SimpleLife.news

March 05, 2026
🔒 Security

← Back to all news

🔒 Security

iOS Exploit Kit Coruna Contains 20+ Vulnerabilities, Used in Active Attacks

Security researchers have discovered the iOS exploit kit Coruna, which comprises over 20 vulnerabilities that can be chained into multiple complete exploitation chains. Primarily targeting older iOS devices, the toolkit has been used by multiple threat actors in real-world cyberattacks, drawing significant attention from the security community.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:揭露大規模漏洞利用套件被實際應用於攻擊活動,影響全球iOS用戶安全,具高度新聞價值與公共利益。

Objectivity:8/10

Popularity:8/10

Tone Adjustment:標題用詞客觀,未過度渲染。摘要準確呈現漏洞數量、利用鏈完整性及多方攻擊等核心事實。

14 Countries Shut Down Hacker Forum LeakBase, Seize 142,000 Member Records

The U.S. Department of Justice and Europol announced a coordinated law enforcement operation involving 14 countries that successfully shut down the hacker forum LeakBase this week. The operation seized personal data of 142,000 members and resulted in multiple arrests. The international effort aims to combat cybercrime and dismantle illegal data trading platforms.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:國際執法機構聯合打擊駭客論壇的重大行動,涉及全球網路安全與個人隱私保護,具有突發性與廣泛影響力。

Objectivity:8/10

Popularity:8/10

Tone Adjustment:標題客觀陳述事實,未見過度渲染。摘要應補充:受影響會員身份、論壇主要犯罪活動類型、各國後續處理措施等細節。

Russian Hacker Group UAC-0050 Targets European Financial Institution

Security firm BlueVoyant released threat analysis in March revealing that Russian-linked hacker group UAC-0050 conducted a social engineering attack against a European financial institution in February. The attackers impersonated Ukrainian judicial institutions via email to distribute RMS remote access tools. Ukraine's CERT-UA tracks the threat actor as UAC-0050, also known as DaVinci Group or Agency DaVinci, while BlueVoyant named the campaign Mercenary Akula.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:揭露跨國駭客組織攻擊金融機構的具體手法與工具,對全球金融安全具重要預警價值,涉及多國利益。

Objectivity:8/10

Popularity:8/10

Tone Adjustment:標題客觀陳述事實,未過度渲染。摘要保持中立,清楚說明威脅行為者身份、攻擊手法與時間軸。

Europol-Led Operation Dismantles Phishing Platform Tycoon2FA with Over 330 Domains

Tycoon2FA, a major phishing toolkit rental platform exposed two years ago, has been successfully dismantled through a coordinated international law enforcement operation. Europol partnered with multiple technology and cybersecurity companies to take down over 330 domains and related infrastructure associated with the platform, disrupting widespread phishing and fraud activities.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:跨國執法打擊網釣工具平臺,直接關乎全球網路安全與用戶隱私保護,具重大公共利益價值。

Objectivity:8/10

Popularity:7/10

Tone Adjustment:標題用詞客觀中立,未見聳動用語。摘要簡潔呈現事實,無過度渲染。

Kaspersky Discovers Keenadu Android Backdoor Preinstalled on Over 13,000 Devices

Kaspersky released a research report in February revealing Keenadu, an Android backdoor program. The malware can be injected during device firmware build stages and integrated into Android system components, causing infected devices to ship with malicious code pre-installed. Over 13,000 devices have been identified as affected, with some being used for ad fraud and Android botnet activities.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:首次披露Keenadu後門程式,涉及出廠預植惡意程式的新型攻擊手法,影響廣泛用戶群體,具重大資安威脅。

Objectivity:8/10

Popularity:8/10

Tone Adjustment:標題用詞客觀,未過度聳動。摘要準確呈現威脅規模與技術特徵,無誇大或渲染。

Cisco Patches Two Critical Vulnerabilities in Secure FMC

Cisco released security updates this week to address two critical vulnerabilities in Secure Firewall Management Center (Secure FMC). Both vulnerabilities carry a CVSS score of 10.0, representing the highest severity level. The patches aim to protect users' firewall management systems from potential security threats.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:防火牆軟體漏洞影響全球企業網路安全,風險等級最高(CVSS 10.0),具重要資安價值。

Objectivity:9/10

Popularity:6/10

Tone Adjustment:標題用詞中立客觀,未見聳動用語。摘要簡潔呈現漏洞風險等級與廠商回應,保持專業資安報導風格。

Zerobot Botnet Exploits Tenda Router and n8n Platform Vulnerabilities

Akamai's security research team SIRT reported that Zerobot, a Mirai variant botnet, is actively exploiting two known vulnerabilities—CVE-2025-7544 and CVE-2025-68613—to attack Tenda routers and n8n workflow automation platforms. The team observed exploitation attempts in their global honeypot network in mid-January 2026, with overall activity traceable back to early December 2025.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:報告揭示活躍的殭屍網路利用已知漏洞進行大規模攻擊,對全球網路基礎設施與企業安全構成重大威脅,具高度新聞價值。

Objectivity:9/10

Popularity:8/10

Tone Adjustment:標題直述事實,用詞中立客觀。摘要準確呈現威脅情報機構的發現,未添加渲染性措辭,保持專業資安報導風格。

LastPass Users Targeted by Phishing Campaign Using Fake Security Alerts

Password management service LastPass has warned of a new phishing campaign targeting its users. Attackers are using forged email conversations and fake login pages to trick users into revealing their master passwords and account credentials. The campaign aims to compromise user accounts and gain unauthorized access to password vaults. LastPass advises users to remain vigilant against such social engineering attempts.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:LastPass用戶面臨主密碼竊取風險,涉及全球數百萬用戶的帳號安全,具高度公共利益與新聞價值。

Objectivity:8/10

Popularity:8/10

Tone Adjustment:標題用詞「挾持」略顯聳動,但準確反映威脅程度。摘要客觀陳述攻擊手法與風險,未過度渲染。

Commvault Integrates AI Anomaly Detection into CrowdStrike's Falcon SIEM Platform

Commvault, a backup and data protection software vendor, announced an expanded partnership with cybersecurity platform CrowdStrike. The company will integrate its AI-powered anomaly detection capabilities into CrowdStrike's Falcon Next-Gen SIEM platform to help enterprises detect and respond more accurately and rapidly to potential data breach incidents.

iThome Original article → AI-edited
📊 Objective Analysis

Selection Reason:涉及資訊安全核心領域,企業級威脅檢測與數據保護整合方案,對全球企業資安防禦有實質幫助。

Objectivity:9/10

Popularity:6/10

Tone Adjustment:標題與摘要用詞中立客觀,無聳動誇大,準確呈現產品整合事實與企業應用價值。