LIVE · cybersecurity feed
Live wire
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructureOpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
nation-state

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.

zeroday.news ·

Reports indicate a significant proliferation of sophisticated iPhone exploit chains, specifically "Coruna" and "DarkSword," which were previously understood to be the exclusive domain of nation-state actors. These advanced iOS exploits are now reportedly being adopted and utilized by organized cybercrime groups on a global scale, marking a notable shift in the landscape of mobile device threats.

The "Coruna" and "DarkSword" exploits are described as sophisticated chains, implying they likely involve multiple vulnerabilities chained together to achieve persistent access or elevated privileges on iOS devices. This class of exploit often bypasses multiple layers of security, including sandboxing and memory protections, to execute arbitrary code or exfiltrate sensitive data. Such chains typically target zero-day vulnerabilities, meaning flaws unknown to the vendor, making them particularly difficult to detect and defend against without prior knowledge of their existence.

These types of exploits commonly target the core operating system and its components, potentially affecting a wide range of iPhone models and iOS versions. The specific mechanisms could involve vulnerabilities in web browsers, messaging applications, or even system services that process untrusted input. Successful exploitation often grants attackers the ability to remotely access device data, monitor communications, or install additional malicious software without the user's knowledge or interaction.

The affected product in this instance is Apple's iOS, running on iPhone devices. Products in this category are frequently targeted due to their widespread adoption and the valuable data they store. The vendor, Apple, regularly releases security updates to patch identified vulnerabilities. However, sophisticated exploit chains like those described often leverage flaws that are either newly discovered or have not yet been publicly disclosed, making immediate mitigation challenging.

For users, typical mitigation guidance for this class of issue includes keeping devices updated to the latest iOS version, as these updates often contain patches for known vulnerabilities. Avoiding suspicious links or attachments, even from seemingly trusted sources, is also crucial, as some exploits may be delivered via phishing or drive-by downloads. Additionally, regularly backing up data and using strong, unique passcodes can help limit the impact of a successful compromise.

The reported expansion of "Coruna" and "DarkSword" from nation-state arsenals to organized cybercrime groups underscores a concerning trend in the democratization of advanced cyber capabilities. This shift suggests that highly effective and previously exclusive offensive tools are becoming more accessible, potentially leading to an increase in targeted attacks against a broader range of individuals and organizations. It highlights the ongoing need for robust security research, rapid vulnerability patching, and heightened user awareness in the face of evolving mobile threats.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

NATO and an AI startup can now name and track software vulnerabilities

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company […] The post NATO and an AI startup can now nam

ransomwarecritical

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

vulnerability

OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users

OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]

security

Everything we launched during Agents Week

Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar.

ransomware

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.