View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE

🚨 ACTIVE EXPLOITATION

  • Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
    A Chinese threat actor is exploiting the leaked DarkSword full-chain exploit kit to deploy GHOSTBLADE malware on Apple iOS devices running versions 18.4 through 18.7.
    • Targets Apple iOS devices versions 18.4 to 18.7
    • Uses leaked DarkSword kit to exploit patched iOS vulnerabilities
    • Delivers GHOSTBLADE malware that steals keychain, iCloud, and Wi-Fi credentials
    • Attack begins via fake AWS and Apple ID sign-in pages hosting malicious JavaScript iframes
    • Attacker operates over 100 domains and multiple admin panels across Hong Kong, Singapore, Japan, US, and Europe
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News

πŸ’₯ BREACHES & INCIDENTS

  • PNLD Breach Exposes UK Police and Government Contact Details on Dark Web
    The Police National Legal Database suffered a data breach exposing contact details of UK police forces, government partners, and criminal justice professionals on the dark web.

    • Exposed names, organizations, and work emails of police officers and staff
    • Included some Ask the Police users' names and emails, increasing phishing risks
    • Likely exploited Microsoft Power Platform misconfigurations allowing anonymous access to Dataverse tables
    • No evidence of password compromise, ransomware, malware, or software vulnerability exploitation
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Hackers breach Liechtenstein beneficial owners register, data of 31,000 entities stolen
    Hackers accessed and copied data from Liechtenstein's beneficial owners register, compromising information on about 31,000 companies, foundations, and trusts.

    • Data of approximately 31,000 legal entities compromised
    • Hackers illegally accessed and copied register information
      πŸ“Ž Coverage: reuters.com Β· πŸ‘ via @metacurity@infosec.exchange

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Security Flaw in DNA Analysis Tech Exposes 30 Years of Crime Lab Data
    A security weakness in forensic DNA analysis technology used by most U.S. crime labs exposes 30 years of crime lab DNA evidence files to potential hacking risks.

    • Discovered by forensic and computer scientists
    • No CVE identifiers assigned yet
      πŸ“Ž Coverage: infosec.exchange Β· πŸ‘ via @metacurity@infosec.exchange
  • Unit 42 Reveals Novel Malware Attacks Bypassing Google Passkey Authentication
    Malware can bypass Google passkey protections on Windows Chrome devices with TPM hardware to silently take over accounts without user interaction.

    • Exploits malware on compromised endpoints to misuse passkey onboarding, recovery, and trust workflows
    • Enables silent authentication, device unlock deception, and extraction of synced passkeys
    • Bypasses user verification flags, device unlock, biometrics, and privilege escalation
    • Accesses local Chrome sync data without elevated privileges
      πŸ“Ž Coverage: unit42.paloaltonetworks.com Β· πŸ‘ via Palo Alto Unit 42
  • ModernStealer Alias Linked to Dark Web Claims of Government and Defense Data Leaks
    ModernStealer alias is linked to dark web posts claiming government and defense data leaks, though no confirmed breaches or malware campaigns exist.

    • Targets military, government, nuclear, and aerospace sectors
    • Activity involves alleged data sales and recycled or exaggerated leak claims
    • Uses dark web forums and Telegram for data advertising
    • Shared Session IDs and Telegram contacts link multiple aliases including ModernStealer
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ”“ CVEs & KEV

  • CVE-2026-68742 β€” CVSS 5.5 β€” Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethost...
  • CVE-2026-0392 β€” CVSS β€” β€” eParakstΔ«tājs 3.0 for Windows – remote code execution via unauthenticated aut...
  • CVE-2026-69082 β€” CVSS β€” β€” Cross-Site Request Forgery in the Administrative User Deletion EndpointCTI-Tr...
  • CVE-2026-33591 β€” CVSS β€” β€” Authentication bypass on WaptServerA vulnerability in Wapt Server before vers...
  • CVE-2026-69079 β€” CVSS β€” β€” Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CT...
  • CVE-2026-69078 β€” CVSS β€” β€” Server-Side Request Forgery and Local File Disclosure in CTI-Transmute Evalua...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check