Millions of iPhones can be hacked with a new tool found in the wild

2026-03-20T20:51:56Z15cd1d24e1dc33c2ae1ee0957311f35e7648aea8745241412c6528abe05b57d3
CISAairsnitchandroid-advanced-flow-24hbios-accessbotnetcrypto-theftdarkSwordgithubiosip-kvmiphonelumma-stealermalwaremobile-exploitnotepad++office-exploitpatchingrouterssideloadingstrykersupply-chainunicode-homoglyphwifiwiperzero-day

What happened

A cluster of high-risk security incidents reported by Ars Technica: DarkSword, a powerful iPhone-hacking tool, is observed in the wild and reportedly capable of compromising hundreds of millions of iPhones; CISA added multiple iOS flaws to its Known Exploited Vulnerabilities catalog. Other active threats include BIOS-level access vulnerabilities in internet-exposed IP‑KVMs, a Unicode-based supply‑chain attack affecting GitHub and package repositories, widespread router malware infecting ~14,000 devices, a destructive wiper attack that has taken down Stryker's Windows network, AirSnitch Wi‑Fi‑b

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
15cd1d24e1dc33c2ae1ee0957311f35e7648aea8745241412c6528abe05b57d3
Enrichment time
2026-03-20T20:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.