Apple expands “DarkSword” patches to iOS 18.7.7

2026-04-02T20:51:52Z02fb15e8c786c124512b58e53eda00d9bc5f86f43ec02c66f4f8840430c11598
ClickFixDarkSwordGlassWormInfiniti StealerNukeChainVPN-auditVenom StealerWhatsAppWindowsaccount-hijackingaxiosbrowser-extensionexploit-kitiOSiPadOSmacOSnpmpersistenceremote-access-trojanscamssecurity-patchsocial-engineeringsupply-chainthird-party-auditvirtual-phones

What happened

Malwarebytes published a roundup of multiple active threats and mitigations: Apple quietly expanded patches for vulnerabilities exploited by the DarkSword exploit kit to iOS/iPadOS 18.7.7; Microsoft warned of an ongoing campaign targeting WhatsApp on Windows to gain persistent access; an npm supply‑chain compromise of axios distributed a RAT; macOS ClickFix attacks and a new Infiniti (NukeChain) macOS infostealer abusing fake CAPTCHA pages and Python/Nuitka were observed; a bogus Avast site pushed Venom Stealer; GlassWorm installs fake browser extensions for surveillance; and US agencies warn‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
02fb15e8c786c124512b58e53eda00d9bc5f86f43ec02c66f4f8840430c11598
Enrichment time
2026-04-02T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.