VulnerabilitiesHIGH

Apple Rolls Out DarkSword Exploit Protection to More Devices

Featured image for Apple Rolls Out DarkSword Exploit Protection to More Devices
SWSecurityWeek
DarkSwordiOS 18Appleexploit kitvulnerabilities
🎯

Basically, Apple updated its software to protect older devices from a dangerous hacking tool.

Quick Summary

Apple has released crucial updates to protect older devices from the DarkSword exploit kit. Millions were previously vulnerable, making this rollout vital for security. Ensure your device is updated to stay safe from these threats.

What Happened

Apple has announced the rollout of iOS 18.7.7 and iPadOS updates to enhance security against the DarkSword exploit kit. This exploit, which targets vulnerabilities in Apple’s mobile platforms, has been linked to state-sponsored hackers and commercial spyware vendors. The updates were made available on April 1, 2026, following warnings from security firms about the risks associated with DarkSword.

The Flaw

The DarkSword exploit kit takes advantage of six vulnerabilities in iOS, allowing attackers to potentially fully compromise devices with minimal user interaction. Security experts have noted that at least two Russian nation-state groups have utilized this exploit in their operations. The vulnerabilities can lead to serious issues, including kernel code execution and keychain access.

What's at Risk

Before the updates, an estimated 200 million devices running iOS versions between 18.4 and 18.6.2 were at risk. This large number highlights the widespread vulnerability among older Apple devices, making the timely release of patches critical for user security.

Patch Status

Apple had previously released patches for these vulnerabilities in 2025. However, the emergence of DarkSword prompted the company to extend these protections to older devices. The latest update addresses two dozen security flaws, significantly reducing the risk of exploitation.

Immediate Actions

Users of affected devices, including various models of iPhones and iPads, are encouraged to ensure that Automatic Updates are enabled. This will allow them to receive the critical security patches without delay. Users can also manually check for updates in their device settings to ensure they are protected against DarkSword and other potential threats.

Conclusion

The rollout of these updates is a proactive measure by Apple to safeguard its users from emerging threats. As cyber threats evolve, it is essential for users to stay informed and keep their devices updated to mitigate risks effectively.

🔒 Pro insight: The rapid response to DarkSword demonstrates Apple's commitment to user security amid increasing state-sponsored cyber threats.

Original article from

SWSecurityWeek· Eduard Kovacs
Read Full Article

Related Pings

CRITICALVulnerabilities

CVE-2025-55182 - Hackers Breach 766 Next.js Hosts

Hackers have exploited a critical vulnerability in Next.js, breaching 766 hosts and stealing sensitive credentials. Organizations must take swift action to mitigate risks and secure their systems.

The Hacker News·
HIGHVulnerabilities

OpenSSH Vulnerabilities - Security Advisory Released

OpenSSH has issued a security advisory for vulnerabilities in versions prior to 10.3. Users need to update to the latest version to protect their systems. This advisory highlights critical risks that could lead to unauthorized access. Stay secure by applying the necessary updates.

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Progress ShareFile - Security Vulnerability Advisory Released

Progress has issued a security advisory for ShareFile vulnerabilities. Users must update to versions v5.12.4 or later to protect their data. This is crucial for maintaining security.

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Mongoose Vulnerabilities - Cesanta Issues Security Advisory

Cesanta has issued a security advisory for Mongoose, affecting versions 7.0 to 7.20. Users must update to safeguard against vulnerabilities. Don't wait—protect your systems now!

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Cisco Patches Critical and High-Severity Vulnerabilities

Cisco has patched critical vulnerabilities that could allow attackers to bypass authentication and gain system access. Organizations using Cisco products are urged to update immediately to avoid risks.

Security Affairs·
CRITICALVulnerabilities

Critical Vulnerability Found in Claude Code After Source Leak

A critical vulnerability in Claude Code was discovered shortly after its source code leak. This flaw could allow attackers to bypass security measures and steal sensitive credentials, posing a significant risk. Developers must act quickly to protect their systems.

SecurityWeek·