CISA orders feds to patch DarkSword iOS flaws exploited attacks
ID: 9ab7d84c-bd98-53fa-8968-28c8f241c966
STIX ID: report--9ab7d84c-bd98-53fa-8968-28c8f241c966
Feed Name: Bleeping Computer
Security researchers and Google Threat Intelligence revealed the DarkSword iOS exploit kit — a chain of six vulnerabilities (CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520) enabling sandbox escape, privilege escalation, and remote code execution on iPhones running iOS 18.4–18.7; the attacks dropped aggressive data-stealing malware families (GhostBlade, GhostKnife, GhostSaber) and were attributed to multiple threat groups including UNC6748 and UNC6353, prompting CISA to add three of the flaws to its actively exploited catalog and order immediate patching for federal devices under BOD 22-01.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
