David Durvaux
Incident responder for more than a decade, I'm now working for the European Commission since 2015. I'm currently in charge of the "Situational Awareness, Threat Intelligence and Malware Analysis" in the European Commission Internal CERT (EC Cybersecurity Operation Centre).
Sessions
March 2026 marked a turning point in the iOS threat landscape. Coruna and DarkSword became the first widely observed mass-exploitation campaigns targeting iOS devices at scale : a shared exploit kit used by multiple threat actors, shattering the assumption that iOS exploitation would remain the exclusive domain of nation-state tools like Pegasus or Predator.
This talk dissects Coruna (a campaign targeting cryptocurrency communities) following its full chain from browser fingerprinting and memory primitives through PAC bypass, code execution, privilege escalation, and implant delivery. Beyond the technical analysis, it offers an honest account of the analyst's journey: a low-cost observation setup using mitmproxy and a Raspberry Pi, the forensic artifacts that made the analysis possible, and a frank discussion of where LLM-assisted analysis accelerates work and where it produces dangerously confident wrong answers.
The talk also covers practical detection and infrastructure tracking using tools like Censys and URLScan.io.
Are you, or your organisation, concerned about potential compromise on your iPhone, iPad, or Apple Watch? This workshop equips you with the knowledge and tools to identify red flags on your iOS device. We delve into the world of sysdiagnose and explore methods to verify potential breaches.
This is the starter workshop, we invite you to also join the second deeper dive session with deeper analysis.
This is the second part, or deep dive, of the Sysdiagnose Analysis Framework Workshop.
We will continue on the topics discussed in the first workshop, but here the focus is on diving DEEP in lots of the data that is present in the sysdiagnose archive.
Please ONLY attend this workshop if you either attended previous year's session or attended the beginners session, or already used the sysdiagnose analysis framework before.