CuraSec

Plan active

Pegasus Zero-Click iMessage Exploit Hits Serbian Student Activist iPhone

2026-09-03 14:58 UTC · The Hacker News · read the source ↗ #pegasus#zero-click#nation-state
  • Engineer — Learn: A zero-click iMessage exploit was used to deploy Pegasus, reinforcing the case for enabling Lockdown Mode on devices belonging to high-risk individuals (executives, journalists, legal); no CVE or patch is identified in this report to act on directly.
  • SOC/IR — Plan: Citizen Lab reports high-confidence indicators from this infection — review the full Citizen Lab report for published IOCs and build or tune a detection for Pegasus-associated network beacons if you defend any high-profile or at-risk individuals in your estate.
  • Leader — Learn: Ongoing confirmed Pegasus deployment against civil-society targets is a governance data point; organizations with journalists, activists, or high-profile executives should review whether Lockdown Mode or equivalent MDM hardening is policy for those roles.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.