LIVE · cybersecurity feed
Live wire
security

European Parliament Member Investigating Spyware Was Hacked With Pegasus

A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with inve

zeroday.news · 29d ago

A former Member of the European Parliament who was part of a committee investigating spyware was himself targeted with the Pegasus surveillance tool, according to a report by Citizen Lab. Stelios Kouloglou's mobile device was reportedly compromised multiple times.

Kouloglou was a member of a special committee established by the European Parliament to investigate the use of spyware, including Pegasus. This committee was formed in response to revelations about the widespread misuse of such surveillance technology against journalists, activists, and politicians across Europe and globally.

The discovery of the Pegasus infection on Kouloglou's device raises significant concerns about the potential for state-sponsored surveillance to infiltrate legislative bodies and target individuals involved in oversight and inquiry into such activities. The timing of the hacks, while he was actively involved in the spyware investigation, is particularly noteworthy.

Pegasus, developed by the Israeli firm NSO Group, is a sophisticated spyware capable of extracting vast amounts of data from a targeted device, including messages, emails, call logs, and location data, and can even activate the device's microphone and camera without the user's knowledge. NSO Group maintains that its product is sold only to vetted government intelligence and law enforcement agencies for the stated purpose of combating terrorism and serious crime.

The Citizen Lab report details the repeated nature of the intrusions, suggesting a persistent effort to monitor Kouloglou's communications and activities. The specific dates and methods of these hacks were not detailed in the provided information, but the repeated targeting indicates a sustained interest in the former MEP.

The European Parliament has been a vocal critic of spyware use and has taken steps to address the issue, including the formation of committees like the one Kouloglou served on. This incident underscores the challenges faced by lawmakers and oversight bodies in protecting themselves from the very tools they are investigating.

The implications of a parliamentarian involved in spyware oversight being targeted are far-reaching, potentially undermining the integrity of legislative investigations and creating a chilling effect on free speech and political discourse. It raises questions about who authorized the deployment of Pegasus against Kouloglou and for what purpose.

While the source material does not specify any immediate actions taken by the European Parliament or Kouloglou following the discovery, such incidents typically prompt calls for further investigation, increased security measures for officials, and stronger regulatory frameworks to prevent the misuse of surveillance technology.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.