60
42
30
60
30
30
55
30
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Citizen Lab and SHARE Foundation confirm a Serbian student activist's iPhone was infected with NSO Group Pegasus via a zero-click iMessage exploit.
Forensic analysis found high-confidence infection indicators on the activist's iPhone during December 2025 and January 2026, using an iMessage zero-click exploit the Citizen Lab believes was patched as of iOS 18.4.1, released April 2025. The target was among at least 14 Apple Threat Notification recipients in Serbia's student movement, civil society, and opposition politics documented by the SHARE Foundation. Targeting occurred ahead of key 2026 election cycles; Amnesty Tech also confirmed a new NoviSpy version on another student movement member's device.
55
60
55
60
30
55
60
60
42
30
30
60
60
55
60
60
60
30
60
60
30
60
55
55
55
30
42
30
55
60
42
60