kaspersky: RevengeHotels returns with AI-coded malware Ruh-roh. DDR5 memory vulnerable to new Rowhammer attack HybridPetya ransomware dodges UEFI Secure Boot
Kaspersky: No signs Coruna iPhone exploit kit made by US
Connor Jones Connor Jones · 2026-03-04 · via The Register - Security: Research

Security

Kaspersky dismisses claims Coruna iPhone exploit kit is connected to NSA-linked operation

Follows suggestions iPhone-pwning toolset bears hallmarks of zero-days that targeted Russian diplomats

Russian cybersecurity outfit Kaspersky is waving away claims that an iPhone exploit kit recently uncovered by Google was developed by the same people who were behind a group of zero-days that allegedly compromised thousands of Russian diplomats in a 2023 campaign.

After Google's Threat Intelligence Group (GTIG) published its findings on the Coruna exploit kit this week, some experts were quick to point fingers at the National Security Agency, suggesting it was behind the attacks seen in Ukraine and China over the past 12 months.

While GTIG made no such suggestions itself, the crossover between some of the same vulnerabilities used in 2023's Operation Triangulation, which Moscow alleged was a National Security Agency job, and those that comprise Coruna, raised questions about how involved the US was in the development and/or use of the exploit kit.

Rocky Cole, cofounder of iVerify, told Wired after reviewing Coruna's code that he believed the US may have been behind Coruna's development.

"It's highly sophisticated, took millions of dollars to develop, and it bears the hallmarks of other modules that have been publicly attributed to the US government," he said. 

"This is the first example we've seen of very likely US government tools – based on what the code is telling us – spinning out of control and being used by both our adversaries and cybercriminal groups."

However, Boris Larin, principal security researcher at Kaspersky GReAT, told The Register on Wednesday: "We see no evidence of actual code reuse in the published reports to support attributing Coruna to the same authors."

What is Coruna?

In a report published on Tuesday, Google said that around a year ago it identified a highly sophisticated and previously unknown iPhone exploit kit, perhaps used by commercial spyware vendors and/or state-sponsored hackers, that could bork a device if a user visited a website.

Internally known as Coruna, the kit comprises 23 distinct vulnerabilities that target iOS versions 13-17.2.1, released in September 2019 and December 2023 respectively, which in turn are used in five unique full exploit chains.

The company first started tracking Coruna in February 2025, after capturing "parts of an iOS exploit chain used by a customer of a surveillance company." 

Through various campaigns since then, GTIG learned more about its makeup, with the most advanced exploits using non-public techniques bundled into novel JavaScript frameworks to pwn iPhones.

Among those various campaigns, researchers said they had seen Coruna being used by unique groups for very different means, and because of this it suggests there may be an active, underexplored market for second-hand zero-days catering to the most well-resourced buyers.

Suggesting some degree of Russian use, in summer 2025 GTIG saw some campaigns targeting Ukrainian websites related to a range of matters such as industrial equipment, local services, and ecommerce.

The JavaScript framework was hosted on a website loaded as a hidden iFrame on these compromised websites, and only delivered to selected iPhone users from a "specific geolocation," GTIG said.

At the end of 2025, the same framework was also being hosted by "a very large set of fake Chinese websites," most of which related to finance and cryptocurrency. 

The websites were crafted to encourage users to visit them on their iOS devices, and in doing so, the hidden iFrame was injected and the exploit kit was installed.

English language raises questions

One of the main turning points in Coruna's discovery was when GTIG spotted that one operator of the exploit kit deployed the debug version of it, which in turn revealed all the exploits that comprised Coruna.

This discovery also led the researchers to understand that all the exploits' codenames were written in English. CVE-2024-23222 (8.8), a WebKit bug, was codenamed "cassowary," for example, and CVE-2020-27932 (7.8), a kernel type confusion flaw, was referred to as "Neutron," to name only two.

The crossover with Operation Triangulation

Of particular interest were CVE-2023-32434 (7.8) and CVE-2023-38606 (5.5), codenamed Photon and Gallium respectively, two vulnerabilities that were exploited as part of the four zero-days that underpinned Operation Triangulation.

Operation Triangulation was itself publicized by Kaspersky in 2023, which the FSB alleged at the time was a National Security Agency job.

It also remains entirely possible that Photon and Gallium were stripped from the Triangulation exploit package and added to Coruna after Kaspersky uncovered the attacks, or were unwittingly mimicked by equally talented attackers.

iVerify's Cole was among those who publicly raised the questions surrounding the US and its involvement, although Kaspersky's Larin dismissed this.

"[Photon and Gallium] are not trivial bugs – we know that firsthand," Larin said. "CVE-2023-32434 gives an attacker full control over the deepest layer of iOS – the kernel, which governs everything the phone does. CVE-2023-38606 goes a step further: it exploited a previously undocumented feature of Apple's own chips to bypass security protections that operate at the hardware level.

"But a vulnerability is not a component. Both CVEs now have publicly available implementations – any sufficiently skilled team could write their own exploits without ever seeing the Triangulation code. We see no evidence of actual code reuse in the published reports to support attributing Coruna to the same authors."

The Register has asked the NSA for comment. 

GTIG provided full technical details of how the exploit kit executes, along with indicators of compromise (IOCs), via its blog post on Coruna. ®