#GoogleVRP, #iVerify & #Lookout on Wednesday jointly revealed their discovery of a sophisticated iPhone hacking technique, they named #DarkSword, that use #WateringHoleAttack to hack into iOS devices the moment user visit an infected website.

🔗 https://www.wired.com/story/hundreds-of-millions-of-iphones-can-be-hacked-with-a-new-tool-found-in-the-wild/

Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

WIRED

NowSecure + iVerify 🤝

Security teams can now see #mobileapp risk directly inside #iVerify Enterprise—from malicious #apps to risky SDK supply-chains.

More visibility. Faster action.

Learn more: https://loom.ly/aalDN3w

政府級黑客工具 Coruna 外洩 逾 4.2 萬舊 iPhone 中招 落入中俄犯罪份子手中 - unwire.hk 香港

Google 旗下威脅情報團隊(GTIG)與流動安全公司 iVerify 於 2026 年 3 月 3 日聯合披露一套名為「Coruna」的高階 iOS 漏洞利用工具包。研究人員相信這套工具原為美國政府開發,現已流入俄羅斯間諜組織及中國網絡犯罪分子手中,令逾 42,000 部 iPhone

香港 unwire.hk 玩生活.樂科技
政府級黑客工具 Coruna 外洩 逾 4.2 萬舊 iPhone 中招 落入中俄犯罪份子手中 - unwire.hk 香港

Google 旗下威脅情報團隊(GTIG)與流動安全公司 iVerify 於 2026 年 3 月 3 日聯合披露一套名為「Coruna」的高階 iOS 漏洞利用工具包。研究人員相信這套工具原為美國政府開發,現已流入俄羅斯間諜組織及中國網絡犯罪分子手中,令逾 42,000 部 iPhone

香港 unwire.hk 玩生活.樂科技
政府級黑客工具 Coruna 外洩 逾 4.2 萬舊 iPhone 中招 落入中俄犯罪份子手中
  Google 旗下威脅情報團隊(GTIG)與流動安全公司 iVerify 於 2026 年 3 […]
#科技新聞 #資訊保安 #Apple #iOS
https://unwire.hk/2026/03/10/coruna-ios-exploit-kit-iphone-attack/tech-secure/?utm_source=rss&utm_medium=rss&utm_campaign=coruna-ios-exploit-kit-iphone-attack
Researchers at mobile threat hunting company #iVerify say that ZeroDayRAT not just steals data but also enables real-time surveillance through GPS, Camera, Microphone, as well a keylogging module to capture user input, like passwords, gestures, or screen unlock patterns.
3/5

Polls. Group typing indicators and all other new crap for iMessage is just increased attack surface.

If I didn't know better I would assume they keep adding these to make sure there will always be remote iOS exploits.

I mean after their track record, you would have assumed they figured things out but last year they added the contact photo sharing, and lo and behold, it's apparently being exploited https://iverify.io/blog/iverify-uncovers-evidence-of-zero-click-mobile-exploitation-in-the-us

#ios26 #imessage #iverify

iVerify Uncovers Evidence of Zero-Click Mobile Exploitation in the U.S.

Examining a previously unknown iMessage vulnerability with possible exploitation in the US and EU

In May 2024, #iVerify released a $1 app for people to scan their phones for any signs of compromise.

In December 2024, iVerify released a report suggesting out of ~ 3,000 users, there were > detections of #Pegasus infection than previously expected.

🔗 https://iverify.io/blog/how-democratizing-threat-hunting-is-changing-mobile-security

How Democratizing Threat Hunting is Changing Mobile Security

iVerify found 11 new Pegasus spyware detections, primarily from business executives with access to future deals, financial data, and professional networks.

"The company’s Mobile Threat Hunting feature uses a combination of malware signature-based detection, heuristics, and machine learning to look for anomalies in iOS and Android device activity or telltale signs of spyware infection. For paying iVerify customers, the tool regularly checks devices for potential compromise. But the company also offers a free version of the feature for anyone who downloads the iVerify Basics app for $1. These users can walk through steps to generate and send a special diagnostic utility file to iVerify and receive analysis within hours. Free users can use the tool once a month. iVerify's infrastructure is built to be privacy-preserving, but to run the Mobile Threat Hunting feature, users must enter an email address so the company has a way to contact them if a scan turns up spyware—as it did in the seven recent Pegasus discoveries."

https://arstechnica.com/security/2024/12/1-phone-scanner-finds-seven-pegasus-spyware-infections/

#CyberSecurity #Spyware #iVerify #iOS #Android #Pegasus

$1 phone scanner finds seven Pegasus spyware infections

iVerify’s detection tool was launched in May and is turning up victims.

Ars Technica