[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4QShraDk1dn9thkFnrkM5FS0PED4pqaAENm_TdIWnZo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"8819a862-4d93-4421-bd74-cb8a5593385a","coruna-exploit-kit-weaponizes-unpatched-ios-vulnerabilities","40d522eb-9024-45a1-b8f7-66cee97b9e85","Coruna Exploit Kit Weaponizes Unpatched iOS Vulnerabilities","The Coruna exploit kit demonstrates how threat actors systematically weaponize known vulnerabilities like CVE-2023-32434 and CVE-2023-38606 to target Apple iPhones through watering-hole attacks. This framework evolved from the sophisticated Operation Triangulation campaign, showing how exploit code gets reused and refined across different attack groups. The discovery reveals that even patched vulnerabilities continue to pose risks when organizations fail to maintain current security updates. Organizations using mobile devices face ongoing exposure when vulnerability management processes don't keep pace with rapidly evolving exploit techniques.","**Immediate actions:**\n- Organizations should implement comprehensive mobile device management (MDM) solutions with automatic security updates enabled for all corporate and BYOD devices\n- Regular vulnerability assessments should include mobile platforms, with documented procedures for emergency patching when critical iOS vulnerabilities are disclosed\n- Network-level protections including web filtering and DNS security can help prevent watering-hole attacks from reaching vulnerable devices even before patches are applied\n\n**Detection measures:**\n- Security teams must monitor threat intelligence sources for reports of active exploitation campaigns like Operation Triangulation to accelerate patch deployment timelines",[12,13,14,15,16],"CIS Control 7","NIST SI-2","CIS Control 11","NIST CM-8","ISO 27001 A.12.6.1","published","2026-03-26T09:07:05.592102+00:00","2026-03-26T09:07:05.509+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fsecurelist.com\u002Fcoruna-framework-updated-operation-triangulation-exploit\u002F119228\u002F","coruna-the-framework-used-in-operation-triangulation","Coruna: the framework used in Operation Triangulation",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]