Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog
CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog
NEWS

CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

CISA orders federal agencies to patch five actively exploited vulnerabilities by April 3, including three Apple flaws linked to the DarkSword iOS exploit...

Dylan H.

News Desk

March 22, 2026
3 min read

Five Actively Exploited Flaws Added to CISA's Known Exploited Vulnerabilities Catalog

CISA added five security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on March 21, 2026, ordering federal agencies to apply patches by April 3, 2026. Three of the flaws are linked to a sophisticated iOS exploit kit codenamed DarkSword.


CVEProductCVSSType
CVE-2025-31277Apple WebKit8.8Memory corruption via web content
CVE-2025-43510Apple Kernel7.8Memory corruption (inter-process)
CVE-2025-43520Apple Kernel8.8Memory corruption (kernel write)
CVE-2025-32432Craft CMS10.0Code injection → RCE
CVE-2025-54068Laravel Livewire9.8Unauthenticated RCE

The DarkSword iOS Exploit Kit

Google Threat Intelligence Group (GTIG), iVerify, and Lookout documented an iOS exploit kit called DarkSword that chains the three Apple vulnerabilities together to deploy multiple malware families:

  • GHOSTBLADE — Primary implant for persistent device access
  • GHOSTKNIFE — Data exfiltration module targeting messaging apps
  • GHOSTSABER — Credential harvesting and keylogging component

The exploit chain requires only that a target visit a malicious webpage, making it a zero-click attack when combined with a phishing link delivered via SMS or messaging apps.

Craft CMS Zero-Day (CVE-2025-32432)

The Craft CMS vulnerability carries the maximum CVSS 10.0 score and has been exploited as a zero-day since February 2025. An intrusion set tracked as Mimo (aka Hezb) has been observed exploiting it to deploy cryptocurrency miners and residential proxyware on compromised servers.

Laravel Livewire RCE (CVE-2025-54068)

The Laravel Livewire flaw allows unauthenticated attackers to achieve remote command execution in specific configurations. With Laravel powering millions of web applications globally, the exposure surface is significant.


Impact AreaDescription
iOS DevicesZero-click exploitation via malicious web content
Web ServersRCE on Craft CMS and Laravel Livewire installations
Data TheftDarkSword deploys multiple espionage malware families
Crypto MiningMimo group leveraging Craft CMS for mining operations
Federal DeadlineAll agencies must patch by April 3, 2026

Recommendations

For iOS Users

  • Update to the latest iOS/iPadOS immediately
  • Enable Lockdown Mode if you are a high-risk target
  • Avoid clicking links from unknown sources

For Web Developers

  • Craft CMS: Update to version 4.14.16 or 5.6.18+ immediately
  • Laravel Livewire: Update to version 3.6.4+ or apply the security patch
  • Audit server logs for signs of exploitation

Key Takeaways

  1. DarkSword is a nation-state-grade iOS exploit kit chaining three vulnerabilities for zero-click compromise
  2. GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER form a complete espionage toolkit targeting messaging app data
  3. Craft CMS CVE-2025-32432 has been exploited for over a year with a perfect CVSS 10.0 score
  4. Laravel Livewire's unauthenticated RCE affects millions of web applications globally
  5. Federal agencies have until April 3 to remediate all five vulnerabilities

Sources

  • CISA Flags Apple, Craft CMS, Laravel Bugs in KEV — The Hacker News
  • CISA Known Exploited Vulnerabilities Catalog
  • U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws — SecurityAffairs
#CISA KEV#Apple#Zero-Day#Vulnerability#iOS

Related Articles

Apple Releases Critical Security Updates Across All

Apple has released security updates for iOS, macOS, watchOS, and tvOS addressing multiple actively exploited vulnerabilities. Users urged to update immediately.

3 min read

DarkSword GitHub Leak Threatens to Turn Elite iPhone Hacking Into a Tool for the Masses

Researchers say the GitHub leak of the DarkSword iOS exploit chain — six chained vulnerabilities targeting iOS 18.4 through 18.7 — threatens to...

5 min read

Interlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure

CVE-2026-20131, a maximum-severity CVSS 10.0 insecure deserialization flaw in Cisco Firepower Management Center, was exploited by Interlock ransomware as...

4 min read
Back to all News