ME News update, September 22 (UTC+8): The Chief Information Security Officer of blockchain security firm SlowMist, 23pds, said attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms via Safari, take control of devices, and extract private keys and other data from self-custody encrypted wallets. The vulnerability has previously been used to carry out attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. The Google Threat Intelligence Group previously disclosed that Darksword originally affected only iOS 18.4 through 18.7. 23pds said the attackers have adapted it for iOS 26.5, but this assessment has not yet been officially verified. Attacks typically begin with social engineering: after users click malicious links sent via social media or communication apps, the device may be obtained with Root privileges and wallet data may be extracted. Users should promptly update their phone systems and avoid clicking links from websites sent by strangers. In addition, three investors have filed a lawsuit against Apple after losing nearly $1.8 million in Bitcoin by downloading a fake wallet app from Apple's official App Store. (Source: ME)