INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Apple, Laravel, Craft CMS Exploit Vulnerabilities Catalog

| 2026-03-22 14:40 CRITICAL HIGH
Executive Summary AI-generated
The threat actor behind the recent attacks is Iran-nexus APT MuddyWater, a known group for targeting diplomatic and critical sectors. The campaign began in February 2017 but gained momentum between October of that year and January 2022 when US Cyber Command linked it to Iran's Ministry of Intelligence and Security. The attackers primarily target telecommunications, government IT services, and oil sectors. Vulnerabilities added to the catalog include CVE-2025-31277 (CVSS score of 8.8) in Craft CMS and Apple Multiple Products Buffer Overflow Vulnerability CVE-2025-32432 (CVSS score of 10.0), as well as Improper Locking Vulnerability CVE-2025-43520 (CVSS score of 8.8). These vulnerabilities were identified by Google Threat Intelligence Group, iVerify, and Lookout. The CISA catalog also includes a code injection issue tracked as CVE-2025-32432.
Technical Mitigations AI-generated
* Implement secure coding practices, such as input validation and sanitization, to prevent code injection vulnerabilities like CVE-2025-32432 (Craft CMS) and CVE-2024-58136 (Yii framework). * Regularly update software applications and frameworks to ensure that known exploits are patched before they can be used against systems. * Use secure protocols for communication, such as HTTPS, and limit the use of outdated or vulnerable libraries and frameworks in development projects. * Conduct regular security audits and penetration testing to identify vulnerabilities and weaknesses in systems and infrastructure.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
MuddyWaterMuddyWater CVE-2025-43510CVE-2025-43510 CVE-2025-32432CVE-2025-32432 CVE-2024-58136CVE-2024-58136 CVE-2025-31277CVE-2025-31277 CVE-2025-54068CVE-2025-54068 CVE-2025-43520CVE-2025-43520
Target & Sectors
GCC GCC MIDDLE_EAST MIDDLE_EAST SOUTH_ASIA SOUTH_ASIA maritimemaritime technologytechnology energyenergy governmentgovernment telecommunicationstelecommunications financefinance
Incident Timeline
late 2017
Threat actors used a previously unknown exploit in Apple's iOS operating system to target devices in the Middle East.
target_region MIDDLE_EAST
threat_actor MuddyWater
organisation APT
January 2022
Threat actors used a known exploited vulnerability in Apple, Laravel Livewire and Craft CMS to target the MuddyWater APT group.
threat_actor MuddyWater
source_region United States
target_region Iran, Islamic Republic of
attribution US Cyber Command
attribution USCYBERCOM
attribution Ministry of Intelligence and Security
February 2025
Threat actors exploited CVE-2025-32432 as a zero-day vulnerability in February 2025.
vulnerability CVE-2025-32432
organisation Orange Cyberdefense SensePost
April 2025
Threat actors exploited CVE-2025-32432 in Craft CMS to breach servers and upload a PHP file manager.
organisation CVE-2025-54068
infrastructure 9.8
general_metric 9.8 score
organisation Craft CMS
organisation Orange Cyberdefense’s
threat_actor MuddyWater
organisation CVE-2025-32432
organisation CVE-2024-58136
infrastructure 3.9.15
infrastructure 4.14.15
infrastructure 5.6.17
infrastructure 2.0.52
organisation Yii 2.0.52
organisation SensePost
organisation PHP
July 2025
Threat actors exploited vulnerabilities in Apple, Laravel Livewire and Craft CMS to gain unauthorized access.
organisation CVE-2025-43510
infrastructure 7.8
general_metric 7.8 score
between August 16, 2025
Threat actors used a sustained campaign to target an unnamed national marine and energy company in the U.A.E. between August 16, 2025, and February 11, 2026, deploying various malware families including GhostBackDoor and Nuso through HTTP_VIP vulnerabilities.
industry Energy
organisation Nuso
August 16, 2025
Threat actors exploited vulnerabilities in Apple, Laravel Livewire and Craft CMS to gain unauthorized access.
December 2025
Threat actors used a known exploited vulnerability in Apple's iOS and iPadOS operating systems to target devices running the Craft CMS web application.
general_metric 8.8 vulnerabilities
organisation CVE-2025-43520
infrastructure 8.8
organisation CVE-2025-32432
infrastructure 10.0
February 11, 2026
Threat actors used a sustained campaign to target an unnamed national marine and energy company in the U.A.E. between August 16, 2025, and February 11, 2026, deploying various malware families including GhostBackDoor and Nuso.
industry Energy
organisation Nuso
Mar 21, 2026
Threat actors exploited known vulnerabilities in Apple, Laravel Livewire and Craft CMS to gain unauthorized access.
between February and October 2017
Threat actors used a combination of vulnerabilities in Apple, Laravel Livewire and Craft CMS to target entities across multiple countries.
threat_actor MuddyWater
target_region Saudi Arabia
target_region Iraq
target_region Israel
target_region United Arab Emirates
target_region Georgia
target_region India
target_region Pakistan
source_region United States
2026-03-22
U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog.
organisation Palo Alto Networks Unit
threat_actor MuddyWater
organisation CVE-2025
organisation CVSS
infrastructure Ios
organisation Apple
organisation Craft CMS
organisation UDPGangster
organisation Rust
April 3, 2026
Threat actors used a known exploit to target Apple, Craft CMS, and Laravel Livewire vulnerabilities.
attribution KEV
attribution Orders Patching
attribution Vulnerability / Threat Intelligence
attribution Apple
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
general_metric 21  Mar
Tactical Metrics
Metrics
infrastructure
​7.8
Software Version
Metrics
infrastructure
​8.8
Software Version
Metrics
infrastructure
​10.0
Software Version
Metrics
infrastructure
​9.8
Software Version
Metrics
infrastructure
​Ios
Affected Product
Metrics
infrastructure
​3.9.15
Software Version
Metrics
infrastructure
​4.14.15
Software Version
Metrics
infrastructure
​5.6.17
Software Version
Metrics
infrastructure
​2.0.52
Software Version