New DarkSword tool targets hundreds of millions of iPhones

A hacking technique called DarkSword, used by Russian hackers, can compromise iPhones running iOS 18 simply by visiting infected websites. Discovered in the wild, this tool has been deployed in espionage and cybercriminal campaigns to target thousands of devices indiscriminately. It is now available online in a reusable form, risking a large portion of iPhone users worldwide.

iPhone hacking techniques were once rare, likened to elusive animals used stealthily against select targets. Recent developments show a shift, with espionage and cybercriminal groups embedding phone-takeover tools in websites to hack thousands of devices broadly. Among these is DarkSword, a powerful method spotted in active use by Russian hackers. This technique can seize control of devices on iOS 18 with just a visit to a malicious site, affecting hundreds of millions of iPhones. The tool has surfaced on the web in an easily adaptable format, heightening risks for many users. Previously selective hacks are now scaling up, as noted in cybersecurity observations.

Makala yanayohusiana

IT expert Supangat warns of Lebaran digital scams via WhatsApp and SMS in a press conference illustration.
Picha iliyoundwa na AI

IT expert warns of digital scams ahead of Lebaran

Imeripotiwa na AI Picha iliyoundwa na AI

Ahead of Idul Fitri, IT expert from Untag Surabaya, Supangat, urges the public to heighten vigilance against scams via WhatsApp and SMS. Rising digital transactions are exploited by cybercriminals. Vida founder Niki Santo Luhur identifies two main methods: phishing and malware prevalent in Indonesia.

Apple released an update to iOS 18.7.7 on April 1, 2026, making it available for more devices to protect against the DarkSword hacking toolkit. The company extended support to older iPhones, such as the iPhone 16e, without requiring an upgrade to iOS 26. DarkSword primarily targets users outside the US.

Imeripotiwa na AI

Kenyan entrepreneur Khalif Kairo has warned iPhone users who have lost their devices to beware of scammers using fake websites mimicking Apple. Fraudsters send SMS messages appearing to come from Apple Support, claiming the phone is in lost mode at a new location with a link. Kairo advised against entering Apple ID details on such links.

Journalists reported mysterious phishing attempts by unknowns a few weeks ago. The Dutch secret service now holds Russia responsible for attacks on the messaging apps WhatsApp and Signal. The report explains how the attacks work and how users can protect themselves.

Imeripotiwa na AI

A deceptive tech support scam has tricked employees into compromising their company computers. Posing as IT help, scammers guide victims through steps that install Havoc malware. The attack begins with spam emails and escalates via fake phone calls.

The CypherLoc scam is deceiving millions of users through fake browser lock screens. It spreads via phishing emails and hidden web traps that turn ordinary pages into alarming displays.

Imeripotiwa na AI

Developer platform Socket has identified a malware known as TrapDoor that is targeting crypto and AI developers.

Jumatano, 20. Mwezi wa tano 2026, 21:38:37

Google publishes exploit code for unfixed chromium vulnerability

Ijumaa, 15. Mwezi wa tano 2026, 14:22:42

Security researchers breach macOS using Anthropic AI tool

Jumanne, 12. Mwezi wa tano 2026, 07:58:04

Scammers expand Claude malware campaign to target Mac users via ads and fake support sites

Jumapili, 10. Mwezi wa tano 2026, 09:57:29

Smartphone users ignore security risks amid free tool reliance

Ijumaa, 8. Mwezi wa tano 2026, 19:49:13

Hackers create fake Claude site to spread malware

Jumatano, 18. Mwezi wa tatu 2026, 22:39:21

Apple releases first iOS 26.3.1 (a) background security improvement

Jumatano, 18. Mwezi wa tatu 2026, 03:20:19

Infostealers Disguised as Claude Code, OpenClaw, and Other AI Tools

Alhamisi, 12. Mwezi wa tatu 2026, 10:26:29

Iran-linked hackers disrupt Stryker's network in apparent retaliation

Jumatatu, 2. Mwezi wa tatu 2026, 12:30:13

Hackers hijack .arpa domain for phishing scams

Alhamisi, 26. Mwezi wa pili 2026, 18:05:06

New AirSnitch attack bypasses Wi-Fi client isolation

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa