Apple has released updates for multiple products to address actively exploited flaws

Recently, Apple released updates for several of its products, including iOS, iPadOS, macOS, watchOS, and the Safari browser. These updates come in response to a set of flaws that Apple reported were being actively exploited by threat actors in the wild.

In this article, we’ll explore the updates and the issues they address in greater detail, including a pair of zero-day vulnerabilities that have already been used in a mobile surveillance campaign called “Operation Triangulation.”

Operation Triangulation and the Weaponized Zero-Days

According to a report from Kaspersky researchers, the mobile surveillance campaign called “Operation Triangulation” has been active since 2019 and is utilizing two zero-day vulnerabilities that have been weaponized. These vulnerabilities, labeled CVE-2021-32434 and CVE-2021-32435, may have been actively exploited against iOS versions released before iOS 15.7.

While it is unclear who is behind Operation Triangulation, these zero-day vulnerabilities have been used to infect devices with spyware. The spyware implant used in the zero-click attack campaign targeting iOS devices via iMessages is called TriangleDB.

TriangleDB and the Importance of Memory Forensics

What makes TriangleDB particularly insidious is that it operates solely in memory. This means that there are no traces of the activity left following a device reboot. As a result, the malware can remain undetected for extended periods, gathering vast amounts of data before being discovered.

This highlights the importance of memory forensics in detecting and responding to such threats. Memory forensics is the process of analyzing data stored in a computer’s volatile memory to extract relevant information such as suspicious processes, network connections, and active modules.

A third zero-day vulnerability has been patched by Apple

In addition to the two zero-day vulnerabilities actively exploited in Operation Triangulation, Apple also addressed a third zero-day vulnerability (CVE-2021-32439) that could result in arbitrary code execution when processing malicious web content. This vulnerability was reported anonymously.

The latest updates are available for the following products:

– iPhone 8 and later
– iPad Pro (all models)
– iPad Air 3rd generation and later
– iPad 5th generation and later
– Apple Watch Series 4 and later
– Macs running macOS Monterey

This is the ninth zero-day vulnerability that Apple has resolved in its products since the start of the year. In February, the company plugged a WebKit flaw (CVE-2021-23529) that could lead to remote code execution.

With the increasing number of threat actors utilizing zero-day vulnerabilities, it’s more important than ever for companies like Apple to promptly address them. While memory forensics and other security measures can help detect and respond to such threats, the best course of action is prevention.

By regularly updating their software and devices, individuals and companies can ensure that they remain protected from the latest security threats. With Apple’s latest updates, those who utilize their products can have greater confidence in their security posture.

Explore more

BlackRock Announces 1-for-3 Reverse Split for Ethereum ETF

The recent decision by BlackRock to implement a one-for-three reverse share split for its iShares Ethereum Trust reflects a strategic recalibration aimed at optimizing the financial product’s market position within the maturing digital asset landscape. As institutional appetite for Ethereum continues to grow throughout 2026 and into the coming years, the necessity for high-liquidity investment vehicles that align with traditional

Industrial Asset Management Boosts Efficiency and Longevity

The unexpected failure of a single critical turbine in a power plant or a robotic arm on a high-speed assembly line can trigger a catastrophic chain reaction that wipes out millions of dollars in revenue within a matter of hours while simultaneously compromising worker safety and environmental integrity. In the current industrial landscape of 2026, the necessity for a sophisticated

Navigating Mid-Flight Decisions in Cloud ERP Projects

The traditional notion of a static enterprise resource planning implementation has effectively vanished as organizations in 2026 navigate a landscape defined by continuous innovation and shifting software baselines. Unlike the rigid, decade-long cycles of the on-premise era, modern cloud ERP platforms evolve through relentless release schedules that often introduce major functional updates while a project is still in the deployment

Why Is Singapore Overhauling Parliament Pay and Retention?

The intricate balancing act of compensating political leaders in a city-state that functions like a global corporation remains one of Singapore’s most debated governance strategies as the nation navigates a volatile international landscape. By 2026, the government has intensified its efforts to refine the remuneration framework for Members of Parliament and Cabinet ministers, ensuring that the country continues to attract

How Can You Better Support Your Entry-Level Employees?

Navigating the complexities of a modern workforce requires more than just filling vacancies; it demands a strategic commitment to nurturing the next generation of professional talent from their very first day on the job. In the competitive landscape of 2026, the traditional models of recruitment and retention are being challenged by shifting expectations among digital natives who seek purpose and