Feds take notice of iOS vulnerabilities exploited under mysterious circumstances

2026-03-07T08:51:54Z2f97f50440eb378639ad20ea10ed8da9893aa066390149a9cf9f63a137d9b200
AirSnitchCISALLM-deanonymizationLumma-StealerOffice-exploitPolandSecure-BootWi-Fibug-bounty-policy-change','Notepad++-supply-chain','FBI-seizure'cURLcertificate-expirycryptocurrency-theftdYdXexploited-vulnerabilitiesiosmalwaremerkle-tree-certificatespassword-managerprivacyquantum-proofingrussian-state-actorserver-compromisesupply-chainwiper-malwarezero-day

What happened

Ars Technica security roundup highlighting multiple high-risk incidents and research: CISA added three iOS vulnerabilities to its known-exploited catalog (mysterious/advanced iOS exploit activity); LLMs shown capable of deanonymizing pseudonymous users at scale; Google rolling out Merkle-tree certificate support to quantum-proof HTTPS; a new “AirSnitch” technique that can bypass Wi‑Fi encryption; server-side compromises undermining password managers; resurgence of Lumma stealer via malicious lures; Secure Boot certificate expirations that could affect future OS boots; malicious packages that b

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
2f97f50440eb378639ad20ea10ed8da9893aa066390149a9cf9f63a137d9b200
Enrichment time
2026-03-07T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.