/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A GitHub user published a newer version of iPhone exploit kit DarkSword; iVerify co-founder Matthias Frielingsdorf says the exploits “will work out of the box”

Lorenzo Franceschi-Bicchierai Zack Whittaker  —  Last week, cybersecurity researchers uncovered …

TechCrunch

Context & Ripple Effects

DarkSword was identified days earlier by Google, iVerify and Lookout as a tool used to target iOS 18 through Ukrainian websites. The publication of a newer build turns that previously investigated iOS-targeting tool into a more immediate defensive concern because its availability is no longer confined to the operators researchers tracked.

The report also fits a longer iOS security pattern: researchers have previously disclosed iOS flaws exploited in the wild before fixes were available. What is distinctive here is the claimed ease of use of a named exploit kit, rather than the discovery of a vulnerability alone.

First-order effects

  • People who obtain the published DarkSword build can assess and potentially use the kit without reproducing the original research; iVerify's “out of the box” assessment makes its practical usability the immediate question.
  • Organizations responsible for potentially affected iPhones must treat DarkSword as an available toolset, not only as a threat-research finding.

Second-order effects

  • Apple and mobile-security providers face pressure to validate exposure, prioritize detections and accelerate mitigations for the iOS 18 targeting technique associated with DarkSword.
  • GitHub becomes part of the incident-response surface: hosting and redistribution can determine how quickly a leaked exploit kit reaches additional actors, even if the original post is removed.

Third-order effects

  • If the kit proves broadly usable, iPhone compromise capability can move from specialized operators toward reusable tooling, shortening the gap between exploit disclosure and defensive action.
  • The episode reinforces the value of maintaining security support for older platform releases; the later backported patches for iOS 18 show how exploit availability can force protection beyond the newest software version.

The trend: This is one data point in the commoditization of mobile exploitation, where leaked operational tooling can turn targeted techniques into a wider patching and detection problem.

Discussion

  • @matteyeux @matteyeux on x
    Got kernel R/W on an iPad mini 6th gen running iOS 18.6.2 using the in the wild exploit chain darksword [image]
  • @zeroxjf Johnny on x
    Update: he's now got the exploit fully working on A15 15.1.1, says offsets hardcoded for that config/you need to supply your own for others.
  • @matteyeux @matteyeux on x
    @John011235 Real iPad
  • @zeroxjf Johnny on x
    Looks like opa334 has extracted the kernel exploit https://github.com/...
  • @zeroxjf Johnny on x
    DarkSword payloads have surfaced and appear to be a full iOS 18.4 staged chain with WebContent RCE, SB escape, a kernel PE/KRW bundle, and post-exploit logic for task ops, process injection, and data collection. Not going to publicly link the payloads. Legit researchers can DM me
  • @amfi_d @amfi_d on x
    I'm reverse-engineering DarkSword and found that it supports 26 iPhone models with only 34,000 offsets. That's crazy.
  • @mastermike88 Michael on x
    For the first time in over two years, there is set to be a new kernel exploit for up to iOS/iPadOS 18.7.1 and 26.0.1 - including the latest EoL versions for 15.x (presumed)/16.x/17.x. [Note: Just like the Coruna kit chain a few weeks ago, stuff here is subject to
  • @kevincollier Kevin Collier on bluesky
    You really gotta watch this space.  I might be wrong, but feels like we're watching a wave starting to crest.  Could see mass takeover of old/unpatched iPhones in a way we've never seen before.  [embedded post]
  • @evacide @evacide on bluesky
    If you have an iPhone, today is a good day to make sure you are running the latest software. techcrunch.com/2026/03/23/s...
  • @yuda.org John Yuda on bluesky
    Seems like apple will go to great lengths to get people to adopt Liquid Glass [embedded post]
  • @symbo1ics @symbo1ics on bluesky
    Meanwhile we're locked into the worst of all worlds:  —  Devices that are locked down into a constant drag of forced obsolescence  —  AND  —  vulnerabilities.  —  So Apple, with essentially infinite resources, is the most erratic and unhelpful steward of technology we depend on. …
  • @lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
    SCOOP: Someone has found new samples of the iPhone spyware DarkSword and published them on GitHub, putting millions of iOS users at risk.  —  A cybersecurity researcher told us that the leaked spyware is “way too easy to repurpose” and “we need to expect criminals and others to s…
  • @zackwhittaker.com Zack Whittaker on bluesky
    NEW: Someone has publicly leaked an exploit toolkit called DarkSword, which allows any hacker or cybercriminal to easily hack iPhones and iPads running iOS 18.  —  Apple said it is aware & has issued patches.  Security researchers have already tested the code as working.  —  w/ @…
  • r/technology r on reddit
    Someone has publicly leaked an exploit kit that can hack millions of iPhones
  • r/technews r on reddit
    Someone has publicly leaked an exploit kit that can hack millions of iPhones
  • r/pwnhub r on reddit
    Someone has publicly leaked an exploit kit that can hack millions of iPhones