Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits
2026-03-28T01:24:14Z•d9cc48c5869002a35c1f28ac0612fc0be62fc395ed2b218db4a430b72820e844
PyPITeamPCPTrivyaagm-web-exploitsapple-iosbackdoorclaude-extensioncorunacredential-harvesterlangchainlanggraphlitellmlock-screen-alertsmalicious-packagesopen-vsxpayment-skimmersecrets-exposuresupply-chaintelnyxtriangulationvetting-bypassvscode-extensionweb-attackwebrtc-skimmerzero-click-xss
What happened
A cluster of high-impact security incidents and disclosures reported Mar 24–27, 2026: active supply‑chain compromises by TeamPCP that pushed backdoored telnyx (4.87.1/4.87.2) and litellm (1.82.7–1.82.8) packages to PyPI — including credential harvesters hidden in WAV files and Kubernetes/backdoor toolkits via a Trivy CI/CD compromise; an Open VSX pre‑publish scan bug that allowed malicious VS Code extensions to be published; Apple issuing Lock Screen alerts for web‑based exploits targeting outdated iOS/iPadOS builds and new analysis linking the Coruna iOS kit to 2023 Triangulation exploit code
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d9cc48c5869002a35c1f28ac0612fc0be62fc395ed2b218db4a430b72820e844
- Enrichment time
- 2026-03-28T01:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.