This day 02:07 06:07 10:08 14:08 18:09 22:09
Info  2026-08-14 02:07Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-08-14 — Apple flags mercenary spyware

Apple has begun pushing a fresh round of Threat Notifications warning targeted iPhone users of mercenary spyware attacks — the kind typically associated with NSO-grade commercial surveillanceware. These notifications matter because they signal active, highly resourced targeting of specific individuals rather than broad opportunistic campaigns. Recipients should treat the alert as an indicator of probable compromise and escalate accordingly.

Top items

Themes

Targeted surveillance remains a live threat. Apple's notification programme continues to be one of the few vendor-side early-warning channels for mercenary spyware. Given yesterday's Safari jailbreak disclosure (Relaxin) and the ongoing stream of mobile exploit research, mobile device hygiene for high-risk users warrants renewed attention.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db