Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Expands KEV List with iOS Vulnerability Additions

CISA Expands KEV List with iOS Vulnerability Additions

Posted on March 6, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has recently expanded its Known Exploited Vulnerabilities (KEV) list to include five new security flaws. Among these are three significant vulnerabilities exploited by the Coruna iOS exploit kit, a tool known for its advanced targeting capabilities against Apple’s mobile operating system.

Coruna Exploit Kit Targets iOS Versions

The Coruna exploit kit has been utilized to exploit 23 different vulnerabilities across iOS versions 13.0 to 17.2.1. However, it is important to note that the latest versions of iOS remain unaffected. The kit has seen deployment by various threat actors, including a spyware vendor’s client, a Russian espionage group, and a financially motivated Chinese organization.

Coruna operates by leveraging ‘second-hand’ zero-day vulnerabilities, allowing it to fingerprint devices and deploy suitable WebKit remote code execution (RCE) exploits. This sophisticated approach circumvents platform defenses to inject a payload into the ‘powerd’ daemon running at root level, primarily targeting financial data and sensitive information from various apps.

Security Flaws and Patching Efforts

Out of the 23 vulnerabilities targeted by Coruna, 12 have been officially assigned CVE identifiers, with the remaining public disclosures having been addressed through patches. Nine of these were previously identified as exploited, often as zero-day vulnerabilities, including notable CVEs such as CVE-2022-48503 and CVE-2024-23222.

Three additional CVEs (CVE-2021-30952, CVE-2023-41974, and CVE-2023-43000) were highlighted with no prior public reports of exploitation until the Coruna kit was found targeting them. CISA’s inclusion of these flaws in the KEV list mandates federal agencies to identify and patch vulnerable devices within three weeks, as per Binding Operational Directive (BOD) 22-01.

Broader Implications and Recommendations

In addition to the iOS vulnerabilities, CISA has alerted organizations to older vulnerabilities in Hikvision and Rockwell products that have been actively exploited. While the directive primarily targets federal agencies, all organizations are encouraged to prioritize addressing vulnerabilities listed in the KEV catalog to mitigate potential threats.

The ongoing efforts to update and expand the KEV list underscore the critical need for organizations to maintain robust cybersecurity measures and ensure timely patch management to protect against emerging threats.

Related updates from Google and Apple highlight the broader industry trends, with insights into zero-day exploits and the importance of staying ahead of potential cyberattacks.

Security Week News Tags:CISA, Coruna exploit kit, cyber threats, Cybersecurity, federal compliance, Hikvision vulnerabilities, iOS vulnerabilities, patch management, WebKit RCE, zero-day exploits

Post navigation

Previous Post: Iranian Hackers Target U.S. Networks with New Malware
Next Post: FBI Captures Contractor for $46 Million Cryptocurrency Theft

Related Posts

Censys Secures M to Boost Internet Intelligence Censys Secures $70M to Boost Internet Intelligence Security Week News
Cape Secures 0 Million to Enhance Cellular Security Cape Secures $100 Million to Enhance Cellular Security Security Week News
WitnessAI Raises  Million for AI Security Platform WitnessAI Raises $58 Million for AI Security Platform Security Week News
Major Firms Release New ICS Security Advisories Major Firms Release New ICS Security Advisories Security Week News
NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch Security Week News
CrowdStrike to Buy Identity Security Firm SGNL for 0 Million in Cash CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms
  • Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit
  • PureRAT Malware Utilizes PNG Files for Stealthy Attacks
  • SystemBC Server Uncovers 1,570 Victims in Ransomware Operation
  • AI-Enhanced NGate Malware Targets NFC Payment Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms
  • Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit
  • PureRAT Malware Utilizes PNG Files for Stealthy Attacks
  • SystemBC Server Uncovers 1,570 Victims in Ransomware Operation
  • AI-Enhanced NGate Malware Targets NFC Payment Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark