A DarkSword hangs over unpatched iPhones
2026-03-19T20:52:01Z•918639762eaf235be84c394f95f302af8e8ea92e5d5e6aa78205ef5a7ba456fa
accessibility-abuseai-prompt-manipulationandroidav-bypasscalendar-scamchromeclickfixcorunacve-2026-20643darkswordexploit-kitfont-renderinginfostealeriosmalwaremicrosoft-authenticatormobilephishingscamssocial-engineeringvidarweb-security','threat-intelwebkitzero-dayzombie-zip
What happened
Malwarebytes' recent feed highlights multiple active and emerging threats across mobile, web, and social channels. Notable items: a state-linked DarkSword exploit chain targeting unpatched iPhones; Apple’s silent WebKit fix (CVE-2026-20643) and additional patches for older iOS to address the Coruna exploit kit; two Chrome zero-days patched under active attack; delivery campaigns for the Vidar infostealer via hacked sites; several phishing and scam networks (fake shops, Pudgy Penguins phishing, Temu airdrop ClickFix, fake calendar renewal notices); and other issues including a Microsoft Authent
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 918639762eaf235be84c394f95f302af8e8ea92e5d5e6aa78205ef5a7ba456fa
- Enrichment time
- 2026-03-19T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.