Safari — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
87
occurrences
First Seen
November 4, 2025
Last Seen
September 4, 2026

Related Threat Clusters

  • CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers

    CVE-2026-2441 is a zero-day CSS vulnerability affecting all Chromium-based browsers, allowing attackers to exploit a use-after-free condition in the Blink rendering engine. This vulnerability enables the theft of…

    3 articles · Updated February 21, 2026
  • New WebKit Zero-Day CVE-2025-14174 Discovered and Exploited

    A new zero-day vulnerability in Apple's WebKit, identified as CVE-2025-14174, has been confirmed and is actively being exploited. This follows the recent disclosure of another critical zero-day vulnerability in…

    1 article · Updated December 16, 2025
  • Google and Apple Issue Security Updates for Zero-Day Vulnerabilities

    Google and Apple released urgent security updates to address zero-day vulnerabilities affecting their platforms. The vulnerabilities were exploited in a sophisticated attack targeting specific users, with one bug…

    8 articles · Updated December 12, 2025
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • 'DarkSword' Attack Targets iPhones via Phishing Emails

    The 'DarkSword' attack is now exploiting unpatched iPhones through phishing emails, as reported by Proofpoint. These emails contain links to malicious sites that host DarkSword, targeting iPhones running iOS versions…

    2 articles · Updated March 30, 2026
  • Coruna and DarkSword iOS Exploit Kits Targeting Users Globally

    The Coruna and DarkSword iOS exploit kits, initially limited to nation-state actors, are now being widely adopted by organized cybercriminals. iVerify has tracked around 17,000 domains associated with second-generation…

    3 articles · Updated August 10, 2026
  • CISA Urges Rapid Fix for Critical Ray RCE Vulnerability

    CISA has added CVE-2025-62593, a critical remote code execution vulnerability in the Ray framework, to its Known Exploited Vulnerabilities catalog. This flaw, first disclosed in November 2025, allows attackers to…

    8 articles · Updated August 18, 2026
  • Malicious Packagist Themes Exploit iPhones for Spyware and Crypto Theft

    Thirteen malicious Composer theme packages on Packagist have been identified, targeting unpatched iPhones by injecting JavaScript into Vietnamese movie and comic streaming sites. The injected code facilitates mobile ad…

    8 articles · Updated September 1, 2026
  • New macOS Gaslight Malware Targets AI Analysis Tools

    A new macOS malware named 'Gaslight' has been identified, attributed to North Korean threat actors. This malware employs prompt injection techniques to confuse AI-assisted malware analysis tools, embedding 38 fake…

    13 articles · Updated June 25, 2026
  • CERT-In Issues High-Severity Alert for Apple Device Vulnerabilities

    On March 26, 2026, India's CERT-In issued a high-severity alert regarding multiple vulnerabilities in Apple devices, including iPhones, iPads, Macs, and Apple Watches. These vulnerabilities could allow attackers to…

    2 articles · Updated March 30, 2026

Recent Intelligence Reports

  • MITRE ATT&CK technique T1566.003 — attack.mitre.org · September 4, 2026
  • Malwarebytes Browser Guard — edge.prnewswire.com · September 3, 2026
  • 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds — Thehackernews · September 1, 2026
  • AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones — Theregister · August 24, 2026
  • CISA gives feds 3 days to fix actively exploited Ray RCE bug — Theregister · August 18, 2026
  • Phishing Protection | The Complete Guide (2026) — Dexpose · August 13, 2026
  • Coruna Inside The Nation State Grade Ios Exploit Kit We Ve Been Tracking — iverify.io · August 11, 2026
  • How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore — Bleepingcomputer · August 6, 2026

CVSS v3.1 Breakdown