Coruna iOS exploit framework linked to Triangulation attacks
2026-03-26T13:23:32Z•21a248ef52457f999e7c07733b22dd01001389b6e96c45af7e2c476b3f926c29
bubblecitrixcode-scanningcorunacrypto-walletsexploit-frameworkgithub-aiinfostealerioslaw-enforcementleakbaselitellmmagentonetscalerphishingpolyshellpypiredlinerouter-auth-bypass','ptc','windchill','flexplm','rce','kali-linxsupply-chainteampcptorg-grabbertp-linktriangulationzero-click
What happened
A batch of high-priority security developments: researchers tied the Coruna iOS exploit framework to the Operation Triangulation zero‑click iMessage campaign; multiple law‑enforcement actions (arrest of a suspected LeakBase owner and extradition of a suspected RedLine infostealer admin) target cybercrime infrastructure; and TeamPCP backdoored the popular LiteLLM PyPI package in a supply‑chain compromise. Active attacks and abuse continue — PolyShell exploitation is targeting a majority of vulnerable Magento stores, a new Torg Grabber infostealer is harvesting hundreds of crypto wallet browser‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 21a248ef52457f999e7c07733b22dd01001389b6e96c45af7e2c476b3f926c29
- Enrichment time
- 2026-03-26T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.