[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f66Jok7ZNNlaA3R8fK74btGdyQyeDxXnNGw4Ww4T6GUc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"5f565bb4-113e-479a-9d20-f576718e5d2f","zero-click-ios-exploits-evolve-from-state-sponsored-to-criminal-use","f9236263-a81d-41b5-9d6b-f88d57de7b4c","Zero-Click iOS Exploits Evolve from State-Sponsored to Criminal Use","The Coruna iOS exploit framework demonstrates how sophisticated state-sponsored attack tools can evolve and proliferate into criminal enterprises. Originally developed for the Operation Triangulation espionage campaign, this framework leveraged 23 vulnerabilities including zero-click iMessage exploits to silently compromise iPhones. The transition from precision espionage to indiscriminate cryptocurrency theft shows how advanced exploits eventually trickle down to financially-motivated threat actors. This highlights the critical importance of rapid patching, as unpatched vulnerabilities in widely-used platforms like iOS become valuable commodities in the cybercriminal ecosystem.","**Immediate actions:**\n- Organizations could have mitigated this threat through aggressive mobile device management policies requiring immediate iOS updates, particularly for security patches addressing zero-click vulnerabilities\n- organizations should enforce policies restricting sensitive business activities on personal devices and consider mobile device isolation techniques\n- Regular security awareness training should educate users about the risks of delayed patching, even though zero-click exploits require no user interaction to succeed\n\n**Detection measures:**\n- Implementing mobile threat detection solutions and network monitoring to identify suspicious device behavior would help detect compromise even when exploits are zero-click",[12,13,14,15,16],"CIS Control 7","NIST SP 800-124","NIST CM-3","CIS Control 3","NIST SI-2","published","2026-03-26T15:09:56.721353+00:00","2026-03-26T15:09:56.615+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcoruna-ios-exploit-framework-linked-to-triangulation-attacks\u002F","coruna-ios-exploit-framework-linked-to-triangulation-attacks","Coruna iOS exploit framework linked to Triangulation attacks",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]