DarkSword emerges as powerful iOS exploit tool in global attacks
2026-03-19T14:51:45Z•1d69ebc34f6a4803cd4303f1a39728558038188cfe1d8454f96a85eef762f18c
CISACVE-2026-20131CVE-2026-32746CVE-2026-3888Cisco-FMCDarkSwordEU-sanctionsInterlockIntuitiveKnown-Exploited-VulnerabilitiesRondoDoxRussia-espionageSharePointUbuntuViennaZimbrabotnetdata-breachexploit-kitiOS-exploitmass-exploitationphishingsystemdtelnetdzero-day
What happened
Multiple high-impact incidents reported: DarkSword — a powerful new iOS exploit kit — is being used by multiple actors (including surveillance vendors and likely nation-state actors) in campaigns targeting Saudi Arabia, Turkey, Malaysia and Ukraine. The Interlock ransomware group has been exploiting a critical Cisco Secure FMC zero-day RCE (CVE-2026-20131, CVSS 10.0) since late January. Researchers disclosed a critical GNU InetUtils telnetd remote code execution flaw (CVE-2026-32746, CVSS 9.8) affecting all versions, and Qualys reported a systemd timing privilege-escalation bug in Ubuntu Desk
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1d69ebc34f6a4803cd4303f1a39728558038188cfe1d8454f96a85eef762f18c
- Enrichment time
- 2026-03-19T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.