NEWS

CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

CISA orders federal agencies to patch five actively exploited vulnerabilities by April 3, including three Apple flaws linked to the DarkSword iOS exploit...

Dylan H.

News Desk

March 22, 2026
3 min read
CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

Five Actively Exploited Flaws Added to CISA's Known Exploited Vulnerabilities Catalog

CISA added five security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on March 21, 2026, ordering federal agencies to apply patches by April 3, 2026. Three of the flaws are linked to a sophisticated iOS exploit kit codenamed DarkSword.


CVEProductCVSSType
CVE-2025-31277Apple WebKit8.8Memory corruption via web content
CVE-2025-43510Apple Kernel7.8Memory corruption (inter-process)
CVE-2025-43520Apple Kernel8.8Memory corruption (kernel write)
CVE-2025-32432Craft CMS10.0Code injection → RCE
CVE-2025-54068Laravel Livewire9.8Unauthenticated RCE

The DarkSword iOS Exploit Kit

Google Threat Intelligence Group (GTIG), iVerify, and Lookout documented an iOS exploit kit called DarkSword that chains the three Apple vulnerabilities together to deploy multiple malware families:

  • GHOSTBLADE — Primary implant for persistent device access
  • GHOSTKNIFE — Data exfiltration module targeting messaging apps
  • GHOSTSABER — Credential harvesting and keylogging component

The exploit chain requires only that a target visit a malicious webpage, making it a zero-click attack when combined with a phishing link delivered via SMS or messaging apps.

Craft CMS Zero-Day (CVE-2025-32432)

The Craft CMS vulnerability carries the maximum CVSS 10.0 score and has been exploited as a zero-day since February 2025. An intrusion set tracked as Mimo (aka Hezb) has been observed exploiting it to deploy cryptocurrency miners and residential proxyware on compromised servers.

Laravel Livewire RCE (CVE-2025-54068)

The Laravel Livewire flaw allows unauthenticated attackers to achieve remote command execution in specific configurations. With Laravel powering millions of web applications globally, the exposure surface is significant.


Impact AreaDescription
iOS DevicesZero-click exploitation via malicious web content
Web ServersRCE on Craft CMS and Laravel Livewire installations
Data TheftDarkSword deploys multiple espionage malware families
Crypto MiningMimo group leveraging Craft CMS for mining operations
Federal DeadlineAll agencies must patch by April 3, 2026

Recommendations

For iOS Users

  • Update to the latest iOS/iPadOS immediately
  • Enable Lockdown Mode if you are a high-risk target
  • Avoid clicking links from unknown sources

For Web Developers

  • Craft CMS: Update to version 4.14.16 or 5.6.18+ immediately
  • Laravel Livewire: Update to version 3.6.4+ or apply the security patch
  • Audit server logs for signs of exploitation

Key Takeaways

  1. DarkSword is a nation-state-grade iOS exploit kit chaining three vulnerabilities for zero-click compromise
  2. GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER form a complete espionage toolkit targeting messaging app data
  3. Craft CMS CVE-2025-32432 has been exploited for over a year with a perfect CVSS 10.0 score
  4. Laravel Livewire's unauthenticated RCE affects millions of web applications globally
  5. Federal agencies have until April 3 to remediate all five vulnerabilities

Sources