Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]

Serbian activists, including members of a student protest movement and civil society figures, have been targeted with advanced spyware, including NSO Group's Pegasus and the locally developed NoviSpy. This surveillance campaign coincides with a period of political unrest and upcoming elections in Serbia.
The Citizen Lab, in collaboration with the SHARE Foundation, confirmed a zero-click Pegasus infection on the iPhone of a Serbian student activist. Forensic analysis traced the infection to an iMessage zero-click exploit, with high-confidence indicators of compromise identified between December 2025 and January 2026. This exploit, which required no action from the victim, allowed attackers full access to the device's data, including messages, photos, notes, microphone, and camera. Apple subsequently patched this specific exploit in iOS 18.4.1.
This confirmed Pegasus infection is part of a broader surveillance effort. The SHARE Foundation has documented at least 14 individuals targeted with advanced spyware since early 2026. These targets include student movement members, civil society activists, an opposition member of parliament, and a local councilor. This wave of targeting, described by the organization as the largest documented surveillance in Serbia's history, aligns with local elections held on March 29, 2026, and precedes planned early parliamentary elections in October, following months of student-led anti-government and anti-corruption protests.
Twelve individuals approached SHARE's digital forensics team in August after receiving Apple Threat Notifications, which are warnings issued when Apple detects likely state-sponsored spyware targeting. Eleven of these devices are presumed infected, pending further forensic confirmation.
Beyond Pegasus, a new version of NoviSpy was discovered on an Android phone belonging to a student activist. This discovery was made by the SHARE Foundation and Amnesty Tech after Serbian authorities seized the device during police questioning. Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, linked the installation of the spyware to the period of detention by Serbian authorities.
Serbia has a documented history of using commercial spyware. Citizen Lab previously reported on Pegasus targeting civil society and the use of Cellebrite tools to install NoviSpy on activists' phones.
For individuals who receive an Apple Threat Notification, Citizen Lab advises treating it as a presumed infection and seeking expert assistance immediately. In Serbia, individuals are directed to contact the SHARE Foundation. Globally, Access Now's Digital Security Helpline supports journalists, human rights defenders, and other high-risk civil society targets. Additionally, anyone at increased risk due to their work or public role is advised to enable Apple's Lockdown Mode, which significantly reduces the attack surface for zero-click exploits, and to keep all devices updated to benefit from the latest security patches.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.