logo

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

ID: b0ee0343-73fc-58a8-9e6a-3094c59b2c12

STIX ID: report--b0ee0343-73fc-58a8-9e6a-3094c59b2c12

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-03-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added five high‑severity flaws (Apple WebKit and kernel bugs, Craft CMS, and Laravel Livewire) to its Known Exploited Vulnerabilities catalog with an April 3, 2026 patch directive; several are confirmed or assessed as actively exploited. Google, vendor researchers, and multiple security firms link the Apple bugs to an iOS exploit kit called DarkSword that deploys data‑theft malware (GHOST* families), while other CVEs have been used by intrusion sets like Mimo/Hezb to install miners/proxyware and by MuddyWater (Boggy Serpens) in espionage and disruptive operations against diplomatic, energy, maritime, and finance targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.