CISA Orders Federal Agencies to Patch DarkSword iOS Exploit Chain Linked to Turkish and Russian State Actors
CISA added three DarkSword iOS vulnerabilities (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) to its Known Exploited Vulnerabilities catalog under BOD 22-01, ordering federal agencies to patch within two weeks by April 3. The DarkSword exploit chain enables sandbox escape, privilege escalation, and remote code execution on iPhones running iOS 18.4-18.7, deploying three information-stealing malware families: GhostBlade, GhostKnife, and GhostSaber. The CSA Research Alliance linked DarkSword to UNC6748, a customer of Turkish commercial surveillance vendor
The prior IC brief tracked the CanisterWorm wiper targeting Iranian systems and the FBI Handala FLASH alert as the two primary cyber operations threads. DarkSword adds a third vector: state-sponsored mobile exploitation now available as a commodity. At 38% staffing, CISA may lack capacity to enforce its own BOD compliance deadline while simultaneously managing Iran-war-related cyber threats.