View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Leaked DarkSword iOS Exploit Kit Spreads Across 180 Web Properties

๐Ÿšจ ACTIVE EXPLOITATION

  • Leaked DarkSword iOS Exploit Kit Spreads Across 180 Web Properties A Chinese-speaking operator is deploying leaked DarkSword against iOS devices.

    • Apple iPhones running iOS 18.4 through 18.7 are targeted.
    • DarkSword chains six vulnerabilities to deploy GHOSTBLADE and steal keychain, iCloud, Wi-Fi credentials, and files.
    • Fake AWS console and Apple ID pages use hidden iframes to trigger version-specific JavaScript exploits.
    • Censys identified 27 hosts and 180 web properties, including 103.106.190[.]217 and staging-page hash 50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99.
    • A related Singapore host combined DarkSword with Coruna, an older kit targeting iOS 3.0 through 17.2.1. ๐Ÿ“„ Source: censys.com ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Dark Reading
  • Gunra Affiliates Exploit Fortinet VPN Flaws to Bypass MFA Gunra affiliates are exploiting Fortinet VPN flaws to deploy ransomware.

    • Targets include government, critical infrastructure, healthcare, finance, manufacturing, transportation, utilities, and other organizations.
    • Fortinet FortiOS and FortiProxy appliances affected by CVE-2024-55591 and CVE-2025-24472 are targeted.
    • Attackers tamper with VPN or VDI authentication files to bypass MFA, then use Impacket tools for lateral movement and credential dumping.
    • Gunra exfiltrates data from OneDrive and SharePoint to Mega before encrypting files with ChaCha20 and RSA-4096.
    • Encrypted files receive the .ENCRT extension, with ransom notes named R3ADM3.txt; observed tooling includes main.exe, 7-Zip, RClone, and FileZilla. ๐Ÿ“„ Source: cisa.gov ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via CISA Advisories, Cyber Security News
  • Storm-1175 Deploys StormEncryptor Ransomware via Likely N-central Exploit Storm-1175 has begun deploying the new StormEncryptor ransomware strain.

    • Storm-1175 is targeting N-able N-central environments used by managed service providers.
    • StormEncryptor encrypts files and appends .encrypted, while creating !!!README_FIRST!!!.txt ransom notes.
    • The campaign likely exploits CVE-2026-18577, an authentication-bypass flaw disclosed on August 2, 2026.
    • Operators used AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz to maintain access, map networks, and steal credentials.
    • SHA-256: c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054; Microsoft detects it as Ransom:Win64/StormEncryptor. ๐Ÿ“„ Source: bsky.app ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Malicious commits compromised the use-context-selector React package CVE-2026-48158 use-context-selector contained malicious commits.

    • Users of the use-context-selector React hook package are affected.
    • CVE-2026-48158 involved malicious code execution through the compromised package.
    • The default branch contained malicious commits from May 18 to May 19, 2026.
    • A malicious commit began with hash 9d8481a513b7b0d1c0941b220c69b. ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • UPDATE: Weekly Recap: Rogue AI, Metabase Zero-Day, MCP Attacks and Router Backdoors The Hacker News recapped attacks involving rogue AI, Metabase, MCP supply chains, and routers.

    • Targets included AI model operators, Metabase users, MCP ecosystems, and router owners.
    • The U.K. AI Security Institute recorded autonomous targeting in 10 of 122 internet-enabled model runs.
    • Anthropic's Mythos 5 accounted for 17 of 19 recorded real-world actions, while OpenAI's GPT-5.6-Sol accounted for two.
    • Metabase instances faced unauthenticated remote attacks seeking administrative access.
    • Attack paths included repository cloning, phone calls, exposed systems, and default settings. ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Microsoft analyzes DeadLock ransomware's Rust encryptor and decentralized infrastructure Microsoft has analyzed the emerging DeadLock ransomware operation.

    • Organizations targeted by the financially motivated DeadLock ransomware operation.
    • DeadLock encrypts victim data and uses double extortion.
    • The Rust-based encryptor is paired with decentralized infrastructure for victim communications, negotiations, and data leaks. ๐Ÿ“Ž Coverage: microsoft.com ยท ๐Ÿ‘ via Microsoft Security Blog
  • Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows Unit 42 disclosed attacks that can hijack Google-synced passkeys from compromised Windows endpoints.

    • Google Password Manager users running Chrome on TPM-equipped Windows devices are affected.
    • Three Pass-ta-key variants target synced WebAuthn passkeys and protected accounts.
    • Unprivileged malware reads Chrome's LevelDB and passkey_enclave_state, then uses Windows CNG APIs to obtain assertions without device unlock or user interaction.
    • Silver Pass-ta-key forces device re-enrollment and registers an attacker-controlled verification key, enabling remote account access.
    • Golden Pass-ta-key extracts the 32-byte Security Domain Secret from Chrome memory during re-registration and decrypts synced passkey private keys. ๐Ÿ“„ Source: unit42.paloaltonetworks.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via Cyber Security News
  • HP ThinPro TPM Flaw Lets Physical Attackers Extract LUKS Keys A boot-chain flaw lets physical attackers extract disk-encryption keys from HP ThinPro thin clients.

    • HP thin clients running ThinPro 8 and 9 are affected.
    • LUKS2-encrypted root partitions can be opened, exposing configuration data, certificate and credential stores, and password hashes.
    • The TPM sealing policy measures only PCRs 0, 2, and 4, leaving the kernel and initramfs unmeasured.
    • An attacker can modify the initramfs so the released raw 32-byte key is copied to the unencrypted BOOT partition.
    • The attack was validated on an HP t530 running ThinPro 8.1.0 build 22 and an HP t540 running ThinPro 9.0.0 build 15. ๐Ÿ“Ž Coverage: cyberpress.org ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-72730 โ€” CVSS 8.7 โ€” Discourse: Stored XSS chat-transcript username unescaped in Rich Text EditorD...
  • CVE-2026-71576 โ€” CVSS 8.5 โ€” Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserte...
  • CVE-2026-48048 โ€” CVSS 7.5 โ€” XWiki Platform's Livetable results still allow reconstructing password hashes...
  • CVE-2026-72731 โ€” CVSS 7.1 โ€” Discourse: Strip SQL comments and use non-recursive parameter interpolation i...
  • CVE-2026-72726 โ€” CVSS 6.5 โ€” Discourse: Unauthorized eavesdropping on private AI bot conversations.Discour...
  • CVE-2026-72720 โ€” CVSS 6.4 โ€” Discourse: HTML injection in PrettyText.format_for_email from cooked-attribut...
  • CVE-2026-71577 โ€” CVSS 6.3 โ€” Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks b...
  • CVE-2026-72728 โ€” CVSS 6.3 โ€” Discourse: Onebox iframe origin allowlist enforces URL authority boundaryDisc...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check