Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
iOS Exploit Kit Coruna Updates Past Exploits

iOS Exploit Kit Coruna Updates Past Exploits

Posted on March 27, 2026 By CWS

A recent analysis by Kaspersky has uncovered that the iOS exploit kit known as Coruna includes updated versions of kernel exploits originally seen in Operation Triangulation. This sophisticated exploit kit, identified in mid-2023, is capable of compromising iOS devices through zero-click iMessage attacks.

Unveiling the Coruna Exploit Kit

In 2023, Kaspersky reported that several iOS devices belonging to its senior employees were infiltrated by a sophisticated exploit kit. Coruna, described as possessing nation-state level capabilities, targets 23 different iOS vulnerabilities, including CVE-2023-32434 and CVE-2023-38606. These kernel vulnerabilities were previously exploited as zero-day flaws in Operation Triangulation.

According to Kaspersky’s recent findings, Coruna employs an updated version of these known exploits, indicating a connection to past cyber-espionage activities. The kernel exploits within Coruna utilize the same exploitation framework and demonstrate code similarities with other elements of the kit.

Unified Exploitation Framework

Kaspersky’s investigation suggests that Coruna was designed with a cohesive exploitation framework, rather than being a patchwork of different components. This strengthened framework appears to be an evolved version of the system used in Operation Triangulation. Notably, the updated exploits now incorporate checks for newer iOS versions and Apple processors, further demonstrating the continuity in source code across various exploits.

The enhanced framework, initially developed for espionage, is now being leveraged by a broader spectrum of cybercriminals, exposing millions of users with unpatched devices to potential threats. Given its modular nature, Kaspersky anticipates other threat actors will adopt this framework for future attacks.

Wider Implications and Threats

Coruna has been linked to a Russian state-sponsored group, UNC6353, which has used it in conjunction with another exploit kit, DarkSword, in cyber-attacks against Ukraine. Notably, a recent version of DarkSword was leaked on GitHub, potentially allowing lower-level cybercriminals to exploit millions of vulnerable iOS devices.

The widespread availability of such powerful exploit kits underscores the urgent need for users to update their devices and for security measures to evolve in tandem with emerging threats. The ongoing risk to millions of devices highlights the critical nature of cybersecurity vigilance.

As these exploit kits become more accessible, the cybersecurity community must remain proactive in developing strategies to mitigate their impact and protect users worldwide.

Security Week News Tags:cyber espionage, Cybersecurity, DarkSword, exploit kit, iOS security, Kaspersky, Operation Triangulation, Spyware, UNC6353, zero-click attacks

Post navigation

Previous Post: Bearlyfy Group Intensifies Cyber Attacks on Russian Firms
Next Post: PXA Stealer Targets Financial Firms with Phishing Attacks

Related Posts

AI Emerges as the Hope—and Risk—for Overloaded SOCs AI Emerges as the Hope—and Risk—for Overloaded SOCs Security Week News
Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms Security Week News
GRC Firm Vanta Raises 0 Million at .15 Billion Valuation GRC Firm Vanta Raises $150 Million at $4.15 Billion Valuation Security Week News
Docker Makes 1,000 Hardened Images Free and Open Source Docker Makes 1,000 Hardened Images Free and Open Source Security Week News
Hackers Access Legacy Systems in Oxford City Council Cyberattack Hackers Access Legacy Systems in Oxford City Council Cyberattack Security Week News
Critical Vulnerability Threatens 300,000 Ollama Deployments Critical Vulnerability Threatens 300,000 Ollama Deployments Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Claude Campaign Utilizes PlugX-Like DLL Sideloading
  • Critical cPanel Vulnerability Exploited by Cybercriminals
  • AI-Powered Zero-Day Exploits Raise Cybersecurity Concerns
  • Frame Security Launches with $50M for AI Cyber Training
  • AI-Powered Zero-Day Exploit Bypasses 2FA Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Claude Campaign Utilizes PlugX-Like DLL Sideloading
  • Critical cPanel Vulnerability Exploited by Cybercriminals
  • AI-Powered Zero-Day Exploits Raise Cybersecurity Concerns
  • Frame Security Launches with $50M for AI Cyber Training
  • AI-Powered Zero-Day Exploit Bypasses 2FA Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark