BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA Flags 5 Exploited Flaws in Apple, CMS

CISA mandates urgent patches for Apple, Laravel, and Craft CMS flaws exploited by state hackers and DarkSword iOS kit.

  • The U.S. CISA has added five actively exploited security flaws impacting Apple, Craft CMS, and Laravel Livewire to its catalog, requiring federal agencies to patch them by April 3, 2026.
  • A dangerous iOS exploit kit codenamed DarkSword leverages three of the Apple vulnerabilities to deploy malware families like GHOSTBLADE for data theft.
  • The Iranian state-sponsored hacking group MuddyWater (aka Boggy Serpens) is exploiting one of the Laravel flaws in attacks targeting diplomatic and critical infrastructure sectors.

On March 20, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urgently flagged five actively exploited vulnerabilities in its Known Exploited Vulnerabilities catalog. Federal agencies have been directed to patch the Apple, Craft CMS, and Laravel Livewire flaws by April 3 to mitigate significant risk, according to the agency. The vulnerabilities include critical CVE-2025-31277 in Apple WebKit and CVE-2025-54068, a code injection flaw in Laravel Livewire with a CVSS score of 9.8.

- Advertisement -

Reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout highlight an iOS exploit kit named DarkSword using several Apple bugs. This kit deploys malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER to steal user data. Meanwhile, the critical Craft CMS vulnerability CVE-2025-32432 was reportedly exploited as a zero-day since February 2025 and later used by the threat actor Mimo to deploy a cryptocurrency miner.

The Iranian state-sponsored group MuddyWater is actively exploiting the Laravel vulnerability CVE-2025-54068. Unit 42 from Palo Alto Networks recently published a detailed threat assessment of the group, noting its focus on diplomatic and critical infrastructure. “While social engineering remains its defining trait, the group is also increasing its technological capabilities,” Unit 42 analysts stated.

Attributed to the Iranian Ministry of Intelligence and Security (MOIS), MuddyWater employs sophisticated methods. The group uses a custom web-based platform to automate mass email delivery and has deployed malware like GhostBackDoor and Nuso in a campaign against a UAE energy company. Consequently, CISA’s warning underscores the need for immediate patching across all affected software platforms.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Virginia Enacts Law for Unclaimed Crypto

Virginia requires custodians to transfer unclaimed digital assets in-kind, retaining the original crypto instead...

GPT-5.4-Cyber Aids Security Defense

OpenAI has launched GPT-5.4-Cyber, a cybersecurity-specific variant of its flagship model, to accelerate defensive...

2027 Social Security COLA Holds at 2.8%, Matching 2026 Rate

The Senior Citizens League (TSCL) estimates the 2027 Social Security COLA at 2.8%, projecting...

Deutsche Börse Buys $200M Stake in Kraken

Deutsche Börse AG acquires a $200 million stake in Kraken's parent company, valuing the...

Ethereum Jumps 9%, Nears $2,400 as Crypto Market Rallies

Ethereum surged over 9% to nearly $2,400, its highest price in more than two...

Must Read

7 Best NFT Marketplaces for Every Need

Open Sea | Pianity | Foundation | Magic Eden | SuperRare | Rarible | Theta Drop | Other Platforms | About NFTs | FAQ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading