This day 02:06 06:06 10:06 14:07 18:07
⚠ exploit status: CVE-2026-18577 · KEV
High  2026-08-04 10:06Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-08-04 — Leaked iOS Exploit Kit Spreads, N-able KEV Confirmed

Executive summary. A leaked iPhone hacking framework (DarkSword) has now spread to 7–8 independent threat groups, amplifying the iOS attack surface. CISA formally added the N-able N-central auth-bypass flaw to its KEV catalog after confirmed customer compromises — patch immediately if you run N-central. Device-code phishing has surged 1,500% year-to-date, reinforcing that legacy MFA controls are increasingly bypassable via social engineering. Two novel attack vectors deserve attention: VLM-powered mobile agents expose new privilege-escalation paths, and empty cryptocurrency transactions can carry hidden C2 messaging invisible to transaction-monitoring tools.

Top items

Themes

Leaked offensive tools are proliferating faster than defensive response. DarkSword's spread to 7–8 groups within days of its GitHub leak mirrors the broader pattern of offensive-framework democratisation — from Cobalt Strike cracks to mobile-agent attack research. The window between a tool leaking and widespread abuse is compressing.

Authentication assumptions keep failing. N-able's alternate-channel auth bypass, device-code phishing's 1,500% surge, and the mobile-agent privilege model all share a root cause: systems trust a secondary authentication path that attackers can reach without triggering the primary control. Audit your alternate-channel and device-flow auth surfaces.

===

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db