[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNKiprEnowbsFy9A6_ld_owRrbOlVWKGcG_-fQLUvs8E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"6a4682c2-c293-435b-a5a0-685e96ea8467","pegasus-zero-click-spyware-targets-serbian-activists-iphone-via-imessage-exploit","740392c7-b8fb-4cb3-8afb-52ae950de9d5","Pegasus Zero-Click Spyware Targets Serbian Activist's iPhone via iMessage Exploit","A Serbian student activist's iPhone was silently compromised using NSO Group's Pegasus spyware through a zero-click iMessage exploit, requiring no interaction from the victim whatsoever. This case illustrates the extreme danger of zero-click vulnerabilities, which bypass traditional security awareness training since users cannot avoid infection through behavioral caution alone. The exploit was eventually patched in iOS 18.4.1, but the gap between exploitation and patching left high-risk individuals exposed during a critical period. This incident underscores that civil society members, journalists, and activists are active targets of nation-state-grade mercenary spyware, making timely patch adoption and proactive threat monitoring essential — not optional.","**Immediate actions:**\n- Update all Apple devices to iOS 18.4.1 or later immediately to close the patched iMessage zero-click vulnerability.\n- Enable Apple's Lockdown Mode on iPhones belonging to at-risk individuals (activists, journalists, dissidents) to drastically reduce the attack surface.\n- Enroll high-risk users in Apple's Advanced Data Protection and threat notification programs to receive early warnings of mercenary spyware targeting.\n\n**Long-term improvements:**\n- Establish a rapid patch deployment policy that prioritizes critical OS and messaging-app updates within 24–48 hours of release for all at-risk personnel.\n- Maintain a device inventory and vulnerability tracking program to ensure no endpoints are running unpatched firmware or OS versions.\n- Partner with organizations like Citizen Lab or Access Now's Digital Security Helpline to provide ongoing spyware threat assessments for civil society groups.\n\n**Detection measures:**\n- Periodically run Mobile Verification Toolkit (MVT) forensic scans on devices belonging to high-risk individuals to detect indicators of Pegasus or similar spyware.\n- Monitor for anomalous device behavior such as unexpected battery drain, data usage spikes, or unsolicited iMessage attachments that may signal exploitation attempts.\n- Subscribe to Apple threat notification alerts and establish an incident response plan specifically for suspected mercenary spyware infections.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets","NIST SP 800-40 Rev 4: Guide to Enterprise Patch Management","NIST SP 800-124 Rev 2: Guidelines for Mobile Device Security","NIST IR-6: Incident Reporting","GDPR Article 32: Security of Processing (for organizations handling activist\u002Fpersonal data)","NIST CSF DE.CM-4: Malicious Code Detection","UN Guiding Principles on Business and Human Rights (re: mercenary spyware vendor accountability)","published","2026-09-03T10:20:55.861566+00:00","2026-09-03T10:20:55.564+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fpegasus-zero-click-spyware-exploit.html","pegasus-zero-click-spyware-exploit-infects-serbian-student-movement-member-s-iph-b6e02e","Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]