Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
iOS Exploit Kit Coruna Updates Past Exploits

iOS Exploit Kit Coruna Updates Past Exploits

Posted on March 27, 2026 By CWS

A recent analysis by Kaspersky has uncovered that the iOS exploit kit known as Coruna includes updated versions of kernel exploits originally seen in Operation Triangulation. This sophisticated exploit kit, identified in mid-2023, is capable of compromising iOS devices through zero-click iMessage attacks.

Unveiling the Coruna Exploit Kit

In 2023, Kaspersky reported that several iOS devices belonging to its senior employees were infiltrated by a sophisticated exploit kit. Coruna, described as possessing nation-state level capabilities, targets 23 different iOS vulnerabilities, including CVE-2023-32434 and CVE-2023-38606. These kernel vulnerabilities were previously exploited as zero-day flaws in Operation Triangulation.

According to Kaspersky’s recent findings, Coruna employs an updated version of these known exploits, indicating a connection to past cyber-espionage activities. The kernel exploits within Coruna utilize the same exploitation framework and demonstrate code similarities with other elements of the kit.

Unified Exploitation Framework

Kaspersky’s investigation suggests that Coruna was designed with a cohesive exploitation framework, rather than being a patchwork of different components. This strengthened framework appears to be an evolved version of the system used in Operation Triangulation. Notably, the updated exploits now incorporate checks for newer iOS versions and Apple processors, further demonstrating the continuity in source code across various exploits.

The enhanced framework, initially developed for espionage, is now being leveraged by a broader spectrum of cybercriminals, exposing millions of users with unpatched devices to potential threats. Given its modular nature, Kaspersky anticipates other threat actors will adopt this framework for future attacks.

Wider Implications and Threats

Coruna has been linked to a Russian state-sponsored group, UNC6353, which has used it in conjunction with another exploit kit, DarkSword, in cyber-attacks against Ukraine. Notably, a recent version of DarkSword was leaked on GitHub, potentially allowing lower-level cybercriminals to exploit millions of vulnerable iOS devices.

The widespread availability of such powerful exploit kits underscores the urgent need for users to update their devices and for security measures to evolve in tandem with emerging threats. The ongoing risk to millions of devices highlights the critical nature of cybersecurity vigilance.

As these exploit kits become more accessible, the cybersecurity community must remain proactive in developing strategies to mitigate their impact and protect users worldwide.

Security Week News Tags:cyber espionage, Cybersecurity, DarkSword, exploit kit, iOS security, Kaspersky, Operation Triangulation, Spyware, UNC6353, zero-click attacks

Post navigation

Previous Post: Bearlyfy Group Intensifies Cyber Attacks on Russian Firms
Next Post: PXA Stealer Targets Financial Firms with Phishing Attacks

Related Posts

Enhanced Governance Critical for Securing AI Systems Enhanced Governance Critical for Securing AI Systems Security Week News
Chrome 137 Update Patches High-Severity Vulnerabilities Chrome 137 Update Patches High-Severity Vulnerabilities Security Week News
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Security Week News
Amazon Ends Partnership with Flock Safety Amid Criticism Amazon Ends Partnership with Flock Safety Amid Criticism Security Week News
Code Execution Vulnerabilities Patched in Veeam, BeyondTrust Products Code Execution Vulnerabilities Patched in Veeam, BeyondTrust Products Security Week News
Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Introduces Bug Bounty for AI Safety Risks
  • New Phishing Attack Targets TikTok Business Accounts
  • Cyberattack Targets South Asian Financial Firm with Custom Malware
  • RSAC 2026: Key Highlights from Days 3-4
  • Telnyx Package Breach: TeamPCP’s Latest Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Introduces Bug Bounty for AI Safety Risks
  • New Phishing Attack Targets TikTok Business Accounts
  • Cyberattack Targets South Asian Financial Firm with Custom Malware
  • RSAC 2026: Key Highlights from Days 3-4
  • Telnyx Package Breach: TeamPCP’s Latest Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark