This day 02:06 06:06 10:06 14:07 18:07
⚠ exploit status: CVE-2026-18577 · KEV
High  2026-08-04 10:06Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-08-04 — Leaked iOS Exploit Kit Spreads, N-able KEV Confirmed

Executive summary. A leaked iPhone hacking framework (DarkSword) has now spread to 7–8 independent threat groups, amplifying the iOS attack surface. CISA formally added the N-able N-central auth-bypass flaw to its KEV catalog after confirmed customer compromises — patch immediately if you run N-central. Device-code phishing has surged 1,500% year-to-date, reinforcing that legacy MFA controls are increasingly bypassable via social engineering. Two novel attack vectors deserve attention: VLM-powered mobile agents expose new privilege-escalation paths, and empty cryptocurrency transactions can carry hidden C2 messaging invisible to transaction-monitoring tools.

Top items

Themes

Leaked offensive tools are proliferating faster than defensive response. DarkSword's spread to 7–8 groups within days of its GitHub leak mirrors the broader pattern of offensive-framework democratisation — from Cobalt Strike cracks to mobile-agent attack research. The window between a tool leaking and widespread abuse is compressing.

Authentication assumptions keep failing. N-able's alternate-channel auth bypass, device-code phishing's 1,500% surge, and the mobile-agent privilege model all share a root cause: systems trust a secondary authentication path that attackers can reach without triggering the primary control. Audit your alternate-channel and device-flow auth surfaces.

===

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb