// 1 CRITICAL · 4 ZERO-DAY · 7 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime Conference 2026, dismantling the notion of national control over digital surveillance. Italy paid Paragon Solutions to spy, but the contract denied it full control of logs and left the door open: the same license authorizing AISE and AISI to intercept does not prevent Paragon from selling the same capability to foreign intelligence agencies to target Italian users. The result is a nation simultaneously a client and a potential target of the same vendor.

On July 18, 2026, at the Cyber Crime Conference 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case that dismantles the idea of national control over digital surveillance. Italy paid Paragon Solutions to spy, but the contract denied it full control of the logs and left the door open: the same license authorizing AISE and AISI to intercept does not bar Paragon from selling the same capability to foreign intelligence agencies to target Italian users. The result is a nation simultaneously a client and a potential target of the same vendor.

Key Takeaways
  • AISE signed a contract with Paragon on December 13, 2023; iOS activation on January 23, 2024 and Android on February 8, 2024
  • The technical vector is CVE-2025-27363, a zero-click exploit via PDF preview in WhatsApp group chats, discovered on December 11, 2024 and patched six days later
  • Five publicly known Italian targets: Francesco Cancellato, Luca Casarini, Giuseppe Caccia, don Mattia Ferrari, and David Yambio; for the first three, no evidence of interception by Italian intelligence services
  • The Italian license excludes microphone, camera, and photo gallery access, but allows Paragon to sell the capability to target Italian numbers to third parties

The December 2023 Contract and the Spyware Architecture

AISE signed the agreement with Paragon Solutions on December 13, 2023. Activation occurred in two phases: iOS systems went live on January 23, 2024, Android systems on February 8, 2024. AISI used Graphite under a contract expiring November 7, 2025, structuring operations on two tracks: dynamic interception, authorized by the Rome Prosecutor General, and extraction of resident chats, governed by Article 18, paragraph 2, of Law 124/2007.

The Italian license imposes precise limits. It does not permit remote activation of microphone and camera, excludes real-time environmental surveillance, and blocks access to the photo gallery. What it authorizes is the interception of encrypted communications, under the regulatory framework of Decree-Law 144/2005, and the extraction of conversations archived on the device. However, the same license that binds Italy does not bind Paragon: the list of countries excluded from targeting does not include Italy. Paragon can sell the same platform to foreign intelligence agencies to target Italian users without violating the contract with AISE.

Graphite operates with a technical separation between exfiltrated data and traceability. The malware channels information to a command-and-control server hosted by the client, requires operator authentication for every action, and logs operations on two levels: a database erasable by the client and an immutable audit log accessible to Paragon. This architecture raises a question the dossier leaves unanswered: who truly holds the proof of use.

CVE-2025-27363: Six Days Between Discovery and Patch

The infection vector is identified with precision. CVE-2025-27363, with a CVSS score of 8.1 HIGH per the NVD record, exploits the preview of a malicious PDF inserted into a WhatsApp group chat. The exploit is zero-click: it requires no user interaction, no file opening, and no explicit download. Meta discovered the vulnerability on December 11, 2024 and completed the patch on December 17, 2024, a six-day interval that leaves a notable window for deployment.

On January 31, 2025, Meta and WhatsApp notified approximately 90 users in over 20 countries of confirmed compromise. Among the publicly confirmed Italian targets are Francesco Cancellato, director of Fanpage.it; activist Luca Casarini; Giuseppe Caccia; don Mattia Ferrari of the NGO Mediterranea Saving Humans; and David Yambio of Refugees in Libya. For Yambio, the notification did not come from Meta: on November 13, 2024, Apple had already alerted him to a "mercenary spyware" attack, with a message stating: "likely because of who you are or what you do."

The COPASIR Conclusions and the Judicial Gap

The Parliamentary Committee for the Control of Intelligence and Security Services and State Secrets conducted intensive activity: eight hearings, ten internal sessions, and four site visits between January 4 and June 4, 2025. The report approved on June 4, 2025 documents that AISI employed Graphite on Casarini and Caccia in an operation begun in September 2024, with active monitoring of the two subjects since 2019. For Cancellato, don Ferrari, and Yambio, COPASIR found no evidence of spywire interception conducted by Italian intelligence services.

The scrutiny went beyond declarations. Parliamentarians directly entered Cancellato's number into the Paragon system at the agencies and detected neither traces of interception nor authorization decrees. For Yambio, however, a traditional wiretap emerged on a line registered to don Ferrari, a datum that complicates the reconstruction without clarifying it.

In March 2026, the Rome and Naples prosecutors, coordinated by the National Anti-Mafia and Anti-Terrorism Prosecutor's Office, ordered a technical consultation on the case. The primary source text breaks off at this point, leaving the outcome unknown. What is known with certainty, thanks to Wired on April 28, 2026, is that over a year after the Paragon scandal, the company has still not provided answers to the Italian judiciary.

Why It Matters

The Graphite case highlights a structural tension the dossier does not resolve. Italy built a technical surveillance capability on foreign commercial platforms, but the contract denies it full control of the logs and does not guarantee protection from parallel uses by the same vendor. The source does not specify whether Paragon has provided complete audit logs to Italian authorities. The brief does not document any contractual or technical corrective measures adopted after the contract termination on February 6, 2025, nor operational guidance for potentially exposed subjects.

For security professionals, the case confirms that encrypted messaging platforms remain vulnerable to zero-click exploits even without human error, and that the government spyware supply chain introduces risks of insufficient countermeasures. For the institutional and legal sector, it underscores how authorized surveillance and transnational accountability can conflict when the vendor evades national oversight. The source does not clarify who ordered the attacks on Cancellato, don Ferrari, and Yambio if not the Italian services, nor whether the CVE-2025-27363 vulnerability was discovered by Meta, Paragon, or third parties.

"Italy is a client and, simultaneously, a possible target" — Luca Cadonici, Cyber Crime Conference 2026

The reading that emerges from the dossier is not that of a closed scandal, but of an incomplete architecture of power. Italy paid to see, but did not obtain the guarantee of not being seen by the same commercial eyes. The persistence of the judicial investigation and Paragon's silence leave open a question that concerns digital sovereignty not as a slogan, but as a balance sheet: what you buy, what you control, what remains in the vendor's hands.

Frequently Asked Questions

What is the difference between dynamic interception and resident chat extraction?

Dynamic interception captures communications in real time as they transit or are generated on the device, and is authorized by the Prosecutor General. Resident chat extraction instead pulls content already archived in memory, with a legal basis in Article 18 of Law 124/2007.

Why did COPASIR rule out Italian services for some targets but not others?

The parliamentary report documents confirmed use of Graphite on Casarini and Caccia from September 2024. For Cancellato, don Ferrari, and Yambio, entering the numbers into the Paragon system at the agencies revealed no evidence of spyware interception by the services, but does not exclude that other actors may have conducted the attacks.

What is the current status of the AISE-Paragon contract?

On February 6, 2025, The Guardian reported that Paragon terminated the contract with Italy for violation of clauses prohibiting the targeting of journalists and activists. The original expiration of the AISI contract was set for November 7, 2025.

Information has been verified against cited sources and updated at the time of publication.

Sources


Sources and references
  1. ictsecuritymagazine.com
  2. wired.it
  3. eventi.ictsecuritymagazine.com
  4. normattiva.it
  5. veepee-ad.com
  6. adventori.com