Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack

2026-03-04T20:35:39Zc25038adc6fd2fd02fce8ebc1c492b1443ce62b44f651bf07da34eae6ff1288d
AI manipulationAndroid patchCISACISA CIO exitChina threatsCometCorunaFBI Winter SHIELDQualcomm zero-dayZenity Labsactively exploitedagentic AI browsersbehavioral profiling attack techniquesdata exfiltrationdeepfakesexploit kitiOS exploitleadership changeleaked frameworklocal file accessmass iOS attacksilent probingspywaresupply chainvulnerability

What happened

This collection of CyberScoop stories highlights multiple high-risk developments: researchers traced a Coruna iOS exploit kit—possibly built from a leaked U.S. framework—used in the first known mass iOS attack and observed moving between a spyware vendor’s customer, Russian actors, and Chinese cybercriminals. Security teams also disclosed agentic AI browser flaws (e.g., Comet/Zenity) that can be triggered via simple invites to access local files, enumerate directories, and exfiltrate data. Google shipped a large March 2026 Android security update that includes a recently actively exploited, on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
c25038adc6fd2fd02fce8ebc1c492b1443ce62b44f651bf07da34eae6ff1288d
Enrichment time
2026-03-04T20:35:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.