VulnerabilitiesMar 23, 2026
CISA orders feds to patch DarkSword iOS flaws exploited attacks
CISA orders federal agencies to patch three iOS vulnerabilities exploited by DarkSword kit in active attacks.
Vendor Watch
Run Apple?
Get an email when a reviewed story names Apple, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
CISA has issued a mandatory patching directive to U.S. government agencies to address three iOS vulnerabilities actively exploited through the DarkSword exploit kit in cryptocurrency theft and cyberespionage campaigns. The vulnerabilities are being weaponized in targeted attacks against government infrastructure and personnel. This emergency order underscores the severity and active exploitation status of these flaws.
Indicators of Compromise
- malware — DarkSword
Entities
Apple (vendor)iOS (product)DarkSword exploit kit (technology)