Feds take notice of iOS vulnerabilities exploited under mysterious circumstances

Ars Technica
March 6, 2026
10 views
1 min read

Quick Insights

The Bottom Line

No summary provided.

AI Summary

The Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to patch three critical iOS vulnerabilities that were exploited over a 10-month period by three distinct hacking groups. These campaigns, detailed in a report by Google, utilized an advanced hacking kit named Coruna, which integrated 23 iOS exploits into five exploit chains. Although the vulnerabilities had been patched prior to Google's observation of Coruna's use, the kit posed a significant threat, particularly against older iOS versions, due to its sophisticated exploit code and non-public exploitation techniques. This directive underscores the ongoing risk posed by advanced exploit kits, even when targeting previously patched vulnerabilities.

What's Being Done

CISA directed federal agencies to patch three critical iOS vulnerabilities that were exploited by hacking groups.

Following this story?

Get notified when new coverage appears

Other Sources Covering This Story

1 source

Multiple outlets have reported on this story. Compare perspectives from different sources.

Should this be getting more attention?

You Might Have Missed

Related stories from different sources and perspectives

Feds move to dismiss charges against officers accused of falsifying warrant in Breonna Taylor raid - AP News
Government Transparency

Feds move to dismiss charges against officers accused of falsifying warrant in Breonna Taylor raid - AP News

<a href="https://news.google.com/rss/articles/CBMioAFBVV95cUxPaXlwSzJXbjR3Nm9aQzlEVXZNVUNyVWdYenVVTlIyMlM0eWYwUFlYOGdRVW1KZThydDBZLVlrSkNLdGxsWEdsaHd4SFBOUFFVem1tOHlyS3d0d1dMLWxpYkcxX0NkdkpNWFR1dWFvOHlaUXVfNjFBNWlXZ0xDSGtOd09ZT2dMdXhlUHJ3RXRac0dMTlRSMngyOUUxUVlabEJL?oc=5" target="_blank">Feds move to dismiss charges against officers accused of falsifying warrant in Breonna Taylor raid</a>&nbsp;&nbsp;<font color="#6f6f6f">AP News</font>

AP NewsMar 20
Feds say no need to recall Tesla's one-pedal driving despite petition
Technology

Feds say no need to recall Tesla's one-pedal driving despite petition

Ars TechnicaMar 20
A mysterious floral artist has taken over the New York Botanical Garden
Technology

A mysterious floral artist has taken over the New York Botanical Garden

Mr. Flower Fantastic is a graffiti artist turned floral designer who keeps his identity a secret. His new show is an ode to NYC in orchids. Oh, and did we mention he's allergic to flowers?

NPRMar 18
Trump mulls risky Kharg Island takeover to force Iran to open strait - Axios
National Security

Trump mulls risky Kharg Island takeover to force Iran to open strait - Axios

AxiosMar 20
Spyware once used by governments is now spreading to cybercriminals
National Security

Spyware once used by governments is now spreading to cybercriminals

<p>Cybercriminal groups are now using <a href="https://www.axios.com/2024/02/06/spyware-industry-proliferates-google" target="_blank">spyware</a> tools once utilized mainly by spies and law enforcement to hack into iPhones, new research shows.</p><p><strong>Why it matters</strong>: Anyone with an iPhone can now be the target of invasive malware that siphons off personal text messages, photos, notes and calendar data. </p><hr><p><strong>Driving the news</strong>: In the last month, researchers at Google, iVerify and Lookout uncovered two campaigns exploiting iPhone vulnerabilities.</p><ul><li>Earlier this month, Google researchers said they identified a sophisticated iPhone hacking toolkit, called <a href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit" target="_blank">Coruna</a>, originally built for an unnamed government customer that later ended up in the hands of a Chinese cybercriminal group. TechCrunch later <a href="https://techcrunch....

AxiosMar 21
Pentagon: Anthropic's foreign workforce poses security risks - Axios
National Security

Pentagon: Anthropic's foreign workforce poses security risks - Axios

AxiosMar 19
Read Next
US man pleads guilty to defrauding music streamers out of millions using AI
Technology

US man pleads guilty to defrauding music streamers out of millions using AI

<p>Michael Smith, 52, charged after flooding platforms with thousands of AI songs and boosting them with bots</p><ul><li><p><a href="https://www.theguardian.com/news/2026/feb/17/sign-up-for-the-breaking-news-us-email-to-get-newsletter-alerts-direct-to-your-inbox?utm_medium=ACQUISITIONS_STANDFIRST&amp;utm_campaign=BN22326&amp;utm_content=signup&amp;utm_term=standfirst&amp;utm_source=GUARDIAN_WEB">Sign up for the Breaking News US email to get newsletter alerts in your inbox</a></p></li></ul><p>A <a href="https://www.theguardian.com/us-news/northcarolina">North Carolina</a> man has pleaded guilty to defrauding music streaming platforms and his fellow musicians out of millions in royalties by flooding the services with thousands of AI-generated songs – and using automated “bots” to artificially boost the number of listens into the billions.</p><p>As part of a deal with federal prosecutors in <a href="https://www.theguardian.com/us-news/new-york">New York</a>’s southern district, 52-year...

Continue reading

Did this story change how you see things?

Stories like this only matter when people see them. Help us get verified journalism in front of more eyes.

Share this story

Get the daily digest

Save for later

The Verity Ledger curates verified investigative journalism from trusted sources only.

See our sources