iOS · 2023Operation Triangulation: how iPhones were spied on
Researchers at Kaspersky uncovered one of the most sophisticated espionage campaigns of recent years. The spyware implant, TriangleDB, was built specifically for iOS.
The victim received an invisible iMessage; a chain of vulnerabilities gave the attackers full control, and the implant lived only in memory — a reboot erased it, so the attackers had to re-infect the device. It could collect files, read the keychain, track location and manage processes, and deleted itself after 30 days.
Takeaway: install updates promptly, restart your phone regularly and keep sensitive work on hardened devices.
Windows · 2017NotPetya: one update, hundreds of companies down
On 27 June 2017 a destructive attack spread from a compromised accounting-software update in Ukraine and within hours hit banks, logistics, energy and global brands.
It spread on its own using the EternalBlue vulnerability and stolen administrator passwords, encrypted the disk's boot record and showed a ransom note — but the keys were destroyed, so data could not be recovered.
Takeaway: patch quickly, separate networks, limit administrator rights and keep offline backups.
Supply chain · 2020SolarWinds: when a trusted update is the way in
In December 2020 it became known that malicious code had been inserted into official, digitally signed updates of the SolarWinds Orion monitoring platform.
The update reached more than 18,000 organisations, including government agencies and major technology companies, and went unnoticed for over nine months.
Takeaway: check what your vendors ship, monitor unusual activity after updates, and share information about incidents.