CPE
high
advisory
Malicious Packagist Composer Themes Deploying iOS Spyware
4 TTPs 2 CVEs 1 IOCThreat actors are distributing 13 malicious Composer themes via Packagist to compromise streaming websites and deploy a WebKit-to-kernel exploit chain against iOS visitors for data exfiltration and cryptocurrency wallet theft.
iOS +1
supply-chain
mobile-malware
web-security
cryptocurrency-theft
spyware
4t
2c
1i
critical
advisory
Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries
3 CVEsNokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.
Nokogiri +2
vulnerability
memory-corruption
libxslt
3c
high
advisory
Apple Security Updates — July 2026
4 CVEs 10 IOCsRoundup of Apple security advisories published in July 2026.
PoC
macOS LaunchAgents +46
roundup
4c
10i
updated
critical
threat
CVE-2024-23222 Apple Safari Type Confusion Leading to Sandbox Escape
2 rules 2 TTPs 1 CVE 1 IOCA type confusion vulnerability exists in Apple Safari, as detailed in CVE-2024-23222. A public exploit demonstrates successful exploitation of the vulnerability on iOS 16.4.1, leading to a sandbox escape, which has been patched in iOS 17.3 and macOS 14.3.
Safari
cve-2024-23222
type-confusion
sandbox-escape
webkit
2r
2t
1c
1i