❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayCyberScoop

European parliament members call for slowdown of Serbia’s EU entry over spyware use

4 September 2026 at 17:02

A group of European Parliament representatives are seeking to delay Serbia’s entry into the European Union and send other messages to Belgrade over the government’s usage of spyware.

The 29 members of the European Parliament (MEPs) cited a report this week from the SHARE Foundation about spyware found on the phones of Serbian student activists and that targeted others as well. The foundation, along with Amnesty International and The Citizen Lab at the University of Toronto, discovered both Pegasus and NoviSpy spyware infections.

The groups didn’t assign responsibility for the Pegasus infection, but said evidence from the NoviSpy infections pointed to Serbian government authorities.

“This is not a technical glitch; it is a direct state attack on democracy,” the 29 MEPs wrote Friday. “With upcoming elections ahead, Aleksandar Vučić’s regime is using illegal digital surveillance to systematically dismantle political opposition.”

The MEPs’ demands include slowing Serbian accession into the EU until completing an investigation into Serbia’s spyware usage and making Serbia’s accession contingent on improving rule-of-law accountability.

They also said President Ursula von der Leyen should cancel a planned visit to Serbia. European leaders were already outraged by the response from Serbia to the death of former Bosnian Serb army commander and war criminal Ratko Mladic, with Enlargement Commissioner Marta Kos canceling her own visit Friday over the alleged “glorification” of Mladic.

The spyware letter adds to the pressure, said Hannah Neumann, an MEP who signed it.

“It could very well be that some of these demands will be honored, but for sure the spyware won’t be the only reason why,” she told CyberScoop. Serbia’s history of spyware use contributed to Friday’s letter, she said: “We have been critical towards the government for already quite some time and demanded consequences so this was another straw.”

The Serbian government did not respond to multiple requests late Friday for comment.

“Appeasement has failed,” the members wrote. “It is time for the Commission to demonstrate that compliance with fundamental democratic standards is a non-negotiable requirement, not an option.”

European Union member nations have faced their own allegations over using spyware, and recent revelations of spyware found on the device of a member of the European Parliament’s PEGA Committee has prompted some to renew calls for enactment of recommendations from that committee to address spyware abuses.

The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

2 September 2026 at 11:03

Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date.

The SHARE Foundation said Wednesday that it found 14 people targeted in all, including one member of parliament and a local government official. The University of Toronto’s Citizen Lab confirmed the Pegasus infection of a student activist with “high probability,” while Amnesty International confirmed that two devices had been infected with a new version of the NoviSpy spyware.

The SHARE Foundation noted that the infections coincided with the build-up to key local elections in March that were viewed as a test of the ruling Serbian Progressive Party, with student protests rising in the wake of the 2024 Novi Sad railway station canopy collapse, and in advance of October parliamentary elections.

Serbian activists have found themselves targeted with spyware numerous times before, including by Pegasus and NoviSpy. But the SHARE Foundation said this was the biggest wave there so far.

Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.

NoviSpy variant infections

One NoviSpy variant infection came after authorities took a student’s phone during police questioning, and the same spyware was found on another device as well after private messages from the phone were disclosed by a media outlet that favors the ruling party, SHARE Foundation said.

The SHARE Foundation said signs point to Serbian police or secret service being behind the NoviSpy variant cases, with Amnesty International offering a similar assessment. 

“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, told CyberScoop. “As with NoviSpy, which Amnesty International found used extensively in Serbia in 2024, the evidence suggests the infections are being carried out during detention by the Serbian authorities.”

Pegasus infection

In the case of the infection from NSO Group’s Pegasus spyware, it’s rare for investigators to determine who specifically made use of it, although they found that the student’s device was hacked with a Pegasus zero-click exploit from December of last year to January of this year. The infection came via a zero-click exploit — meaning without victim interaction.

But Citizen Lab said the Serbian case harkens back to the first discovery of Pegasus a decade ago when it was against a pro-democracy activist, Ahmed Mansoor.

“Today, Pegasus is still being used to hack people campaigning for democracy,” said John Scott-Railton, senior researcher. “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”

NSO Group maintains that its spyware is for usage against terrorism and crime, and that it halts any abuses it discovers.

The spyware discoveries in Serbia came after Apple sent threat notifications to the targets.

“Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS,” said Bill Marczak, senior researcher at Citizen Lab.

The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.

Someone infected a spyware probe overseer with spyware

3 July 2026 at 01:00

In 2022 and 2023, the European Parliament’s PEGA Committee investigated spyware abuses across the European Union following journalistic revelations about government deployment of NSO Group’s Pegasus technology.

Now, years later, it turns out that someone was using Pegasus spyware on one of the committee’s own. 

In a report published Friday, the University of Toronto’s Citizen Lab revealed that it found Pegasus on the phone of substitute PEGA Committee member Stelios Kouloglou, a Greek journalist and former member of the European Parliament. It’s the first time a member of the committee has been publicly identified as a Pegasus victim.

For Kouloglou, the Pegasus infection was surprising. For another PEGA Committee member, it was fully expected, if delayed. For Citizen Lab, it was ironic.

For all of them, it was further evidence that much more needs to be done to prevent spyware abuses — such as enacting the very recommendations of the PEGA Committee’s final report that never saw action in the European Parliament.

Kouloglou told CyberScoop that he had run security tests on his phone prior to joining the PEGA committee in 2022, so he didn’t think anyone would be bold enough to try to infect his phone once he became a member. With Greece’s use of Predator spyware under scrutiny, “it would be a big scandal” if he was hacked while on the panel, he said.

But someone — Citizen Lab’s investigation didn’t uncover whom — infected Kouloglou’s phone with Pegasus twice, once around October of 2022 and once around March of 2023, investigators concluded with “high confidence.”

During the first infection, the committee was preparing for some prominent hearings and the first draft of its report. Kouloglou was in the hospital and got a visit from another Greek journalist who had testified before the committee and had himself had his phone infected with spyware earlier. Given the ability of spyware to listen to audio through an infected phone, it’s possible the infection ran afoul of protections for health data.

During the second infection, the panel was preparing for yet more hearings and “was engaged in intense discussions related to the final drafting process,” according to Citizen Lab.

The Citizen Lab investigation of Kouloglou’s came about this May, after he said a lawyer he knew told him there was a way to send his phone’s data to the research organization, during a time when Kouloglou was doing some investigative reporting and writing a “scandal of the week” column. “I said, ‘Why not? Let’s do it,” he said.

Whoever was responsible for infecting Kouloglou’s phone did so during “crucial moments” of the committee’s work, said Hannah Neumann, a member of the PEGA Committee and European Parliament member from Germany.

“Many of us were expecting some hacks during the committee, but it’s still frustrating now to figure out that it really happened,” she told CyberScoop. “When we decided to set up the Pega Committee, we really worked hard with our internal European Parliament IT security…  so that they can provide spyware checks for the members of the Pega Committee and their staff.”

Kouloglou and Neumann could only speculate on who was responsible. But for the two of them, and Citizen Lab, the motive seems clear.

“It is ironic that a member of the committee charged with investigating Pegasus was himself targeted with Pegasus spyware,” Ron Deibert, founder and director of Citizen Lab. “Someone, somewhere likely wanted to breach parliamentary privilege and find out what was going on in that committee. This case shows how the still unregulated and highly abused mercenary spyware industry is poisonous to democratic processes.” 

Kouloglou said he plans to pursue legal action against NSO Group. Many spyware victims have had difficulty winning lawsuits against spyware makers, although not all.

Israel-based NSO Group did not respond to a request for comment Thursday afternoon.

Neuman said the lessons learned as a result of Kouloglou’s phone infection include, “for members of national parliament and the European Parliament: Regularly get your devices checked. Apparently they don’t respect European democracy and parliamentarism.”

Most importantly, it’s time to enact the PEGA committee’s recommendations, she said.

“I don’t know how much more it needs for member states and the commission to wake up and actually start implementing the very good recommendations of our PEGA committee, because we all know that there is a spyware abuse,” Neuman said. “I don’t need to have another committee for that. I just need them to act.”

Kouloglou almost certainly won’t be the last member of parliament to get infected, said John Scott-Railton, senior researcher at Citizen Lab. Some had been infected prior to the work of the PEGA Committee, and some have been found to be targeted since. (The United States’ legislative body has been targeted in the past as well.)

“Providing highly secretive government agencies with surveillance tools supplied by unaccountable and often unethical mercenary firms is a recipe for the abuse of power,” he told CyberScoop. “I can tell you how the next chapter will go: more hacked Parliamentarians. In fact, I suspect there are members voting and attending high level meetings with no idea that their phone has been turned into a spy in their pocket.”

The post Someone infected a spyware probe overseer with spyware appeared first on CyberScoop.

❌
❌