// 3 CVE · 2 EXPLOIT IN THE LAST 24H
On September 2, 2026, Citizen Lab and SHARE Foundation published a forensic analysis of an iPhone belonging to a member of the Serbian student movement, infected with NSO Group's Pegasus spyware between December 2025 and January 2026. The infection — the first confirmed of the year — exploited a zero-click iMessage vulnerability patched by Apple in April 2025 with iOS 18.4.1, reigniting debate over the resilience of technical countermeasures against mercenary surveillance.
{"main_topic":"cybersecurity","topics":["cybersec","exploit","malware","apple","iphone"]}

On September 2, 2026, Citizen Lab and SHARE Foundation published the forensic analysis of an iPhone belonging to a member of the Serbian student movement, infected with NSO Group's Pegasus spyware between December 2025 and January 2026. The infection — the first confirmed of the year — exploited a zero-click iMessage vulnerability patched by Apple in April 2025 with iOS 18.4.1, reigniting debate over the resilience of technical countermeasures against mercenary surveillance.

The case sits within a broader wave: at least 14 people in Serbia have been targeted with advanced spyware since the start of 2026, including activists, student movement members, an opposition MP, and a city councilor. The infections coincided with the local elections of March 29, 2026.

Key Takeaways
  • Citizen Lab forensically confirmed the Pegasus infection via a zero-click iMessage exploit, with high-confidence indicators for the period December 2025 – January 2026.
  • SHARE Foundation describes the wave as the most severe spyware surveillance campaign ever documented in Serbia.
  • Apple sent threat notifications to 14 individuals linked to the Serbian student movement and civil society.
  • Amnesty International separately detected an Android variant of NoviSpy installed physically during detentions by Serbian police.

Forensic Analysis: How the Attack Works

Citizen Lab's research, conducted in collaboration with SHARE Foundation, is based on a forensic analysis of the victim's device. According to the team's official statement: "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware". The exploit requires no interaction from the target: simply receiving an iMessage is sufficient for infection.

Researchers identified high-confidence indicators for the period December 2025 – January 2026, while noting this does not rule out additional infections. The exploited vulnerability was subsequently patched by Apple in iOS 18.4.1, released in April 2025. Bill Marczak, senior researcher at Citizen Lab, stated: "Apple's updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS".

The victim requested anonymity; the exact infection date was not disclosed to protect their privacy. No CVE was assigned to the exploited iMessage vulnerability — a recurring pattern with NSO Group exploits, which are typically used as zero-days before public disclosure.

Pegasus and NoviSpy: Two Surveillance Models Compared

The forensic investigation revealed the simultaneous presence of two spyware ecosystems with radically different deployment methods. On one side, Pegasus, NSO Group's commercial product, delivered remotely via zero-click exploit. On the other, NoviSpy, an Android variant documented by Amnesty International Security Lab, installed physically on devices during detention by Serbian authorities.

Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, stated: "These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware... the evidence suggests the infections are being carried out during detention by the Serbian authorities". Amnesty confirmed two devices infected with a new version of NoviSpy. In one case, infection occurred after police seized a student's phone during an interrogation. In the second, the same variant was detected after private Viber messages were broadcast on a pro-government television channel.

SHARE Foundation and Amnesty International assess that Serbian police or intelligence services are behind the NoviSpy cases. On the Pegasus front, no infrastructure overlaps link the attack to a specific operator at this stage. NSO Group sells its systems exclusively to governments; which authorized customer conducted the attack remains unknown.

The Political Dimension: Elections, Protests, and EU Accession

The infections occurred amid high political tension. The local elections of March 29, 2026 coincided with a mobilization phase of the Serbian student movement, which has emerged as a significant opposition force to the government. The use of advanced spyware against activists and opposition figures raises direct questions about the rule of law in the country.

Serbia is formally a candidate for European Union accession. Protection from illegitimate surveillance and respect for fundamental freedoms are criteria assessed in the enlargement process. Documentation of a spyware wave against political dissidents — described by SHARE Foundation as the most severe ever recorded in the country — introduces a friction variable in relations with Brussels.

John Scott-Railton, senior researcher at Citizen Lab, summarized the persistence of the problem: "Today, Pegasus is still being used to hack people campaigning for democracy. NSO spent a decade promising reform, yet their spyware is still an instrument of political repression". The first discovery of Pegasus dates to 2016; a decade later, the mercenary surveillance business model retains its operational effectiveness despite Apple's technical countermeasures and NSO Group's reform promises.

"Today, Pegasus is still being used to hack people campaigning for democracy. NSO spent a decade promising reform, yet their spyware is still an instrument of political repression." — John Scott-Railton, senior researcher, Citizen Lab

What to Do Now

For high-risk users — journalists, activists, members of political oppositions in sensitive contexts — priority actions derive directly from the technical evidence in this case:

  • Update immediately to iOS 18.4.1 or later: the patch released in April 2025 breaks the specific iMessage exploit documented by Citizen Lab.
  • Enable Lockdown Mode: Apple introduced this feature as a specific mitigation against mercenary spyware; it significantly reduces the attack surface of iMessage and other zero-click vectors.
  • Heed Apple Threat Notifications: 14 individuals in Serbia received them; Apple's official alert is a reliable indicator of targeting with advanced spyware.
  • Physically separate the mobile device in detention or seizure situations: the NoviSpy cases demonstrate that physical access to the phone is exploited to install Android spyware in government custody environments.

Why the Serbian Case Is a Signal for Europe

The forensic confirmation of the Pegasus infection in Serbia in 2026 breaks a dominant narrative: that Apple's technical countermeasures, combined with regulatory and media pressure on NSO Group, had reduced the operational effectiveness of commercial spyware. The facts show a different picture. The exploit patched in April 2025 found vulnerable targets the following winter, likely due to update delays or the absence of Lockdown Mode on targeted devices.

The convergence between transnational mercenary spyware and domestic spyware developed or deployed directly by the same authorities who physically detain dissidents is the most concerning phenomenon. It is no longer a choice between sophisticated remote surveillance and traditional interception: the two models coexist, reinforce each other, and operate on complementary timelines — one before detention, the other during.

For European institutions, the question extends beyond the Serbian case. If protection from illegitimate surveillance is an accession criterion, verification cannot be limited to normative text: it requires independent forensic capacity, cooperation among researchers, digital foundations, and technology vendors, and a coordinated response when indicators become proof.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. cyberscoop.com
  3. citizenlab.ca
  4. ft.com
  5. eutoday.net
  6. support.apple.com