惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
V
V2EX
Microsoft Security Blog
Microsoft Security Blog
V
Visual Studio Blog
A
About on SuperTechFans
博客园_首页
L
LangChain Blog
量子位
雷峰网
雷峰网
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence
N
Netflix TechBlog - Medium

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
iOS hacking tool 'DarkSword' leaked on GitHub
Suhasini Srinivasaragavan · 2026-03-24 · via Enterprise – Silicon Republic

DarkSword is similar to Coruna, which targets iPhone models running iOS versions from 13.0 up to 17.2.1.

A major iOS exploit kit uncovered by cybersecurity experts earlier this month has been leaked on GitHub, further increasing vulnerabilities for older iPhones and iPads.

In a joint investigation this month, Google Threat Intelligence Group (GTIG) and iVerify shone a light on ‘DarkSword’, a new full-chain exploit that targets iOS versions 18.4 through 18.7. It is likely that millions of users globally run older Apple products that this exploit could affect.

Since at least November 2025, DarkSword has been used by numerous commercial surveillance and suspected state-sponsored actors to target users in Saudi Arabia, Turkey, Malaysia and Ukraine, found GTIG.

These attacks used multiple vulnerabilities in Apple’s operating system to gain access to sensitive information from the users’ devices.

GTIG identified hackers leveraging a Snapchat-themed fake website to target Saudi Arabian users, while it also observed DarkSword use in Turkey, as well by suspected a Russian espionage actor leveraging the exploit to target Ukrainian users.

The group said it reported these DarkSword vulnerabilities to Apple late last year, and these have all since been patched with the release of iOS 26.3. However, yesterday (23 March), TechCrunch reported that a newer version of DarkSword was leaked on the code-sharing site GitHub.

Speaking to the publication, iVerify co-founder Matthias Frielingsdorf said that these exploits are “way too easy to repurpose”.

He added: “I don’t think that can be contained anymore. So we need to expect criminals and others to start deploying this.”

DarkSword is similar to ‘Coruna’, an exploit uncovered earlier this month. Coruna targets iPhone models running iOS versions from 13.0 up to 17.2.1.

The exploit kit infects outdated iPhones visiting certain websites. It does not contain any specific targeting or one-time links, meaning anyone who visited such a website while running a vulnerable iOS version could get infected, and also get re-infected multiple times.

GTIG and iVerify said that the use of both DarkSword and Coruna by a variety of actors demonstrates the ongoing risk of exploit proliferation across actors with different goals across the globe.

It is recommended that users update their devices to the latest version of iOS. In cases of older models where updates are not possible, it is advised that users enable ‘Lockdown Mode’ for enhanced security.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.