Back to Feed
VulnerabilitiesMar 23, 2026

CISA orders feds to patch DarkSword iOS flaws exploited attacks

CISA orders federal agencies to patch three iOS vulnerabilities exploited by DarkSword kit in active attacks.

Vendor Watch

Run Apple?

Get an email when a reviewed story names Apple, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

CISA has issued a mandatory patching directive to U.S. government agencies to address three iOS vulnerabilities actively exploited through the DarkSword exploit kit in cryptocurrency theft and cyberespionage campaigns. The vulnerabilities are being weaponized in targeted attacks against government infrastructure and personnel. This emergency order underscores the severity and active exploitation status of these flaws.

Indicators of Compromise

  • malware — DarkSword

Entities

Apple (vendor)iOS (product)DarkSword exploit kit (technology)