Operations & Intelligence Failures — 2026-03-23

CISA Orders Federal Agencies to Patch DarkSword iOS Exploit Chain Linked to Turkish and Russian State Actors

CISA added three DarkSword iOS vulnerabilities (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) to its Known Exploited Vulnerabilities catalog under BOD 22-01, ordering federal agencies to patch within two weeks by April 3. The DarkSword exploit chain enables sandbox escape, privilege escalation, and remote code execution on iPhones running iOS 18.4-18.7, deploying three information-stealing malware families: GhostBlade, GhostKnife, and GhostSaber. The CSA Research Alliance linked DarkSword to UNC6748, a customer of Turkish commercial surveillance vendor PARS Defense, and suspected Russian espionage group UNC6353, making the chain a multi-state-actor intelligence collection tool. The public leak of the complete exploit kit means any capable adversary now has weaponized iOS zero-days affecting federal government devices.

Analysis
The prior IC brief tracked the CanisterWorm wiper targeting Iranian systems and the FBI Handala FLASH alert as the two primary cyber operations threads. DarkSword adds a third vector: state-sponsored mobile exploitation now available as a commodity. At 38% staffing, CISA may lack capacity to enforce its own BOD compliance deadline while simultaneously managing Iran-war-related cyber threats.
1 sources
  1. CISA Orders Federal Agencies to Patch Critical iOS Flaws Exploited by Attackers - News4Hackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE