Breaking news

DarkSword Redux: New iOS Exploit Kit Amplifies Legacy Device Vulnerabilities

Recent developments in cybersecurity have revealed a concerning evolution of the DarkSword exploit. Following the exposure of a sophisticated hacking campaign targeting iPhone users, cybersecurity professionals now report that a revised version of DarkSword has been released on GitHub, significantly lowering the barrier for malicious actors to compromise iOS devices running outdated operating systems.

New Version, Increased Risks

Researchers, including iVerify co-founder Matthias Frielingsdorf, warn that the leaked tools can be quickly adapted and reused. The latest version, built largely with HTML and JavaScript, allows attackers to target older iPhones without requiring deep knowledge of iOS systems. This increases exposure for devices that have not been updated, with a significant number of users still running earlier versions of the operating system.

Ecosystem Vulnerabilities And Expert Warnings

Security experts continue to stress that software updates remain the primary line of defense. Apple has issued an emergency patch for devices unable to upgrade to newer iOS versions, noting that the exploit affects only systems running outdated software. Keeping devices updated significantly reduces the risk of exploitation.

Legacy Exploit Mechanisms And Operational Impact

The leaked DarkSword code includes detailed inline comments explaining how the exploit operates. These outline steps, such as extracting data through HTTP requests and transferring information to external servers after access is gained. Sensitive data that can be targeted includes contacts, messages, call history and keychain information. The level of detail in the code also makes it easier for less experienced attackers to reuse and adapt the exploit. References within the code suggest links to additional targets, indicating that the activity may be part of a broader campaign.

Comparative Landscape And Broader Implications

This significant update to DarkSword comes on the heels of another advanced iPhone hacking toolkit, Coruna, which was traced to tools developed by defense contractor L3Harris. The convergence of these sophisticated exploits underscores an escalating threat landscape where state-of-the-art tools leak into the cybercriminal ecosystem, magnifying risks for legacy devices. With Apple reporting that approximately one-quarter of all active iPhone and iPad devices run on older operating systems, the potential impact is vast.

Conclusion and Recommendations for Users

The emergence of a simplified version of DarkSword highlights how quickly advanced exploits can spread once made public. As accessibility increases, the gap between highly specialized tools and general use continues to narrow, raising the importance of timely updates and ongoing security awareness.

Meta’s $18 Billion Settlement Limits State Claims Over Children’s Data

Meta’s $18 billion settlement with attorneys general from 29 U.S. states includes a provision limiting future state claims over the company’s use of children’s data for age-assurance systems.

Under the agreement, Meta must develop, train and begin testing a system to identify users under 13 within a year of the settlement taking effect. The company already uses AI-based age-detection tools, although the agreement does not require the new system to use AI.

States Agree To Limits On Future Claims

The Children’s Online Privacy Protection Act (COPPA) generally restricts the collection and retention of personal data from children under 13. Under the settlement, the 29 state attorneys general agreed not to bring past, present or future claims under COPPA or similar state laws over the specified use of children’s data.

Meta will not be permitted to use information from users under 13 for advertising, marketing or algorithmic optimisation.

Federal Enforcement Remains Unclear

COPPA is primarily enforced by the Federal Trade Commission, which is not a party to the agreement. That leaves open the possibility of separate federal action over how Meta collects or uses children’s data.

Another issue is whether Meta can keep age-assurance data isolated from its other systems. An independent auditor will monitor compliance, but the settlement does not fully specify what data Meta can retain for training, how long it can be stored or whether derived insights can be used elsewhere.

Legal Risks Remain

Joshua Wurtzel, a partner at Schlam Stone & Dolan, said states could still pursue claims if Meta uses the data outside the settlement’s limits. Such cases could depend on how those limits are interpreted.

Peter Jackson, a data and intellectual property attorney at Greenberg Glusker, said the provision could “disincentivize future enforcement actions.”

The agreement gives Meta greater legal certainty around using children’s data for age assurance, but questions remain over federal enforcement, data retention and secondary use.

Uol
Aretilaw firm
The Future Forbes Realty Global Properties
eCredo

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter