CERT-FR Apple spyware notification mitigation advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CERT-FR warned that Apple spyware notifications can mean devices linked to an iCloud account were targeted and potentially compromised. The agency said the threat can involve zero-day spyware that may need no user interaction, making fast hardening important. It told users to update immediately or enable automatic updates, turn on Lockdown Mode, and restart devices daily.
Related Happenings
Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Security Patch Release
H score55
First: 14.04.2026 20:41
Last: 14.04.2026 20:41
Sources 1
About this happening:
Microsoft's April 2026 Patch Tuesday ships security updates for 167 flaws, including 2 zero-days, reducing exposure across widely used Microsoft software. The rele...
Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Security Patch ReleaseAbout this happening: Microsoft's April 2026 Patch Tuesday ships security updates for 167 flaws, including 2 zero-days, reducing exposure across widely used Microsoft software. The rele...
Apple iOS 18.7.7 security update expansion for DarkSword
Security Patch Release
H score41
First: 02.04.2026 00:50
Last: 02.04.2026 00:50
Sources 1
About this happening:
Apple expanded iOS 18.7.7 availability to more older iPhones and iPads on April 1, 2026, letting devices that stay on iOS 18 receive protections against the acti...
Apple iOS 18.7.7 security update expansion for DarkSword
Security Patch ReleaseAbout this happening: Apple expanded iOS 18.7.7 availability to more older iPhones and iPads on April 1, 2026, letting devices that stay on iOS 18 receive protections against the acti...
Operation Triangulation updated iPhone espionage campaign
Campaign
H score41
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
The Operation Triangulation espionage lineage has resurfaced through Coruna, extending zero-click iPhone targeting to newer A17 and M3 devices and iOS 17.2...
Operation Triangulation updated iPhone espionage campaign
CampaignAbout this happening: The Operation Triangulation espionage lineage has resurfaced through Coruna, extending zero-click iPhone targeting to newer A17 and M3 devices and iOS 17.2...
Coruna watering-hole and fake-site exploitation campaign
Campaign
H score44
First: 26.03.2026 13:07
Last: 26.03.2026 13:07
Sources 1
About this happening:
A suspected Russia-aligned nation-state actor is using Coruna in watering-hole attacks in Ukraine and a mass exploitation campaign, expanding the kit’s abuse beyon...
Coruna watering-hole and fake-site exploitation campaign
CampaignAbout this happening: A suspected Russia-aligned nation-state actor is using Coruna in watering-hole attacks in Ukraine and a mass exploitation campaign, expanding the kit’s abuse beyon...
Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/Mitigation
H score35
First: 20.03.2026 07:16
Last: 20.03.2026 07:16
Sources 1
About this happening:
Apple is sending Lock Screen notifications to outdated iPhones and iPads after detecting active web-based attacks, urging users to install updates. The latest noti...
Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/MitigationAbout this happening: Apple is sending Lock Screen notifications to outdated iPhones and iPads after detecting active web-based attacks, urging users to install updates. The latest noti...
Timeline
-
12.09.2025 22:28 1 articles · 10mo ago
Apple spyware threat notification on Sept. 3
Campaign Scope UpdateApple sent a spyware threat notification on Sept. 3 to an individual linked to an iCloud account, indicating that at least one associated device had been targeted and was potentially compromised. Apple’s notification flow can arrive as an iMessage and an alert email, and an alert also appears when the user logs into iCloud.
Show sources
- French Advisory Sheds Light on Apple Spyware Activity — www.darkreading.com — 12.09.2025 22:28
-
12.09.2025 22:28 2 articles · 10mo ago
CERT-FR advisory urges Apple users to harden devices
Mitigation Patch UpdateCERT-FR said Apple had sent four spyware threat notifications this year and recommended that Apple users update devices as soon as possible or enable automatic updates, turn on Lockdown Mode, and restart devices at least once a day. The advisory framed the threat as spyware that often exploits zero days and requires no user interaction, and it also noted that Apple unveiled Memory Integrity Enforcement (MIE) the same week to improve memory safety and help thwart spyware attacks.
Show sources
- French Advisory Sheds Light on Apple Spyware Activity — www.darkreading.com — 12.09.2025 22:28
- French Advisory Sheds Light on Apple Spyware Activity — www.darkreading.com — 12.09.2025 22:28