Darksword Spyware: CISA Sets Deadline for Federal Agencies to Patch Apple & Web Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive Friday, ordering federal agencies to patch five newly identified security vulnerabilities by April 3, 2026. The vulnerabilities, impacting Apple products, Craft CMS, and Laravel Livewire, are reportedly being actively exploited by hackers, raising concerns about potential data breaches and system compromises.
Among the most critical flaws is a code injection vulnerability in Craft CMS (CVE-2025-32432), assigned a severity score of 10.0, which could allow remote attackers to execute arbitrary code. A similar vulnerability exists in Laravel Livewire (CVE-2025-54068), enabling unauthenticated attackers to execute commands. CISA also flagged three vulnerabilities affecting Apple’s iOS and macOS operating systems, stemming from issues in Apple WebKit and the kernel component. These Apple vulnerabilities – CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520 – can be triggered through maliciously crafted web content.
The CISA directive comes amid growing concern over sophisticated mobile exploits. Security researchers at iVerify, Lookout, and Google recently identified a new iOS exploit kit dubbed “DarkSword,” which leverages some of these vulnerabilities. According to Lookout’s Justin Albrecht, DarkSword can be used to exfiltrate saved passwords, cryptocurrency wallet data, text messages, and more. The discovery of DarkSword follows the emergence of another similar exploit kit, Coruna, earlier this month.
While Coruna was primarily used for financial gain by Russian and Chinese hackers, researchers suggest DarkSword may serve both financial and surveillance purposes, or even be used to inflict harm. IVerify estimates that up to 270 million iPhone users could be susceptible to DarkSword, with roughly 15% of all iOS devices currently in utilize running vulnerable versions of iOS 18 or earlier. The group behind DarkSword is currently tracked as UNC6353, and definitive attribution remains unclear.
Apple responded to reports of DarkSword, stating that the underlying iOS vulnerabilities were patched last year. The company also released an emergency software update on March 11 for older iOS devices unable to update to the latest versions. Apple asserts that users running iOS 15 through iOS 26 are protected, but those still using iOS 13 or 14 must update to iOS 15 to receive the same protections. Users on older versions will receive alerts prompting them to install a Critical Security Update in the coming days. Apple also confirmed that its optional Lockdown Mode protection effectively blocks DarkSword and similar exploits.
Researchers have also noted the potential involvement of large language models (LLMs) in customizing both Coruna and DarkSword, suggesting a trend toward AI-assisted cyberattacks. Google Threat Intelligence Group (GTIG) has reported that DarkSword has been used in attacks targeting individuals in Saudi Arabia, Turkey, and Malaysia, in addition to Ukraine.
The addition of these vulnerabilities to CISA’s Known Exploited Vulnerabilities (KEV) catalog mandates that federal agencies address the flaws within a specified timeframe. The KEV catalog highlights vulnerabilities that are actively being exploited in the wild, requiring immediate attention to mitigate potential risks. As of Monday, March 23, 2026, the agency has not released a public statement detailing the extent of any breaches related to these vulnerabilities.