DarkSword emerges as powerful iOS exploit tool in global attacks

2026-03-19T14:51:45Z1d69ebc34f6a4803cd4303f1a39728558038188cfe1d8454f96a85eef762f18c
CISACVE-2026-20131CVE-2026-32746CVE-2026-3888Cisco-FMCDarkSwordEU-sanctionsInterlockIntuitiveKnown-Exploited-VulnerabilitiesRondoDoxRussia-espionageSharePointUbuntuViennaZimbrabotnetdata-breachexploit-kitiOS-exploitmass-exploitationphishingsystemdtelnetdzero-day

What happened

Multiple high-impact incidents reported: DarkSword — a powerful new iOS exploit kit — is being used by multiple actors (including surveillance vendors and likely nation-state actors) in campaigns targeting Saudi Arabia, Turkey, Malaysia and Ukraine. The Interlock ransomware group has been exploiting a critical Cisco Secure FMC zero-day RCE (CVE-2026-20131, CVSS 10.0) since late January. Researchers disclosed a critical GNU InetUtils telnetd remote code execution flaw (CVE-2026-32746, CVSS 9.8) affecting all versions, and Qualys reported a systemd timing privilege-escalation bug in Ubuntu Desk­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1d69ebc34f6a4803cd4303f1a39728558038188cfe1d8454f96a85eef762f18c
Enrichment time
2026-03-19T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.