A European Parliament member investigating spyware abuse was hacked with Pegasus malware, according to research from Citizen Lab. The attack highlights sophisticated surveillance threats against officials scrutinizing digital rights violations.
Citizen Lab researchers discovered that a member of the European Parliament's committee investigating spyware abuse was targeted with NSO Group's Pegasus malware. The compromise occurred during the committee's active investigation into spyware exploitation across EU institutions.
Pegasus, a commercial surveillance tool, can extract messages, photos, and location data from targeted devices without user knowledge. The attack underscores the vulnerability of high-profile officials pushing for stricter regulations on invasive monitoring technologies.
The incident raises critical questions about who deployed the spyware and whether state or commercial actors were involved. EU lawmakers have previously called for restrictions on Pegasus sales and investigations into unauthorized deployment by member states.
Citizen Lab's findings contribute to growing evidence that spyware poses systemic risks to democratic institutions and privacy. The breach occurred as the Parliament weighs new regulations targeting surveillance tool manufacturers and their government clients.
PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.
A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.
A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.
A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.