Breaking news

Leaked Exploit Kits Threaten Millions Of Apple Devices Worldwide

Security researchers identified leaked exploit kits targeting Apple devices, including iPhones and iPads. Tools, known as Coruna and DarkSword, were previously used in government-linked operations. Exposure of the code increases risks for devices running older versions of iOS. Researchers said vulnerabilities affect a wide range of software versions.

Unprecedented Threat To Apple Users

Leak expands the scope of attacks beyond targeted campaigns. Earlier incidents focused on specific groups, including users in China and Hong Kong. Current exposure makes the tools accessible to a broader set of actors. Risk now extends to general users with unpatched devices.

Anatomy Of Coruna And DarkSword

Coruna targets devices running iOS 13 through iOS 17.2.1. DarkSword affects more recent versions, including iOS 18.4 and 18.7. Parts of the DarkSword code are publicly available online. Availability lowers the barrier to deploying attacks.

Methodology Of The Attacks

Exploits rely on multiple vulnerabilities within iOS. Attacks often begin when users access compromised websites. Once a device is compromised, attackers can access data such as messages, location and browsing activity. Information may be transferred to external servers.

Origins And Proliferation Of The Tools

Investigations link parts of Coruna to Trenchant, a unit within L3Harris that developed exploit capabilities for government use. Some elements were previously associated with Operation Triangulation. Leak shows how state-developed tools can circulate beyond their original context. Distribution increases exposure across different threat environments.

The Leak And Its Implications

Recent tests conducted by independent researchers have demonstrated that the DarkSword kit, now effectively a plug-and-play instrument for cybercriminals, can exploit older versions of iOS with ease. Despite GitHub’s stance on preserving code for educational and security research purposes, the availability of such a potent tool heightens the risk of widespread data breaches. Experts compare this situation to the infamous WannaCry ransomware attack, which exploited a leaked NSA tool to cause global disruption in 2017.

Mitigation And Protection Strategies

Apple recommends updating devices to the latest software versions. Updated systems include protections against known vulnerabilities. Users can also enable Lockdown Mode for additional security. The feature is designed for high-risk scenarios but is available to all users.

Maintaining A Secure Digital Environment

Users are advised to apply software updates and monitor device security settings. Risks remain higher for outdated systems. Security depends on timely updates and awareness of potential threats.

Meta’s $18 Billion Settlement Limits State Claims Over Children’s Data

Meta’s $18 billion settlement with attorneys general from 29 U.S. states includes a provision limiting future state claims over the company’s use of children’s data for age-assurance systems.

Under the agreement, Meta must develop, train and begin testing a system to identify users under 13 within a year of the settlement taking effect. The company already uses AI-based age-detection tools, although the agreement does not require the new system to use AI.

States Agree To Limits On Future Claims

The Children’s Online Privacy Protection Act (COPPA) generally restricts the collection and retention of personal data from children under 13. Under the settlement, the 29 state attorneys general agreed not to bring past, present or future claims under COPPA or similar state laws over the specified use of children’s data.

Meta will not be permitted to use information from users under 13 for advertising, marketing or algorithmic optimisation.

Federal Enforcement Remains Unclear

COPPA is primarily enforced by the Federal Trade Commission, which is not a party to the agreement. That leaves open the possibility of separate federal action over how Meta collects or uses children’s data.

Another issue is whether Meta can keep age-assurance data isolated from its other systems. An independent auditor will monitor compliance, but the settlement does not fully specify what data Meta can retain for training, how long it can be stored or whether derived insights can be used elsewhere.

Legal Risks Remain

Joshua Wurtzel, a partner at Schlam Stone & Dolan, said states could still pursue claims if Meta uses the data outside the settlement’s limits. Such cases could depend on how those limits are interpreted.

Peter Jackson, a data and intellectual property attorney at Greenberg Glusker, said the provision could “disincentivize future enforcement actions.”

The agreement gives Meta greater legal certainty around using children’s data for age assurance, but questions remain over federal enforcement, data retention and secondary use.

Aretilaw firm
Uol
eCredo
The Future Forbes Realty Global Properties

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter