
Security experts have long believed that uncovering vulnerabilities within iOS is a complex process, requiring extensive resources and teams of adept researchers to breach its robust defenses. Traditionally, this has made instances of iPhone spyware and zero-day vulnerabilities—flaws unknown to the vendor prior to exploitation—quite rare, typically limited to targeted attacks, as noted by Apple. However, recent investigations by cybersecurity researchers from Google, iVerify, and Lookout have revealed alarming hacking campaigns utilizing tools named Coruna and DarkSword. These tools have been indiscriminately targeting victims worldwide, particularly those who have not yet updated their iOS software. Among the attackers are alleged Russian spies and Chinese cybercriminals, who exploit compromised websites and fraudulent pages to potentially harvest data from numerous victims. What exacerbates this situation is that some of these hacking tools have leaked online, enabling malicious actors to effortlessly replicate and launch attacks against Apple users on older iOS versions. Despite Apple's substantial investments in security enhancements—like the introduction of memory-safe code in the latest iPhone models and the rollout of features such as Lockdown Mode to protect against spyware—older iPhones remain more vulnerable. The disparity in security is stark: users operating on the latest iOS 26 and iPhone 17 models benefit from a feature called Memory Integrity Enforcement. This new layer of protection is designed to thwart memory corruption bugs, which are frequently exploited in spyware attacks. In contrast, those still using iOS 18 or earlier versions find themselves susceptible to a range of memory-based hacks. The emergence of Coruna and DarkSword raises concerns that memory-based attacks will continue to affect users of older iPhones and iPads, which lack the enhanced security features of newer models. Experts from iVerify and Lookout argue that the prevalence of mobile attacks is increasing, challenging the notion that iPhone hacks are infrequent. Matthias Frielingsdorf, co-founder of iVerify, remarked on the escalation of mobile attacks while also indicating that zero-day exploits against the latest software will command a premium, suggesting these methods are not intended for mass hacking. Patrick Wardle, an Apple security specialist, cautioned that while iPhone attacks may be labeled as rare or sophisticated, this perception may stem from the lack of documented cases rather than their actual occurrence. Additionally, the existence of a lucrative second-hand market for exploits presents a significant challenge, according to Justin Albrecht, principal researcher at Lookout. This market incentivizes exploit developers to resell vulnerabilities even after they have been patched, indicating that the threat is not just a fleeting issue but a persistent concern for Apple users moving forward.
The landscape of money is transforming beyond just cash or bank balances, and TechCrunch Disrupt 2026 is set to spotligh...
TechCrunch | Jul 24, 2026, 22:40
Waymo is reportedly exploring options to exit its partnership with Uber, which has allowed the Alphabet-owned firm to de...
TechCrunch | Jul 24, 2026, 21:00
Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...
CNBC | Jul 25, 2026, 05:15
Poke, the friendly AI assistant that users interact with as if chatting with a friend, is set to embark on a new journey...
TechCrunch | Jul 24, 2026, 18:25
It has been a challenging week for Elon Musk, as both Tesla and SpaceX experienced substantial stock declines. Tesla sha...
CNBC | Jul 24, 2026, 20:40