
On March 5, 2026, the CISA (Cybersecurity and Infrastructure Security Agency) officially added three iOS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of their use in crypto-theft and cyberespionage campaigns. Federal agencies have been ordered to patch these flaws by March 26, 2026.
The “Coruna” Exploit Kit
The vulnerabilities are part of a sophisticated exploit kit dubbed Coruna, first identified by Google’s Threat Intelligence Group (GTIG) and iVerify. The kit features a “1-click” attack chain triggered when a user visits a compromised website.
Risk and Mitigation
While the Coruna kit is highly sophisticated, it is only effective against iOS versions 13.0 through 17.2.1. It does not work on the most recent versions of iOS (v18 and later).
#“coruna”: #attacks #block #crypto-theft #devices #feds #immediately #ios #must #news #update — News
© Bulletproof Servers. All rights reserved.