Pegasus zero-click iMessage exploit hits Serbian activists
🔍 The Citizen Lab and SHARE Foundation found that an iPhone linked to Serbia's student protest movement was infected via an iMessage zero-click exploit delivering NSO Group's Pegasus spyware. Analysis showed high-confidence indicators of infection between December 2025 and January 2026, and Apple addressed the exploited vulnerability in iOS 18.4.1. Multiple activists, politicians and students in Serbia have been targeted with advanced spyware amid the 2026 election period.
