Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The Google Threat Intelligence Group has identified DarkSword, a full-chain iOS exploit affecting versions 18.4 to 18.7. This exploit leverages multiple zero-day vulnerabilities, including CVE-2025-31277 and CVE-2025-14174, to compromise devices and deploy malware families like GHOSTBLADE. DarkSword...
Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts...
The Coruna and DarkSword iOS exploit kits, initially limited to nation-state actors, are now being widely adopted by organized cybercriminals. iVerify has tracked around 17,000 domains associated with second-generation variants of these exploit chains. The exploits target iPhones running iOS version...
A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a maximum severity rating due to hardcoded credentials, allowing unauthorized access t...