Tuesday , September 29 2026
iPhone

270M iPhones Vulnerable to ‘DarkSword’ Exploit
270m iPhones Vulnerable to ‘DarkSword’ Exploit: Hack code now on GitHub

The iPhone is said as one of the safest smartphones now, but like Android phones, it has been attacked by hackers who use various flaws. Last week, a cybersecurity expert found a hacking scheme aimed at iPhone users using a tool named DarkSword. Now, someone has uploaded a new version of DarkSword to the well-known code-sharing site GitHub.

What is DarkSword?

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Discovered by the Google Threat Intelligence Group (GTIG) last week, DarkSword is an iOS “full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices.”

GTIG said, several companies that sell surveillance tools and some government groups are already using DarkSword in different operations aimed at iPhone users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

DarkSword supports iOS 18.4 to iOS 18.7 and uses a total of six different vulnerabilities and three different malware families – GHOSTBLADE< GHOSTKNIFE, and GHOSTSABER.

GTIG also mentioned that all security holes used by DarkSword were fixed in the iOS 26.3 update. This means that iPhones updated to the newest version of the system are safe from this attack. Most iPhones got the iOS 26 update, but some models like the iPhone X and older are still on iOS 18. This means the exploit can still attack these devices.

Millions of iPhone users are at risk

Researchers said that now DarkSword is on GitHub, anyone can use the tools to attack iPhone users with older iOS versions. This flaw reportedly impacts hundreds of millions of iPhones and iPads.

Matthias Frielingsdorf, the co-founder of mobile security startup iVerify said, “This is bad. They are way too easy to repurpose. I don’t think that can be contained anymore. So we need to expect criminals and others to start deploying this,”.

He said the new DarkSword version on GitHub has the same setup that iVerify checked before, but the files are somewhat different. Frielingsdorf mentioned that since the files on the code-sharing site are simple HTML and JavaScript, anyone can easily copy the code and put it on a server in just a few minutes.

He added that the “exploits will work out of the box. This is no iOS expertise required.” Right now, the surefire way to protect your iPhone against DarkSword is by updating your iPhone to the latest version of iOS 26.

Check Also

Fortinet FortiGate

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate …