<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone]]></title><description><![CDATA[<p dir="auto">Analysis from Citizen Lab, working alongside the SHARE Foundation, has confirmed that the iPhone of a member of Serbia’s student protest movement was compromised with NSO Group’s Pegasus spyware. The investigation points to the use of an iMessage zero-click exploit to deliver the malware, meaning the attack required no interaction from the victim.</p>
<p dir="auto">High-confidence indicators of compromise were identified on the device, aligning with previously documented Pegasus infection vectors. The discovery underscores the continued use of commercial surveillance tools against civil society actors, particularly those involved in political activism.</p>
<ul>
<li>The infection was carried out via an iMessage zero-click exploit.</li>
<li>The device belonged to a member of Serbia's student protest movement.</li>
<li>The analysis was a joint effort between Citizen Lab and the SHARE Foundation.</li>
</ul>
<p dir="auto">The findings highlight the risk posed by zero-click vulnerabilities in widely used messaging platforms. For organizations or individuals in high-risk professions, it is worth reviewing device security settings and considering lockdown modes where available, though the specifics of this exploit chain have not been fully disclosed.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">With this level of sophistication in delivery, how is your organization approaching the threat of zero-click mobile exploits, and what mitigation steps are you prioritizing?</p>
]]></description><link>https://xploitlk.com/topic/200/pegasus-zero-click-spyware-exploit-infects-serbian-student-movement-member-s-iphone</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:36:37 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/200.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 03 Sep 2026 10:30:19 GMT</pubDate><ttl>60</ttl></channel></rss>