Federal News
CISA Orders Federal Agencies to Patch iOS Flaws
March 23, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a binding directive requiring all federal civilian agencies to patch three actively exploited iOS vulnerabilities associated with the DarkSword exploit kit by April 3, 2026. These vulnerabilities enable sophisticated espionage and financial theft operations targeting iPhones, with multiple commercial surveillance vendors and suspected state-backed actors involved. This mandate highlights the critical need for rapid mobile device security updates and enhanced threat visibility within federal IT environments.
- Federal agencies must prioritize patch deployment for iOS devices to meet the April 3, 2026 deadline, ensuring compliance with CISA's directive.
- Procurement professionals should anticipate increased demand for mobile security solutions, vulnerability management tools, and threat intelligence services tailored to iOS platforms.
- Contractors specializing in cybersecurity, especially those with expertise in mobile device protection and incident response, may find new opportunities supporting federal compliance efforts.
- This directive underscores the growing importance of securing mobile endpoints against advanced persistent threats, influencing future federal cybersecurity procurement strategies.
DarkSword has been observed since at least November 2025 in the hands of multiple commercial surveillance vendors and suspected state-backed actors.
— Google Threat Intelligence Group
The phone in your pocket may have become a far more exposed instrument than its owner imagines.
— iVerify
Agencies
Cybersecurity and Infrastructure Security Agency
Vendors
Google, iVerify, Lookout, PARS Defense