Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack  – CyberScoop
AttackFeed by Joe Wagner | Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack  - CyberScoop

Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack  – CyberScoop

Posted on March 3, 2026 By Tim Starks
Attack Feeds

An exploit kit that may have originated from a leaked U.S. government framework is behind what researchers are calling the first mass-scale attack on iOS, the operating system for Apple’s iPhones.

Traces of the exploits, found in the work of Chinese cybercriminals, also have been spotted in Russian attacks on Ukraine and used by a customer of a spyware vendor.

Those conclusions come from two pieces of research that Google Threat Intelligence Group and iVerify released separately Tuesday. Rocky Cole, co-founder of iVerify, said it represented a potential “EternalBlue moment,” with echoes of that exploit software escaping the National Security Agency to fuel the global WannaCry ransomware and NotPetya attacks in 2017.

Google said that the so-called Coruna exploit kit that’s the subject of Tuesday’s research “provides another example of how sophisticated capabilities proliferate,” as it wrote in a blog post about the zero-day — or previously undisclosed and unpatched — exploits.

“How this proliferation occurred is unclear, but suggests an active market for ‘second hand’ zero-day exploits,” Google wrote. “Beyond these identified exploits, multiple threat actors have now acquired advanced exploitation techniques that can be re-used and modified with newly identified vulnerabilities.”

Said iVerify: “While iVerify has some evidence that this tool is a leaked U.S. government framework, that shouldn’t overshadow the knowledge that these tools will find their way into the wild and will be used unscrupulously by bad actors.”

Just last week, a U.S. court sentenced a former L3 Harris executive to prison for selling zero-day exploits to a Russian broker.

Both Google and iVerify connected the exploit kit to Operation Triangulation, which Russian cybersecurity firm Kaspersky said in 2023 had targeted the company and the Russian government attributed to the U.S. government. The NSA declined to comment on that allegation.

An Apple spokesperson didn’t respond to a request for comment Tuesday afternoon. Apple issued multiple patches in response to Operation Triangulation, and worked with Google on the newest research.

Spencer Parker, chief product officer at iVerify, said the attack affected at least 42,000 devices —a “massive number” for iOS, even if it sounds small to other platforms. That number has the potential to expand as researchers dive further into the technical details, Cole said.

Other signs point to U.S. development of the exploit kit, Cole said.

“The code base for the framework and the exploits was superb,” he said. “It was elegantly written. It’s fluid and holds together very well. There were comments in the code that, as someone who’s been around the U.S. defense industrial base for years, really are reminiscent of the sort of insider jokes and insider remarks that you might see from a U.S. based coder. Certainly they were native English language speakers.”

Google said it tracked the use of the exploit kit over the course of last year in operations from an unnamed customer of a surveillance vendor to attacks on Ukrainian users from a suspected Russian espionage group, before retrieving the complete exploit kit from a financially motivated group operating out of China.

Apple-focused security researcher Patrick Wardle observed on the social media site X about the Coruna research: “Turns out even lowly cybercriminals were (ab)using 0days to hack Apple devices.”

The post Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: CISA CIO Robert Costello exits agency  – CyberScoop
Next Post: CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  - The Hacker News
Attack Feeds
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  – The Hacker News
April 2, 2026
AttackFeed by Joe Wagner | CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026  - The Hacker News
Attack Feeds
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026  – The Hacker News
March 21, 2026
AttackFeed by Joe Wagner | SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks  - The Hacker News
Attack Feeds
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks  – The Hacker News
February 25, 2026
AttackFeed by Joe Wagner | CrowdStrike says attackers are moving through networks in under 30 minutes  - CyberScoop
Attack Feeds
CrowdStrike says attackers are moving through networks in under 30 minutes  – CyberScoop
February 24, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.