Apple urges iPhone users to update as Coruna and DarkSword exploit kits emerge

2026-03-20T14:51:49Z1d4184512d411a65ee29293635548ebfa3265f88f3f3b740ad170519207eeae3
aisuruaptcisaciscocorunacve-2025-66376cve-2026-20131darkswordespionageexploit-kitinterlockiosiot-botnetjackskidkevkimwolflaw-enforcementopsecrcestravaubiquitiunifixsszero-dayzimbra

What happened

Multiple high-risk developments: Apple warns iPhone users to update as Coruna and DarkSword iOS exploit kits are actively used to steal data; DarkSword is linked to multiple actors and nation-state surveillance. A critical Cisco Secure Firewall Management Center (FMC) RCE, CVE-2026-20131 (CVSS 10.0), is being actively exploited (Interlock) and was added to CISA’s Known Exploited Vulnerabilities catalog. A Zimbra XSS vulnerability (CVE-2025-66376) is being used by a Russia-linked APT against Ukrainian targets and was also added to KEV; Ubiquiti patched a maximum-severity UniFi account-takeover.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1d4184512d411a65ee29293635548ebfa3265f88f3f3b740ad170519207eeae3
Enrichment time
2026-03-20T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.