Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
- ID
- 21000
- Status
- summarized
- Published
- 03 Sep 2026, 4:43 PM
- Fetched
- 03 Sep 2026, 7:22 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 03 Sep 2026, 7:23 PM
- Tags
- Audience
- developers
What happened
Citizen Lab and the SHARE Foundation confirmed that a Serbian student movement member's iPhone was infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit, patched in iOS 18.4.1 released April 2025. At least 14 people in Serbia have been targeted with advanced spyware since early 2026, including activists, an MP, and a local councilor, coinciding with March 29, 2026 local elections. A new Android spyware variant similar to NoviSpy was also found installed on a student's device while detained by police.
Why it matters
The only concrete action for this audience is ensuring devices are on iOS 18.4.1 or later, which patches the specific iMessage zero-click exploit used here. Beyond that, this is a nation-state surveillance story targeting political activists in Serbia with no direct bearing on AI tooling, developer infrastructure, or SaaS building.
Discussion angle
Worth a brief mention only as a reminder that mercenary spyware exploits against iMessage are real and patched — but skip deep discussion since this audience doesn't ship or defend against nation-state surveillance tooling.