[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhGHIurOZr1X2Q3svXx5WgBgXnpBE9q9WS3GUEvtrNZU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"d92cd3e6-da4d-4f77-850d-49242cbbc10e","pegasus-spyware-compromises-eu-parliament-investigators-iphone","58ac2c52-409e-479e-8028-c48a07745148","Pegasus Spyware Compromises EU Parliament Investigator's iPhone","A member of the very committee investigating Pegasus spyware abuse was himself successfully targeted with Pegasus on his iPhone, highlighting how high-value targets — especially those handling sensitive investigations — face elevated and sophisticated threat levels. The attack exploited likely zero-click or zero-day iOS vulnerabilities, which are difficult to defend against without advanced device hygiene and threat monitoring. This incident underscores the danger of assuming institutional role or awareness provides protection against state-level spyware. The potential exposure of confidential parliamentary investigation data represents not just a personal privacy violation but a systemic threat to democratic oversight processes.","**Immediate actions:**\n- Deploy mobile threat defense (MTD) solutions on all devices used by high-risk officials to detect indicators of compromise like those identified by Citizen Lab.\n- Conduct emergency forensic audits of devices belonging to all members of sensitive investigative committees using tools such as the Mobile Verification Toolkit (MVT).\n- Enforce immediate OS updates and apply Apple Lockdown Mode on iPhones used by at-risk individuals to reduce the device attack surface.\n\n**Long-term improvements:**\n- Establish a dedicated device refresh and hardening program for officials involved in sensitive national security or investigative roles.\n- Implement a formal Bring-Your-Own-Device (BYOD) prohibition for sensitive committee work, issuing managed, security-hardened devices instead.\n- Develop a tiered threat model that identifies individuals at heightened risk (e.g., investigators, journalists, lawyers) and applies commensurate security controls.\n\n**Detection measures:**\n- Subscribe to threat intelligence feeds covering commercial spyware (e.g., NSO Group, Intellexa) and configure alerts for associated indicators of compromise.\n- Conduct periodic third-party forensic audits of high-risk officials' devices using Citizen Lab or equivalent independent security researchers.\n- Implement network-level anomaly detection to flag unusual data exfiltration patterns from official devices connected to parliamentary infrastructure.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 7 – Continuous Vulnerability Management","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-124 Rev. 2 – Guidelines for Managing the Security of Mobile Devices","NIST SP 800-53 SI-3 (Malicious Code Protection)","NIST SP 800-53 AC-19 (Access Control for Mobile Devices)","NIST SP 800-53 RA-5 (Vulnerability Monitoring and Scanning)","GDPR Article 5(1)(f) – Integrity and Confidentiality of Personal Data","GDPR Article 32 – Security of Processing","EU Cybersecurity Act (ENISA mandate for high-risk entity guidance)","NIST CSF DE.CM-4 – Malicious Code Detection","ITIL 4 – Security Management Practice (Threat Intelligence Integration)","published","2026-07-03T06:20:45.319862+00:00","2026-07-03T06:20:45.206+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Feu-politicians-investigated-pegasus-spyware-then-it-ended-up-on-one-of-their-phones\u002F","eu-politicians-investigated-pegasus-spyware-then-it-ended-up-on-one-of-their-pho-894de7","EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]