Apple urges iPhone users to update as Coruna and DarkSword exploit kits emerge
2026-03-20T14:51:49Z•1d4184512d411a65ee29293635548ebfa3265f88f3f3b740ad170519207eeae3
aisuruaptcisaciscocorunacve-2025-66376cve-2026-20131darkswordespionageexploit-kitinterlockiosiot-botnetjackskidkevkimwolflaw-enforcementopsecrcestravaubiquitiunifixsszero-dayzimbra
What happened
Multiple high-risk developments: Apple warns iPhone users to update as Coruna and DarkSword iOS exploit kits are actively used to steal data; DarkSword is linked to multiple actors and nation-state surveillance. A critical Cisco Secure Firewall Management Center (FMC) RCE, CVE-2026-20131 (CVSS 10.0), is being actively exploited (Interlock) and was added to CISA’s Known Exploited Vulnerabilities catalog. A Zimbra XSS vulnerability (CVE-2025-66376) is being used by a Russia-linked APT against Ukrainian targets and was also added to KEV; Ubiquiti patched a maximum-severity UniFi account-takeover.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1d4184512d411a65ee29293635548ebfa3265f88f3f3b740ad170519207eeae3
- Enrichment time
- 2026-03-20T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.