CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
ID: b0ee0343-73fc-58a8-9e6a-3094c59b2c12
STIX ID: report--b0ee0343-73fc-58a8-9e6a-3094c59b2c12
Feed Name: The Hacker News
CISA added five high‑severity flaws (Apple WebKit and kernel bugs, Craft CMS, and Laravel Livewire) to its Known Exploited Vulnerabilities catalog with an April 3, 2026 patch directive; several are confirmed or assessed as actively exploited. Google, vendor researchers, and multiple security firms link the Apple bugs to an iOS exploit kit called DarkSword that deploys data‑theft malware (GHOST* families), while other CVEs have been used by intrusion sets like Mimo/Hezb to install miners/proxyware and by MuddyWater (Boggy Serpens) in espionage and disruptive operations against diplomatic, energy, maritime, and finance targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
