Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits

2026-03-28T01:24:14Zd9cc48c5869002a35c1f28ac0612fc0be62fc395ed2b218db4a430b72820e844
PyPITeamPCPTrivyaagm-web-exploitsapple-iosbackdoorclaude-extensioncorunacredential-harvesterlangchainlanggraphlitellmlock-screen-alertsmalicious-packagesopen-vsxpayment-skimmersecrets-exposuresupply-chaintelnyxtriangulationvetting-bypassvscode-extensionweb-attackwebrtc-skimmerzero-click-xss

What happened

A cluster of high-impact security incidents and disclosures reported Mar 24–27, 2026: active supply‑chain compromises by TeamPCP that pushed backdoored telnyx (4.87.1/4.87.2) and litellm (1.82.7–1.82.8) packages to PyPI — including credential harvesters hidden in WAV files and Kubernetes/backdoor toolkits via a Trivy CI/CD compromise; an Open VSX pre‑publish scan bug that allowed malicious VS Code extensions to be published; Apple issuing Lock Screen alerts for web‑based exploits targeting outdated iOS/iPadOS builds and new analysis linking the Coruna iOS kit to 2023 Triangulation exploit code

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
d9cc48c5869002a35c1f28ac0612fc0be62fc395ed2b218db4a430b72820e844
Enrichment time
2026-03-28T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.