惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
Arctic Wolf
有赞技术团队
有赞技术团队
H
Help Net Security
N
Netflix TechBlog - Medium
G
Google Developers Blog
GbyAI
GbyAI
Jina AI
Jina AI
D
DataBreaches.Net
博客园 - Franky
Recent Announcements
Recent Announcements
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
N
News | PayPal Newsroom
S
SegmentFault 最新的问题
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
S
Schneier on Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
V
V2EX
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】
P
Privacy International News Feed
T
The Exploit Database - CXSecurity.com
云风的 BLOG
云风的 BLOG
F
Full Disclosure
Microsoft Security Blog
Microsoft Security Blog
MongoDB | Blog
MongoDB | Blog
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
C
Cyber Attacks, Cyber Crime and Cyber Security
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
Spread Privacy
Spread Privacy
罗磊的独立博客
P
Proofpoint News Feed
The Last Watchdog
The Last Watchdog
S
Secure Thoughts
O
OpenAI News
P
Palo Alto Networks Blog
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
Tenable Blog
雷峰网
雷峰网
C
Cisco Blogs

Enterprise – Silicon Republic

Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Cybersecurity warning for Irish businesses ahead of EU Presidency Dublin's TensorX to partner with Solstice on sovereign European AI Irish Internet Hotline named Trusted Flagger under EU Digital Services Act Don't panic, prepare: A cyber expert's advice on the Mythos hype Day-to-day cyber incidents driving loss for SMEs, finds report Anthropic to reassess Claude Fable 5 AI development restrictions after backlash Anthropic rolls out ‘Mythos-like’ AI model Claude Fable 5 EMEA firms underestimating 'routine risks', finds cyber report More than 20,000 Instagram accounts hacked using Meta AI bug Report: Irish firms cut cybersecurity spend despite rising risks TCS launches sovereign cloud offering in Europe ECB urging action on AI from lenders’ IT departments Hackers access GitHub, download codebase in Grafana Labs breach Europe's public sector deploying AI faster than it can manage – report UK watchdog probes Microsoft over interoperability issues Foxconn confirms cyberattack on North American facilities Clear gap between AI expectations and preparedness, finds report Canvas parent settles with hacker group that stole user data ShinyHunters demands ransom after Canvas hack EU agrees to simpler AI rules and complete ‘nudification’ ban What’s the difference between IT and OT security? Opinion: Why ISO 27001 alone won't save your data from itself Report: Medical device cyberattacks on the rise AI race intensifies with Google's new agent management platform Anthropic probing reported Mythos leak on Discord Nearly 75pc of AI’s economic value captured by just 20pc of companies Anthropic’s Mythos to bolster cybersecurity at UK banks The death of ETL: Is zero-copy a ‘liberation’ for data teams? After Anthropic, OpenAI launches cyber-specific AI model The Interview: Dentons' Carlo Salizzo on three forces defining digital law Anthropic's Mythos a game-changer, NCSC chief tells Oireachtas Mythos just first of power models to come: Anthropic co-founder New XP95 hacker group targets Dublin recruitment platform Healthdaq OpenAI apps for MacOS exposed by threat Mythos testing begins as governments raise cyber concerns Anthropic's Glasswing project employs Mythos to prevent AI cyberattacks Is your data integrity framework just a fancy spreadsheet? Ireland begins digital wallet testing and consultation How is Australia working to make data centres more sustainable? China's DeepSeek suffers rare outage lasting several hours ShinyHunters claims responsibility for European Commission breach Security first: Why cybersecurity needs to adapt in the age of AI China’s Alibaba could launch Qwen for enterprise this week Stryker's Cork site hit by global cyberattack Office.eu and the hope for a digitally sovereign Europe How fully homomorphic encryption is reshaping secure AI Major phishing operation disrupted in joint Europol action Hacking tool with possible US origins targets outdated iPhones Pure Storage, now Everpure, to acquire 1touch Hacker used commercial AI to breach 600 firewalls: AWS Why cloud strategies are pivoting from reaction to precision ‘Complexity is where cyber risk tends to grow’ ‘In cyber, bridging the gap between the server room and boardroom is crucial’ AWS expanding in Belgium, Netherlands and Portugal, amid sovereign cloud launch
iOS hacking tool 'DarkSword' leaked on GitHub
Suhasini Srinivasaragavan · 2026-03-24 · via Enterprise – Silicon Republic

DarkSword is similar to Coruna, which targets iPhone models running iOS versions from 13.0 up to 17.2.1.

A major iOS exploit kit uncovered by cybersecurity experts earlier this month has been leaked on GitHub, further increasing vulnerabilities for older iPhones and iPads.

In a joint investigation this month, Google Threat Intelligence Group (GTIG) and iVerify shone a light on ‘DarkSword’, a new full-chain exploit that targets iOS versions 18.4 through 18.7. It is likely that millions of users globally run older Apple products that this exploit could affect.

Since at least November 2025, DarkSword has been used by numerous commercial surveillance and suspected state-sponsored actors to target users in Saudi Arabia, Turkey, Malaysia and Ukraine, found GTIG.

These attacks used multiple vulnerabilities in Apple’s operating system to gain access to sensitive information from the users’ devices.

GTIG identified hackers leveraging a Snapchat-themed fake website to target Saudi Arabian users, while it also observed DarkSword use in Turkey, as well by suspected a Russian espionage actor leveraging the exploit to target Ukrainian users.

The group said it reported these DarkSword vulnerabilities to Apple late last year, and these have all since been patched with the release of iOS 26.3. However, yesterday (23 March), TechCrunch reported that a newer version of DarkSword was leaked on the code-sharing site GitHub.

Speaking to the publication, iVerify co-founder Matthias Frielingsdorf said that these exploits are “way too easy to repurpose”.

He added: “I don’t think that can be contained anymore. So we need to expect criminals and others to start deploying this.”

DarkSword is similar to ‘Coruna’, an exploit uncovered earlier this month. Coruna targets iPhone models running iOS versions from 13.0 up to 17.2.1.

The exploit kit infects outdated iPhones visiting certain websites. It does not contain any specific targeting or one-time links, meaning anyone who visited such a website while running a vulnerable iOS version could get infected, and also get re-infected multiple times.

GTIG and iVerify said that the use of both DarkSword and Coruna by a variety of actors demonstrates the ongoing risk of exploit proliferation across actors with different goals across the globe.

It is recommended that users update their devices to the latest version of iOS. In cases of older models where updates are not possible, it is advised that users enable ‘Lockdown Mode’ for enhanced security.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.