Google’s Threat Intelligence Group detailed “Coruna,” a powerful iOS exploit kit containing five full exploit chains and 23 exploits targeting iOS 13.0 through 17.2.1. Initially seen with a commercial surveillance vendor’s customer, it later surfaced in a suspected Russian espionage watering-hole operation and broad financially motivated campaigns from China. The kit’s payload modules focus on stealing crypto wallet data; it is not effective against the latest iOS, so urgent updates (or Lockdown Mode where updates aren’t possible) are advised.
Source: Google Cloud Threat Intelligence
Chrome flaw let extensions hijack Gemini Live camera, mic, and file access
A now-patched Chrome vulnerability (CVE-2026-0628) allowed malicious extensions to inherit Gemini Live’s elevated permissions, including camera, microphone, and file access. The issue stemmed from insufficient policy enforcement in the side panel, effectively turning the AI pane into a privilege escalator. Enterprises should ensure Chrome is updated across fleets and review extension allowlists for abuse-prone add-ons.
Source: Malwarebytes Blog
Android March patch fixes 100+ issues, including Qualcomm zero-day under active exploitation
Google’s March 2026 security update addresses scores of flaws across the Android stack and confirms targeted exploitation of CVE-2026-21385, a High-severity issue in the Qualcomm Display component. Devices at patch level 2026-03-05 or later receive all fixes; organizations should prioritize updates for Qualcomm-based handsets and enforce rapid mobile patch SLAs.
Source: Help Net Security
Attackers weaponize OAuth redirection logic to bypass filters and deliver malware
Microsoft researchers warn of phishing campaigns abusing legitimate OAuth redirect flows to shuttle users from trusted Microsoft/Google login pages to attacker infrastructure. The technique evades typical email and browser checks without stealing tokens, enabling malware delivery and credential capture against government and public-sector targets. Lock down redirect URIs, scrutinize IdP sign-in logs, and tighten conditional access to blunt this tactic.
Source: Help Net Security
VMware Aria Operations RCE exploited in the wild; added to CISA KEV
An unauthenticated command injection bug in VMware Aria Operations (CVE-2026-22719) is being actively exploited for remote code execution. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, underscoring the need for immediate patching and removal of any internet exposure. Environments should also hunt for post-exploitation indicators and rotate credentials used by the platform.
Source: SecurityWeek
China-linked “Silver Dragon” APT hides C2 in Google Drive and persists via Windows service hijacking
Check Point profiled Silver Dragon, a China-nexus espionage group targeting ministries and public-sector bodies across Southeast Asia and parts of Europe. The actors obtain initial access via public-facing server exploits and spear-phishing, maintain persistence by hijacking legitimate Windows services, and use a custom backdoor (“GearDoor”) that blends C2 traffic with Google Drive. Defenders should monitor for anomalous service changes and inspect sanctioned cloud storage traffic for covert channels.
Source: Check Point Blog
Iranian strikes damage AWS data centers, exposing cloud’s physical risk surface
Drone strikes in the UAE and Bahrain directly hit AWS facilities, disrupting services regionally and highlighting the fragility of cloud workloads to kinetic events. The incident reinforces the need for multi-region redundancy, tested failover, and contingency plans that assume concurrent physical and cyber disruptions.
Source: SecurityWeek
You May Also Be Interested In...
Cloudflare tracked 230 billion daily threats and here is what it found
Google speeds up Chrome updates with new security-focused release cycle
mquire: Open-source Linux memory forensics tool