CERT-FR Apple spyware notification mitigation advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CERT-FR warned that Apple spyware notifications can mean devices linked to an iCloud account were targeted and potentially compromised. The agency said the threat can involve zero-day spyware that may need no user interaction, making fast hardening important. It told users to update immediately or enable automatic updates, turn on Lockdown Mode, and restart devices daily.
Related Happenings
Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Security Patch Release
First: 14.04.2026 20:41
Last: 14.04.2026 20:41
Sources 1
About this happening:
Microsoft's **April 2026 Patch Tuesday** ships **security updates** for **167 flaws**, including **2 zero-days**, reducing exposure across widely used Microsoft software. The rele...
Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Security Patch ReleaseAbout this happening: Microsoft's **April 2026 Patch Tuesday** ships **security updates** for **167 flaws**, including **2 zero-days**, reducing exposure across widely used Microsoft software. The rele...
Apple iOS 18.7.7 security update expansion for DarkSword
Security Patch Release
First: 02.04.2026 00:50
Last: 02.04.2026 00:50
Sources 1
About this happening:
Apple expanded **iOS 18.7.7** availability to more older **iPhones and iPads** on **April 1, 2026**, letting devices that stay on **iOS 18** receive protections against the **acti...
Apple iOS 18.7.7 security update expansion for DarkSword
Security Patch ReleaseAbout this happening: Apple expanded **iOS 18.7.7** availability to more older **iPhones and iPads** on **April 1, 2026**, letting devices that stay on **iOS 18** receive protections against the **acti...
Operation Triangulation updated iPhone espionage campaign
Campaign
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
The **Operation Triangulation** espionage lineage has resurfaced through **Coruna**, extending **zero-click iPhone** targeting to newer **A17** and **M3** devices and **iOS 17.2**...
Operation Triangulation updated iPhone espionage campaign
CampaignAbout this happening: The **Operation Triangulation** espionage lineage has resurfaced through **Coruna**, extending **zero-click iPhone** targeting to newer **A17** and **M3** devices and **iOS 17.2**...
Coruna watering-hole and fake-site exploitation campaign
Campaign
First: 26.03.2026 13:07
Last: 26.03.2026 13:07
Sources 1
About this happening:
A suspected **Russia-aligned nation-state actor** is using **Coruna** in **watering-hole attacks in Ukraine** and a **mass exploitation campaign**, expanding the kit’s abuse beyon...
Coruna watering-hole and fake-site exploitation campaign
CampaignAbout this happening: A suspected **Russia-aligned nation-state actor** is using **Coruna** in **watering-hole attacks in Ukraine** and a **mass exploitation campaign**, expanding the kit’s abuse beyon...
Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/Mitigation
First: 20.03.2026 07:16
Last: 20.03.2026 07:16
Sources 1
About this happening:
**Apple** is sending **Lock Screen notifications** to **outdated iPhones and iPads** after detecting **active web-based attacks**, urging users to install updates. The latest noti...
Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/MitigationAbout this happening: **Apple** is sending **Lock Screen notifications** to **outdated iPhones and iPads** after detecting **active web-based attacks**, urging users to install updates. The latest noti...
Timeline
-
12.09.2025 22:28 1 articles · 8mo ago
Apple spyware threat notification on Sept. 3
Campaign Scope UpdateApple sent a spyware threat notification on Sept. 3 to an individual linked to an iCloud account, indicating that at least one associated device had been targeted and was potentially compromised. Apple’s notification flow can arrive as an iMessage and an alert email, and an alert also appears when the user logs into iCloud.
Show sources
- French Advisory Sheds Light on Apple Spyware Activity — www.darkreading.com — 12.09.2025 22:28
-
12.09.2025 22:28 2 articles · 8mo ago
CERT-FR advisory urges Apple users to harden devices
Mitigation Patch UpdateCERT-FR said Apple had sent four spyware threat notifications this year and recommended that Apple users update devices as soon as possible or enable automatic updates, turn on Lockdown Mode, and restart devices at least once a day. The advisory framed the threat as spyware that often exploits zero days and requires no user interaction, and it also noted that Apple unveiled Memory Integrity Enforcement (MIE) the same week to improve memory safety and help thwart spyware attacks.
Show sources
- French Advisory Sheds Light on Apple Spyware Activity — www.darkreading.com — 12.09.2025 22:28
- French Advisory Sheds Light on Apple Spyware Activity — www.darkreading.com — 12.09.2025 22:28