Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
iOS Exploit Kit Coruna Updates Past Exploits

iOS Exploit Kit Coruna Updates Past Exploits

Posted on March 27, 2026 By CWS

A recent analysis by Kaspersky has uncovered that the iOS exploit kit known as Coruna includes updated versions of kernel exploits originally seen in Operation Triangulation. This sophisticated exploit kit, identified in mid-2023, is capable of compromising iOS devices through zero-click iMessage attacks.

Unveiling the Coruna Exploit Kit

In 2023, Kaspersky reported that several iOS devices belonging to its senior employees were infiltrated by a sophisticated exploit kit. Coruna, described as possessing nation-state level capabilities, targets 23 different iOS vulnerabilities, including CVE-2023-32434 and CVE-2023-38606. These kernel vulnerabilities were previously exploited as zero-day flaws in Operation Triangulation.

According to Kaspersky’s recent findings, Coruna employs an updated version of these known exploits, indicating a connection to past cyber-espionage activities. The kernel exploits within Coruna utilize the same exploitation framework and demonstrate code similarities with other elements of the kit.

Unified Exploitation Framework

Kaspersky’s investigation suggests that Coruna was designed with a cohesive exploitation framework, rather than being a patchwork of different components. This strengthened framework appears to be an evolved version of the system used in Operation Triangulation. Notably, the updated exploits now incorporate checks for newer iOS versions and Apple processors, further demonstrating the continuity in source code across various exploits.

The enhanced framework, initially developed for espionage, is now being leveraged by a broader spectrum of cybercriminals, exposing millions of users with unpatched devices to potential threats. Given its modular nature, Kaspersky anticipates other threat actors will adopt this framework for future attacks.

Wider Implications and Threats

Coruna has been linked to a Russian state-sponsored group, UNC6353, which has used it in conjunction with another exploit kit, DarkSword, in cyber-attacks against Ukraine. Notably, a recent version of DarkSword was leaked on GitHub, potentially allowing lower-level cybercriminals to exploit millions of vulnerable iOS devices.

The widespread availability of such powerful exploit kits underscores the urgent need for users to update their devices and for security measures to evolve in tandem with emerging threats. The ongoing risk to millions of devices highlights the critical nature of cybersecurity vigilance.

As these exploit kits become more accessible, the cybersecurity community must remain proactive in developing strategies to mitigate their impact and protect users worldwide.

Security Week News Tags:cyber espionage, Cybersecurity, DarkSword, exploit kit, iOS security, Kaspersky, Operation Triangulation, Spyware, UNC6353, zero-click attacks

Post navigation

Previous Post: Bearlyfy Group Intensifies Cyber Attacks on Russian Firms
Next Post: PXA Stealer Targets Financial Firms with Phishing Attacks

Related Posts

136 NPM Packages Delivering Infostealers Downloaded 100,000 Times 136 NPM Packages Delivering Infostealers Downloaded 100,000 Times Security Week News
OpenAI Introduces Bug Bounty for AI Safety Risks OpenAI Introduces Bug Bounty for AI Safety Risks Security Week News
How TTP-based Defenses Outperform Traditional IoC Hunting How TTP-based Defenses Outperform Traditional IoC Hunting Security Week News
Surge in Cyberattacks Targeting Journalists: Cloudflare Surge in Cyberattacks Targeting Journalists: Cloudflare Security Week News
CISA Warns of Flaw in TeleMessage App Used by Ex-National Security Advisor  CISA Warns of Flaw in TeleMessage App Used by Ex-National Security Advisor  Security Week News
Cloudflare’s Strategic Layoffs Amidst AI Expansion Cloudflare’s Strategic Layoffs Amidst AI Expansion Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Vulnerability Exploited by Cybercriminals
  • AI-Powered Zero-Day Exploits Raise Cybersecurity Concerns
  • Frame Security Launches with $50M for AI Cyber Training
  • AI-Powered Zero-Day Exploit Bypasses 2FA Security
  • fsnotify Go Library Maintainer Changes Spark Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Vulnerability Exploited by Cybercriminals
  • AI-Powered Zero-Day Exploits Raise Cybersecurity Concerns
  • Frame Security Launches with $50M for AI Cyber Training
  • AI-Powered Zero-Day Exploit Bypasses 2FA Security
  • fsnotify Go Library Maintainer Changes Spark Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark