[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTgY0H_5LncwjQhBJM_Mi1nN4DlcsoTbOaykcrcuIMFE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"8c557346-253a-4d51-97d7-5d87aacb51ca","pegasus-zero-click-spyware-targets-eu-parliament-investigator","b4316636-adb6-47b6-af31-e8f9eda1853b","Pegasus Zero-Click Spyware Targets EU Parliament Investigator","A European Parliament member investigating commercial spyware abuse was himself targeted with Pegasus via a zero-click exploit in Apple's HomeKit, requiring no user interaction to compromise the device. This attack demonstrates the acute risk that sophisticated, state-licensed spyware poses to democratic oversight processes — the very people investigating surveillance abuse were being surveilled. The repeated infections over several months suggest a failure to detect, respond to, and remediate the initial compromise, allowing prolonged access to sensitive committee materials. When high-value public officials handle confidential legislative work on personal or insufficiently hardened devices, the consequences extend beyond individual privacy to institutional integrity and national security.","**Immediate actions:**\n- Apply all available iOS security patches immediately and enable Lockdown Mode on devices belonging to high-risk individuals such as lawmakers, journalists, and activists.\n- Conduct forensic triage (e.g., using MVT\u002FCitizen Lab tools) on devices belonging to anyone involved in sensitive investigations or oversight roles.\n- Revoke and rotate credentials and access tokens for any accounts accessible from a potentially compromised device.\n\n**Long-term improvements:**\n- Establish a dedicated device security program for high-risk personnel that includes hardened, regularly wiped devices and strict separation between personal and official use.\n- Implement institutional policies requiring officials on sensitive committees to use managed, monitored devices with zero-click exploit mitigations enabled.\n- Engage with national CERTs or trusted security partners to provide ongoing threat intelligence tailored to political and civil society targets.\n\n**Detection measures:**\n- Deploy Mobile Device Management (MDM) solutions with anomaly detection to flag unusual network traffic or process behavior indicative of spyware activity.\n- Perform periodic forensic scans of devices used by high-risk individuals using tools like Amnesty Tech's Mobile Verification Toolkit (MVT).\n- Establish clear incident reporting channels so officials can quickly escalate suspected device compromises to security teams.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-124 Rev. 2: Guidelines for Managing Mobile Device Security","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 IR-4: Incident Handling","NIST SP 800-53 SC-28: Protection of Information at Rest","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of a Personal Data Breach","EU Cybersecurity Act (ENISA mandate for high-risk entity guidance)","MITRE ATT&CK T1476: Deliver Malicious App via Other Means (Zero-Click)","MITRE ATT&CK T1512: Video Capture \u002F Device Sensor Abuse","published","2026-07-03T12:20:26.272377+00:00","2026-07-03T12:20:26.191+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Feuropean-parliament-member.html","european-parliament-member-investigating-spyware-was-hacked-with-pegasus-8f8ffe","European Parliament Member Investigating Spyware Was Hacked With Pegasus",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[51,57,62],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"a9e701d2-0bfe-47a7-bb40-da332b8f6e3c","2026-07-05","afternoon","ThreatNoir Weekend Brief — July 5","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-05\u002Fthreatnoir-afternoon-brief-2026-07-05.mp3",{"id":58,"date":59,"edition":54,"title":60,"audio_url":61},"2f511c5e-ad88-48d0-97e2-30ae28e25766","2026-07-04","ThreatNoir Weekend Brief — July 4","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-04\u002Fthreatnoir-afternoon-brief-2026-07-04.mp3",{"id":63,"date":64,"edition":54,"title":65,"audio_url":66},"d09580d0-cd7a-4b68-9170-5fa41174a07d","2026-07-03","ThreatNoir Afternoon Brief — July 3","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-03\u002Fthreatnoir-afternoon-brief-2026-07-03.mp3"]