Apple warns iPhone users of data theft: Act immediately

Apple Issues Emergency iOS Update to Protect Against Cyber Threats
Apple has rolled out an emergency software update, urging millions of iPhone users to download it immediately. The company has expanded the availability of its iOS 18.7.7 and iPadOS 18.7.7 updates to a broader range of devices, warning that the software includes critical protections against a cyberattack method known as DarkSword.
The update is designed to safeguard users from web-based attacks that exploit vulnerabilities in Apple devices. This comes as security experts have identified a growing threat from the DarkSword exploit kit, which was first discovered in 2025. The toolkit is specifically crafted to target vulnerable Apple devices and secretly install malicious software.
Understanding the DarkSword Threat
DarkSword operates through a technique called a “watering hole attack,” where users are tricked into visiting legitimate websites that have been infected with malicious code. Once a user lands on such a site, the malware can be activated, allowing hackers to install hidden backdoors. These backdoors provide long-term access to a device, enabling the theft of sensitive information.
Experts warn that a newer version of the hacking tool has recently surfaced online, raising concerns that more cybercriminal groups could begin using it in larger-scale attacks. This development underscores the importance of staying vigilant and keeping devices updated.
Recommendations for High-Risk Users
Users who believe they may be targeted by these attacks—especially journalists, activists, or individuals handling sensitive information—are advised to enable Apple’s Lockdown Mode. To do this, go to Settings, select Privacy & Security, tap Lockdown Mode, and follow the prompts to turn it on and restart the device.
Global Impact of DarkSword
Cybersecurity firms, including Google’s Threat Intelligence Group and Lookout, have reported that the DarkSword toolkit has been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine since July 2025. The malware exploits several hidden weaknesses in iPhones and the Safari browser, allowing attackers to secretly install malware on a device.
In some cases, attackers have created fake websites or apps to deceive users, such as lookalike versions of popular services like Snapchat. In other instances, they have hacked legitimate websites, including government sites. Once a phone is infected, hackers can install different types of spyware depending on their objectives.
One variant, called ‘Ghostblade,’ is designed to steal large amounts of personal information. This includes text messages, call history, contacts, photos, emails, passwords, location data, browsing history, and even files stored in iCloud. It can also access messages from apps like WhatsApp and Telegram.

Financial and Digital Asset Risks
The malware also searches for cryptocurrency apps and wallets, making it possible for hackers to steal digital assets or sensitive financial data. This highlights the need for users to be cautious about the websites they visit and the apps they download.
Apple initially released the iOS 18.7.7 update on March 24, 2026, but at the time, it was limited to a small number of older devices. The company has now expanded the update to cover a much wider range of iPhones and iPads, including devices capable of upgrading to newer operating systems but still running older versions.
Apple’s Response and User Actions
In a statement shared with WIRED, an Apple spokesperson said the company made the unusual move to expand the update to protect users who have not yet upgraded to the latest software. Users without automatic updates enabled can manually install the patch by updating their device to the latest secure version of iOS 18 or upgrading to iOS 26.
Cybersecurity researchers say the threat highlights growing concerns that sophisticated spyware targeting iPhones is becoming more common. Rocky Cole, co-founder of cybersecurity firm iVerify, noted that “DarkSword silently steals vast amounts of user data simply because the user visited a real, but compromised, website.”
Apple has also begun sending lock screen warnings to some users running outdated software, urging them to install updates immediately. Experts warn that failing to install the patch could leave devices vulnerable to data theft and long-term surveillance.























