Episode

Double-edged threat. [Research Saturday]

Podcast
CyberWire Daily
Published
May 2, 2026
Duration seconds
165
Processing state
processed
Canonical source
https://thecyberwire.com/podcasts/research-saturday/423/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW1180027346.mp3?updated=1777650720
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/double-edged-threat-research-saturday
Markdown
/podcast/cyberwire-daily-454880/double-edged-threat-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/double-edged-threat-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/double-edged-threat-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Justin Albrecht, Principal Researcher at Lookout, discussing "Attackers Wielding DarkSword Threaten iOS Users." DarkSword is a highly sophisticated iOS exploit chain discovered by Lookout that targets iPhones (iOS 18.4–18.6.2), enabling near zero-click compromise and rapid theft of sensitive data, including credentials and cryptocurrency wallet information. Likely deployed by a Russia-linked threat actor (UNC6353) against Ukrainian users, it uses watering hole attacks on compromised websites and operates in a “hit-and-run” fashion—exfiltrating data within minutes before wiping traces. The campaign highlights a growing secondary market for advanced exploits, allowing financially motivated groups to access powerful tools once reserved for state actors, significantly expanding the mobile threat landscape. The research and executive brief can be found here: ⁠Attackers Wielding DarkSword Threaten iOS Users Learn more about your ad choices. Visit megaphone.fm/adchoices