Apple expands “DarkSword” patches to iOS 18.7.7
2026-04-02T20:51:52Z•02fb15e8c786c124512b58e53eda00d9bc5f86f43ec02c66f4f8840430c11598
ClickFixDarkSwordGlassWormInfiniti StealerNukeChainVPN-auditVenom StealerWhatsAppWindowsaccount-hijackingaxiosbrowser-extensionexploit-kitiOSiPadOSmacOSnpmpersistenceremote-access-trojanscamssecurity-patchsocial-engineeringsupply-chainthird-party-auditvirtual-phones
What happened
Malwarebytes published a roundup of multiple active threats and mitigations: Apple quietly expanded patches for vulnerabilities exploited by the DarkSword exploit kit to iOS/iPadOS 18.7.7; Microsoft warned of an ongoing campaign targeting WhatsApp on Windows to gain persistent access; an npm supply‑chain compromise of axios distributed a RAT; macOS ClickFix attacks and a new Infiniti (NukeChain) macOS infostealer abusing fake CAPTCHA pages and Python/Nuitka were observed; a bogus Avast site pushed Venom Stealer; GlassWorm installs fake browser extensions for surveillance; and US agencies warn‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 02fb15e8c786c124512b58e53eda00d9bc5f86f43ec02c66f4f8840430c11598
- Enrichment time
- 2026-04-02T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.