Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of
- 1. Citizen Lab and the SHARE Foundation confirmed that a Serbian student activist's iPhone was infected with Pegasus spyware.
- 2. At least 14 Serbian activists, opposition figures, and students have been targeted by advanced spyware since early 2026.
- 3. Amnesty International reported that Serbian authorities installed invasive Android spyware on devices confiscated from detained students.
Article analysis
Skim this article about "Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone": 3 key takeaways and more.
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
skim AI Analysis | The Hacker News
The Hacker News on Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone: skim's analysis surfaces 3 key takeaways. Citizen Lab and the SHARE Foundation confirmed that Pegasus spyware targeted a Serbian student activist via an iMessage zero-click exploit. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Tech. News article analyzed by skim.
Summary
Citizen Lab and the SHARE Foundation confirmed that Pegasus spyware targeted a Serbian student activist via an iMessage zero-click exploit. The findings highlight wider state surveillance efforts affecting at least 14 activists and opposition politicians in Serbia.
Key Takeaways
- The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.
- In all, at least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026, the SHARE Foundation confirmed.
- "The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities," Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, said.
Statement Breakdown
- Claimed Facts: 75% of statements the article presents as facts
- Opinions: 15% of statements classified as editorial or subjective
- Claims: 10% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The report relies on technical investigations conducted by reputable cybersecurity research entities including Citizen Lab, Amnesty International, and SHARE Foundation. The findings cite specific exploit vectors, vulnerability patches, and forensic examinations. Factual statements are clearly attributed to established digital rights and security organizations.
Bias assessment: Technical Cybersecurity Reporting. The reporting focuses on digital forensic disclosures and technical mitigation strategies without hyperbole. It covers state surveillance targeting political figures and activists while relying directly on primary forensic research statements. The overall perspective is oriented toward privacy rights and technical accuracy.
Note: This article relies on verified digital forensic findings from independent security research labs.
Credibility flag: Forensically Verified
Claimed Facts (5)
- This is a direct technical finding presented as checkable forensic evidence.
- This is a specific, verifiable metric regarding Apple threat notifications.
- This statement describes documented targets identified during the investigation.
- This provides a specific verifiable calendar date and political context.
- This is a concrete incident report verified by forensic detection and public broadcast.
Opinions (5)
- This is an evaluative security recommendation directed at potential high-risk targets.
- This is an informative evaluation of available commercial protection programs.
- This contains an expert qualitative assessment regarding the developers' technical intentions.
- This represents an analytical attribution assessment of the underlying software vulnerability.
- This characterizes a series of events as part of a continuous pattern of technological abuse.
Claims (5)
- The claim leaves open unproven possibilities beyond what direct forensic telemetry verified.
- The chain of custody and attribution directly linking police custody to the deployment is strongly implied rather than legally adjudicated.
- The statement asserts conclusive proof of state deployment during detention based on forensic timing correlations.
- The notification process is based on proprietary Apple suspicion models rather than transparent open telemetry.
- Commercial vendor claims regarding broad protection against advanced mercenary attacks can overstate defensive completeness.
Key Sources
- The Citizen Lab — Academic Research Lab at the University of Toronto
- SHARE Foundation — Serbian Non-Profit Digital Rights Organization
- Donncha Ó Cearbhaill — Head of Amnesty International's Security Lab
- Apple — Technology Corporation
- Ravie Lakshmanan — Journalist at The Hacker News
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 3rd September 2026.