/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Investigation: Israel-based NSO Group's malware infected 23 phones belonging to government officials, reporters, execs, and activists, out of 67 checked

Dana Priest, a reporter at The Washington Post for 30 years, covers national security issues.  Recently, she has investigated Russian

Washington Post Dana Priest

Discussion

  • @jsrailton John Scott-Railton on x
    BREAKING: massive, global leak of the targets of NSO Group's Pegasus spyware. *huge deal.* Forensic investigation by @AmnestyTech in collaboration with @FbdnStories reporters. We @citizenlab conducted peer review. Here's an explainer THREAD. https://www.washingtonpost.com/ ... ht…
  • @washingtonpost @washingtonpost on x
    Military-grade Israeli spyware was used in attempted and successful hacks of 37 smartphones belonging to journalists, human rights activists, business executives and the fiancee of murdered Saudi journalist Jamal Khashoggi, a global investigation finds. https://www.washingtonpost…
  • @snowden Edward Snowden on x
    Stop what you're doing and read this. This leak is going to be the story of the year: (LINK: https://t.co/...) https://twitter.com/...
  • @wcathcart Will Cathcart on x
    This groundbreaking reporting from @Guardian, @WashingtonPost, and many others demonstrates what we and others have been saying for years: NSO's dangerous spyware is used to commit horrible human rights abuses all around the world and it must be stopped. https://www.theguardian.c…
  • @josephfcox Joseph Cox on x
    Newly released NSO linked domains https://github.com/... https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    2. Background: the already-notorious NSO Group makes mercenary spyware to silently & remotely hack iPhones & Androids. Many of their government customers are authoritarians. Most cannot resist the temptation to target their critics, reporters, human rights groups etc. https://twi…
  • @jsrailton John Scott-Railton on x
    3. More about leaked numbers & targets in a sec, but first you need to know: @AmnestyTech just released a report with technical analysis of NSO's infrastructure... & analysis validating w/forensics that some phones were infected with Pegasus. https://www.amnesty.org/...
  • @jslaternyc Joanna Slater on x
    Introducing the Pegasus Project: a collaborative investigation involving more than 80 journalists on 4 continents showing how powerful spyware licensed only to governments targeted journalists, activists and more. https://www.washingtonpost.com/ ... 1/
  • @billmarczak Bill Marczak on x
    It also indicates that Apple has a MAJOR blinking red five-alarm-fire problem with iMessage security that their BlastDoor Framework (introduced in iOS 14 to make zero-click exploitation more difficult) ain't solving.
  • @jsrailton John Scott-Railton on x
    5. Now, to the findings: >50k numbers were leaked that are reportedly part of the infection & targeting workflow with Pegasus. To help validate the relationship between these numbers & infections @AmnestyTech got consent to forensically examine a subset of the devices. https://tw…
  • @snowden Edward Snowden on x
    Hungary gave the most incriminating response I've ever seen to a request for comment on the #Pegasus surveillance scandal. I mean, whenever I'm “not aware” of whether I did something or not, I demand to know if foreign spies tipped you off about it. LINK: https://www.theguardian.…
  • @thewire_in @thewire_in on x
    @svaradarajan @mkvenu1 @DevirupaM @rohini_sgh @sukanyashantha 7. The NSO Group issued multiple responses to the #ProjectPegasus investigation. Some were direct communications to media, and others were from legal counsel warning that media partners could be sued for defamation. ht…
  • @shanehuntley Shane Huntley on x
    Continuing evidence of the harm done by companies like NSO. What will it take for governments to stop these vendors operating with impunity? https://twitter.com/...
  • @nihamasih Niha Masih on x
    BREAKING: Introducing the Pegasus Project: a collaborative investigation involving more than 80 journalists on 4 continents showing how powerful spyware licensed only to governments targeted journalists, activists and more. (1/n) https://www.washingtonpost.com/ ...
  • @jsrailton John Scott-Railton on x
    8. #HUNGARY 🇭🇺 Ask the government for comment... get hacked. Hungary's far-right PM Viktor Orbán is using Pegasus spyware to surveil & attack Hungary's independent media, like @direkt36, @panyiszabolcs, and many more. Story: @shaunwalker7 https://www.theguardian.com/ ... https://…
  • @glcarlstrom Gregg Carlstrom on x
    The charming folks at Israel's NSO Group were asked by a number of mostly authoritarian governments, among them Saudi Arabia and the UAE, to spy on the phones of more than 180 journalists around the world (myself included). https://www.theguardian.com/ ...
  • @josephfcox Joseph Cox on x
    Apps that are installed by default on iOS are being leveraged by NSO to install their malware; apps that people would not ordinarily see as a threat, or may not even use, so likely haven't removed from their devices https://www.amnesty.org/... https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    4. We @citizenlab independently peer reviewed @AmnestyTech's forensic methodology, including how they identify an infected phone. Our review, led by my colleague @billmarczak, judged their forensics & research methodology to be SOUND. https://citizenlab.ca/... https://twitter.com…
  • @snowden Edward Snowden on x
    The Israeli company behind this — the NSO group — should bear direct, criminal liability for the deaths and detentions of those targeted by the digital infection vectors it sells, which have no legitimate use. https://twitter.com/...
  • @fs0c131y Baptiste Robert on x
    Insane work of @amnesty on the activity of the NSO group. They also released IOCs and the tools they used. #DFIR folks this article is made for you. https://www.amnesty.org/...
  • @amnesty @amnesty on x
    Here's how our Security Lab analysed the phones 👇 #PegasusProject https://www.amnesty.org/...
  • @satyajeettambe Satyajeet Tambe on x
    Marching towards the dictatorial state. #Pegasus https://twitter.com/...
  • @mairavz @mairavz on x
    Potential targets of surveillance included the Wall Street Journal, CNN, the New York Times, Al Jazeera, France 24, Radio Free Europe, Mediapart, El País, AP, Le Monde, Bloomberg, Agence France-Presse, the Economist, Reuters and Voice of America https://www.theguardian.com/ ...
  • @dalrymplewill William Dalrymple on x
    FT editor among 180 journalists identified by clients of spyware firm Data leak and forensics suggest NSO's surveillance tool used against journalists at some of world's top media companies https://www.theguardian.com/ ...
  • @andraslederer Andras Lederer on x
    300+ HUN targets identified, incl @direkt36's investigative stars @AndrasSzab & @panyiszabolcs. No surprise #pegasus spyware targets civil society figures as well. In the first 3,5 mths of 2021, Judit Varga approved on avg 5 surveillance reqs/day. Govt reaction speaks for itself …
  • @wcathcart Will Cathcart on x
    In 2019, @WhatsApp discovered and defeated an attack from NSO. They rely on unknown vulnerabilities in mobile OSes, which is one of the reasons why we felt it was so important to raise awareness of what we'd found. https://www.washingtonpost.com/ ...
  • @iamcouncil Indian American Muslim Council on x
    Among the journalists hacked by Pegasus were Siddharth Varadarajan and Paranjoy Guha Thakurta, a co-founder and a reporter at the Indian news website the Wire. Thakurta was hacked in 2018 while he was working on an investigation into Hindu nationalists. https://www.theguardian.co…
  • @panyiszabolcs Szabolcs Panyi on x
    200 journalists worldwide were selected as targets for surveillance by authoritarian & corrupt regimes. My phone was hacked for 7 months with a spyware called Pegasus, forensic analyses by @amnesty & @citizenlab confirmed. That's life.😬 #PegasusProject https://www.theguardian.com…
  • @salmansoz Salman Anees Soz on x
    The Indian contingent at the #pegasus olympics includes “ministers, opposition leaders, business executives, senior officials, scientists, activists and others”. Is there anyone Modi & Shah are not scared of? Thread👇 https://twitter.com/...
  • @galffy @galffy on x
    If this doesn't explode as it should, there's no hope for Hungary. https://twitter.com/...
  • @billmarczak Bill Marczak on x
    Because the 0-clicks they're using appear to be quite reliable, the lack of traditional “persistence” is a feature, not a drawback of the spyware. It makes the spyware more nimble, and prevents recovery of the “good stuff” (i.e., the spyware and exploits) from forensic analysis
  • @jsrailton John Scott-Railton on x
    18. Know who else is saying #NSOGroup must be stopped? Big tech. These days they are hitting back hard against the mercenary spyware industry for hacking their products & users. E.g. this thread by @wcathcart @WhatsApp's CEO.👇 https://twitter.com/...
  • @billmarczak Bill Marczak on x
    Phone logs show that (at least some of) the iOS 13.x and 14.x zero-click exploits deployed by NSO Group involved ImageIO, specifically the parsing JPEG and GIF images. ImageIO has had more than a dozen high-severity bugs reported against it in 2021.
  • @philthatremains @philthatremains on x
    Your privacy is not intact if you own a cell phone. https://twitter.com/...
  • @zahrahankir Zahra Hankir on x
    Roula Khalaf, the Lebanese veteran journalist and first female editor of the FT, and Omar Radi, the Moroccan freelance journalist and human rights activist who is currently on trial (verdict due Monday), were also targeted https://twitter.com/...
  • @haaretzcom @haaretzcom on x
    Here's how NSO's Pegasus software is used to infect journalists phones in what is called “zero clicks” https://www.haaretz.com/...
  • @wcathcart Will Cathcart on x
    Thank you to @Microsoft, @Google, @Cisco, @VMWare, the @InternetAssn and others who have spoken up against the perils of giving spyware firms like NSO immunity.
  • @drewharwell Drew Harwell on x
    New: Our giant global investigation into the private Israeli spyware used to hack the phones of journalists and activists around the world. Reported with #PegasusProject across 10 countries. And there are so many stories to tell: https://www.washingtonpost.com/ ...
  • @langamahesh Mahesh Langa on x
    @WhatsApp chief is scathing on Israel technology company for commiting horrible human rights abuses. @POTUS should force Israel to stop selling such technology that undermines democracies as authoritarian regimes target media/political opponents/judiciary & critcs. #Pegasus https…
  • @freedomofpress @freedomofpress on x
    HUGE new investigation: “The editor of the @FT is one of more than 180 editors, investigative reporters and other journalists around the world who were selected as possible candidates for surveillance by gov't clients of the surveillance firm NSO Group” https://www.theguardian.co…
  • @avischarf Avi Scharf on x
    Israeli firm NSO's Pegasus software is used to infect journalists phones utilizing ‘zero click’ exploits. Here's how they did it and what we found out https://www.haaretz.com/...
  • @shaunwalker7 Shaun Walker on x
    My piece on how some of the world's most invasive spyware is being used against independent Hungarian media - the result of a long, enriching and very collaborative investigation with various outlets. A small part of the upcoming #PegasusProject https://www.theguardian.com/ ...
  • @elise_jordan Elise Jordan on x
    This is a HUGE story: “Reporters...range from local freelancers, such as the Mexican journalist Cecilio Pineda Birto, who was murdered by attackers armed with guns one month after his phone was selected, through to prize-winning investigative reporters, editors and executives” ht…
  • @washingtonpost @washingtonpost on x
    The widespread use of spyware has emerged as a leading threat to democracies worldwide, critics say. “This is nasty software — like eloquently nasty,” said Timothy Summers, a former cybersecurity engineer at a U.S. intelligence agency. https://www.washingtonpost.com/ ...
  • @panyiszabolcs Szabolcs Panyi on x
    Thank you @citizenlab for doing the peer review of my phone's forensic analysis. I finally have proof I wasn't paranoid - I was right all the time!😬 My surveillance with the Pegasus spyware started on April 4, 2019 & ended on November 7, 2019. Is it going to start again...? 🤷🏻‍♂ …
  • @wcathcart Will Cathcart on x
    At the time, we worked with @CitizenLab, who identified 100+ cases of abusive targeting of human rights defenders and journalists in 20+ countries. But today's reporting shows that the true scale of abuse is even larger, and with terrifying national security implications.
  • @arvindgunasekar Arvind Gunasekar on x
    WhatsApp head 👇🏻 https://twitter.com/...
  • @billmarczak Bill Marczak on x
    (4) One of the other interesting bits here is just how much of pain it is to do phone forensics. @AmnestyTech couldn't do much w/ Android (as a lot of logs that are easy-to-access are wiped on device reboot), and the highest-signal iPhone analysis was limited to DataUsage.sqlite
  • @valeriein140 Valerie Hopkins on x
    There were 11 occasions when a Pegasus infection was confirmed within a few days of a comment request from @panyiszabolcs to the Hu Gvt, according to analysis. More than 50% of the comment requests he sent to the government during a 7 month period were followed up with an attack …
  • @drewharwell Drew Harwell on x
    * Jamal Khashoggi's wife was targeted with spyware before his death: https://www.washingtonpost.com/ ... * Surveilled in Hungary: https://www.washingtonpost.com/ ... * A guide to Pegasus spyware: https://www.washingtonpost.com/ ... * Key details: https://www.washingtonpost.com/ .…
  • @pbhushan1 Prashant Bhushan on x
    “Revealed: leak uncovers global abuse of cyber-surveillance weapon. Spyware sold to authoritarian regimes used to target activists, politicians and journalists, data suggests.” Many activists, journalists, politicians& judges are targets in India. #Pegasus https://www.theguardian…
  • @vidyakrishnan Vidya on x
    This is a bomb shell of a story. #PegasusProject #ModiHaiTohMumkinHai https://twitter.com/...
  • @cat_zakrzewski Cat Zakrzewski on x
    “Humanity is not in a place where we can have that much power just accessible to anybody.” https://twitter.com/...
  • @evacide Eva on x
    My mentions are now a pit of privacy nihilism. Fuck privacy nihilism. Privacy is not dead. Scared and insecure government leaders spy on the people who stand up to them precisely because privacy is not dead and its continued existence is a threat to them.
  • @agnescallamard Agnes Callamard on x
    Our first statement on the massive data leak which @amnesty helped unveil. NSO claims that the targeting of human rights defenders and journalists through its spyware are rare and down to rogue use of their technology are blown apart. https://www.amnesty.org/...
  • @omerbenj Omer Benjakob on x
    Snowden calls to hold NSO directly accountable for abuse of its spy tech software after @PhineasJFR's bombshell report for @FbdnStories comes out across the world as part of massive global investigation https://twitter.com/...
  • @billmarczak Bill Marczak on x
    BlastDoor is a great step, to be sure, but it's pretty lame to just slap sandboxing on iMessage and hope for the best. How about: “don't automatically run extremely complex and buggy parsing on data that strangers push to your phone?!”
  • @omthanvi Om Thanvi on x
    NSO Group claims that its Pegasus spyware is only used to “investigate terrorism and crime” and “leaves no traces whatsoever”. This Forensic Methodology Report shows that neither of these statements are true. ~ ⁦@amnesty⁩ https://www.amnesty.org/...
  • @billmarczak Bill Marczak on x
    DataUsage.sqlite is a file in an iTunes backup that records process names accessing the mobile data, as well as bytes uploaded and downloaded. Information can persist in here for *years* unless cleaned up. So, in around 2019, NSO Group decided to try their hand at cleaning it up.
  • @fbhutto Fatima Bhutto on x
    Hatice Cengiz, Khashoggi's fiance, Umar Khalid, Loujain Hathloul, Father Stan Swamy all had their phones tapped by Israeli NSO spyware #Pegasus. I cannot remember the last time I read a story so chilling. https://www.theguardian.com/ ...
  • @salmansoz Salman Anees Soz on x
    As @rohini_sgh points out, the name of a sitting Indian Supreme Court judge is on this list (name to be disclosed). Should the Supreme Court not seek an explanation from PM Modi? Not for the Supreme Court's sake but for the Constitution of India? For India? #PegasusProject https:…
  • @kathviner Katharine Viner on x
    Viktor Orbán, prime minister of Hungary, using NSO spyware in assault on media, data suggests https://www.theguardian.com/ ...
  • @carolecadwalla Carole Cadwalladr on x
    Great explainer & round-up of global scale of NSO Pegasus leak. Massive database of 50k numbers, journalists & government critics across the world targeted for surveillance. Huge kudos to global collaboration by @FbdnStories & @AmnestyTech inc @guardian team led by @PaulLewis htt…
  • @wcathcart Will Cathcart on x
    Human rights defenders, tech companies and governments must work together to increase security and hold the abusers of spyware accountable. Microsoft was bold in their actions last week https://blogs.microsoft.com/ ...
  • @billmarczak Bill Marczak on x
    Also, (3) as @AmnestyTech observed and we @citizenlab can confirm, NSO Group's Pegasus spyware delivered via 0-click exploits is no longer “persistent” in the strict sense of the word (i.e., doesn't come back when you reboot). Persistence is achieved via firing the 0-click again
  • @rdanielkelemen R. Daniel Kelemen on x
    Must read by @shaunwalker7 on how the Orbán autocracy in Hungarian is hacking phones of investigative journalists and targeting owners of independent media 👇 cc: @VeraJourova https://twitter.com/...
  • @thewire_in @thewire_in on x
    BREAKING | Here's a thread of the #PegasusProject stories we've released tonight. 1. Over 300 verified Indian mobile telephone numbers in a leaked database of thousands believed to have been listed by clients of the NSO Group (that sells Pegasus spyware.) https://thewire.in/...
  • @brettmmurphy Brett Murphy on x
    Last paragraph in this screenshot is terrifying https://twitter.com/...
  • @ericgarland Eric Garland on x
    IT GETS WORSE: Israel's NSO Group also sold surveillance tech to pro-Putin dictator Viktor Orban in Hungary for the harassment of journalists. https://www.theguardian.com/ ...
  • @crubiomartinezu Carlos Rubio on x
    I was the victim of the spyware, and ended up running from Dominican Republic to USA, and even in the US, the Dominican Republic Government, leaked to narco traffickers my location in the USA. Had to move a few times. https://twitter.com/...
  • @noupside Renee DiResta on x
    So just to be clear: social media had major impact here in a foundational sense. And as COVID took off, the anti-vax apparatus - Groups, Pages, etc- and its affinity circles pivoted to denigrating the COVID vaccine. We have been documenting how at https://viralityproject.org/
  • @evacide Eva on x
    This is a really important story and I suggest that everyone read it, but this headline is cringe. “Military-grade spyware” is not a thing. https://twitter.com/...
  • @wcathcart Will Cathcart on x
    We need more companies, and, critically, governments, to take steps to hold NSO Group accountable. Once again, we urge a global moratorium on the use of unaccountable surveillance technology now. It's past time.
  • @dangillmor Dan Gillmor on x
    WashPost has key “takeaways” from a great global journalistic collaboration — exposing, in more detail than before, the rancid operations of the world's most notorious spyware company. https://www.washingtonpost.com/ ... But read it all. Chilling, dangerous, and infuriating.
  • @cyalm Cyril Almeida on x
    Pegasus spyware gives NSO clients complete device access and thereby the ability to bypass even encrypted messaging apps like Signal, WhatsApp and Telegram. Pegasus can be activated at will until the device is shut off. As soon as it's powered back on, the phone can be reinfected…
  • @marietjeschaake Marietje Schaake on x
    Read this thread and research about the targets of NSO Group's spyware. Spoiler: it's ugly! I hope this straw breaks the camel's back of the complete reluctance to stop these toxic, private, high-tech intelligence services ↘️ https://twitter.com/...
  • @jslaternyc Joanna Slater on x
    Among those targeted by NSO Group's Pegasus spyware: the fiancee of murdered columnist Jamal Khashoggi. Her phone was compromised days after he was killed, forensic analysis showed. 7/ https://www.washingtonpost.com/ ...
  • @camillefrancois @camillefrancois on x
    🚨 The #PegasusProject stories coming out today are a must read for anybody who cares about technology and human rights. Remarkable work from @FbdnStories, @amnesty @citizenlab and all orgs involved in this massive, global, complex investigation. 🗞 https://www.washingtonpost.com/ …
  • @noupside Renee DiResta on x
    But, Facebook *did improve*. And now, despite the focus on the Disinformation Dozen, perhaps the largest amplifier of COVID health misinfo has been figures like MTG & Tucker Carlson. Media. Politicians with huge platforms. That must be emphasized.
  • @khalafroula Roula Khalaf on x
    Press freedoms are vital, and any unlawful state interference or surveillance of journalists is unacceptable. FT editor among 180 journalists identified by clients of spyware firm https://www.theguardian.com/ ...
  • @arvindgunasekar Arvind Gunasekar on x
    Govt cannot deny the fact that phones of Indian citizens were hacked by Pegasus through WhatsApp. This was Cert-in (under MeiTY) ‘Vulnerability Notes’ dated May 2019 on WhatsApp-Pegasus. In Oct 2019, WhatsApp sued NSO in US court for “surveillance of specific WhatsApp users”. htt…
  • @billbrowder Bill Browder on x
    A number of journalists I have dealt with on Magnitsky case among the 180 journalists identified by clients of spyware firm. They include ⁦@bradleyhope⁩ ⁦@Khadija_Ismayil⁩ & many others. The firm supplying this spyware should face consequences https://www.theguardian.com/ ...
  • @drewharwell Drew Harwell on x
    @SallyBuzbee @FbdnStories @guardian @lemondefr @SZ @OCCRP @thewire_in @zeitonline @direkt36 @haaretzcom @AristeguiOnline @radiofrance @proceso @Knack @Daraj_media @lesoir @frontlinepbs How @AmnestyTech found Pegasus. Huge breakthrough. Their forensic analyses discovered traces of…
  • @brhodes Ben Rhodes on x
    I talked to @panyiszabolcs - a terrific journalist - for After the Fall. Here was my impression after that conversation: https://twitter.com/... https://twitter.com/...
  • @utwitily @utwitily on x
    Haha wow that's wild Oh well I'm sure someone is going to face some consequences for this, let's just wait https://twitter.com/... https://twitter.com/...
  • @occrp @occrp on x
    Loved ones and colleagues of Washington Post columnist Jamal Khashoggi had their phones compromised with NSO Group software both before and after Khashoggi's 2018 killing. Read the full story in @washingtonpost, one of 17 reporting partners in the #PegasusProject 👇 https://twitte…
  • @milanv Milan Vaishnav on x
    “The minister first moved the meeting..at the last moment, then switched off his phone & told Varadarajan to do the same Then “the two phones were put in a room and music was put on in that room..and I thought: ‘Boy, this guy is really paranoid. But maybe he was being sensible’” …
  • @alok_bhatt Alok Bhatt on x
    Introducing Govt response - “However, questionnaire sent to GoI indicates that story being crafted is one that is not only bereft of facts but also founded in pre-conceived conclusions. It seems you are trying to play the role of an investigator, prosecutor as well as jury” https…
  • @mihirssharma Mihir Sharma on x
    One of the most important news stories of the year. GoI has denied it has used this spyware. That denial simply doesn't hold up when faced with this leak. https://twitter.com/...
  • @narangvipin Vipin Narang on x
    Government surveillance of journalists and opposition leaders isn't new. What's new is the speed, stealth, and totality of ownage by the Pegasus tool, which requires no user interaction whatsoever. It's like the nuclear weapon of government surveillance. https://twitter.com/...
  • @davidbelle_ David Belle on x
    You journos are brave. After the Panama Files I would have done this anon. https://twitter.com/...
  • @josephmenn Joseph Menn on x
    The most important work to date exposing spyware vendor NSO's role in spying on human rights advocates, journalists and politicians in countries around the world. https://twitter.com/...
  • @ihackbanme Zuk on x
    [Important thread 1/N]: Let that sink in for a second: almost all respected publications were under espionage. All the sources of journalists, were exposed. If you ever spoke to a journalist (even with “Signal"/"Whatsapp") you are exposed. THIS IS A MAJOR THREAT TO DEMOCRACY! htt…
  • @anthony @anthony on x
    Human rights activists, journalists and lawyers across the world have been targeted by authoritarian governments using hacking software sold by the Israeli surveillance company NSO Group, according to an investigation into a massive data leak https://www.theguardian.com/ ...
  • @gargirawat Gargi Rawat on x
    FT editor among 180 journalists identified by clients of spyware firm | Surveillance | ‘Among the journalists confirmed by analysis to have been hacked by Pegasus were Siddharth Varadarajan and Paranjoy Guha Thakurta’ #Pegasus https://www.theguardian.com/ ...
  • @moonofa @moonofa on x
    “Other prominent journalists whose phones were selected by NSO's clients include Gregg Carlstrom, a Middle East reporter at the Economist, whose Egyptian and Qatari phone numbers were selected as possible targets by an NSO client, believed to the UAE. ” https://twitter.com/...
  • @abuhilalah @abuhilalah on x
    I am one of them too! https://twitter.com/...
  • @snowden Edward Snowden on x
    HUGE: Israel's NSO group has repeatedly denied having had anything to do with Khashoggi's killing — but astonishing new evidence confirms the phones of the central women in his life were hacked right around his murder. https://twitter.com/...
  • @pwnallthethings @pwnallthethings on x
    @amnesty Special kudos to them publishing model as well as version details; turns out to be important when reasoning about the robustness of certain platform security features. https://twitter.com/...
  • @pranavdixit @pranavdixit on x
    This is *very* concerning. Apple routinely markets iPhones, especially the ones running the latest versions of their operating system, as more secure than Android devices, which more often than not, run outdated software. https://twitter.com/...
  • @billmarczak Bill Marczak on x
    @AmnestyTech (1) @AmnestyTech saw an iOS 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. We at @citizenlab also saw 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. All this indicates that NSO Group can break into the latest iPho…
  • @ryanaraine Ryan Naraine on x
    Reacting to iOS zero-days: Apple said: “Security researchers agree iPhone is the safest, most secure consumer mobile device on the market.”
  • @juanandres_gs J. A. Guerrero-Saade on x
    Unbelievable work by @AmnestyTech, done in spite of @Apple's reticence to provide means to verify the integrity of iOS devices. What's it going to take for Apple to stop burying its head in the sand? https://twitter.com/...
  • @datadrivenmd Jorge A. Caballero on x
    ⚠️ This tells me we're just seeing the tip of the iceberg. NSO seems to have found some kind of authentication flaw in iCloud's content-sharing processes. There's something about the way that Apple shares content across accounts that's being exploited https://www.amnesty.org/... …
  • @evacide Eva on x
    Tools like Pegasus are a win/win for authoritarians. For a while, they get to spy covertly on their enemies. And if they get caught, it's just one big advertisement for how omniscient and omnipotent they are.
  • @datadrivenmd Jorge A. Caballero on x
    Devs out there will appreciate how clever this is: “Again, after a successful exploitation, crash reporting was disabled by writing a com[.]apple[.]CrashReporter[.]plist file to the device.” https://www.amnesty.org/...
  • @matthew_d_green Matthew Green on x
    Regardless of what you name it, what kind of idiots give such a recognizable name to a process that might be logged by iPhone telemetry?
  • @ayleighk Kayleigh E. Long on x
    “All this indicates that NSO Group can break into the latest iPhones.” https://twitter.com/...
  • @byron_wan Byron Wan on x
    In this report, Amnesty International shares its methodology and publishes an open-source mobile forensics tool and detailed technical indicators, in order to assist information security researchers and civil society with detecting and responding to 1/n https://www.amnesty.org/..…
  • @ihackbanme Zuk on x
    @ShaneHuntley Even if we stop them, what stops governments developing their own tools abusing it in a similar way? So it's not really up to governments, it's up to Google and Apple to change the model. Identifying NSO is actually easy. (HINT: open up the sandbox, at least on mana…
  • @emilybell Emily Bell on x
    Thread - your iPhone is not secure... https://twitter.com/...
  • @i0n1c Stefan Esser on x
    With PEGASUS in the news again. Never forget that behind closed doors people will tell you that when PEGASUS was found the first time in the wild Apple forbid researchers to put the samples in the public and they complied because they were scared for their app(s) in the @AppStore
  • @patrickwardle Patrick Wardle on x
    Reminder that your iPhone can be remotely hacked ...& attackers can leverage your device's security/privacy to their benefit. 😥 Examples: 🎯 Invisibly deliver exploits (e.g. protected by iMsg's E2E encryption) 🙈 Remain undetected on device (as iOS prevents introspection) https://t…
  • @matthew_d_green Matthew Green on x
    The thing that makes identifying NSO hard is that iMessage is encrypted, and Apple doesn't want to upload every suspicious payload for privacy reasons (but also I think because they don't even have the infrastructure to do so.) https://twitter.com/...
  • @datadrivenmd Jorge A. Caballero on x
    🔥 Cyber/InfoSec/NatSec folks: This. Whole. Thread. 👀⤵️ https://twitter.com/...
  • @billmarczak Bill Marczak on x
    (2): @AmnestyTech also found that after @citizenlab's Dec 2020 report mentioning the zero-click hacking of Al Jazeera, NSO Group switched to Amazon's CloudFront to deliver exploits (lololol). @AmnestyTech reported this to Amazon, who took action to try and block the activity. htt…
  • @ndtv @ndtv on x
    Government of India's response to inquiries on the ‘#Pegasus Project’ media report. https://twitter.com/...
  • @evawolfangel Eva Wolfangel on x
    #NSO Group can break into the latest iPhones. 😳 (thread with more interesting facts from @citizenlab) https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    Time to reboot our iPhones I guess.
  • @evacide Eva on x
    India insists that any spying they may or may not have done using Pegasus was nice and legal. https://twitter.com/...
  • @jasonhaw_ Jason Haw on x
    Of all the Pegasus news articles in the past 24 hours, this is probably the most disappointing because Apple likes to tout they have the most secure smartphones - the iPhone's security features are basically a dud against Pegasus https://www.washingtonpost.com/ ...
  • @matthew_d_green Matthew Green on x
    I sympathize with Ivan here. Imagine building up Apple's security for years and doing a great job, then finding out you also have to deal with the worst people, willing to spend infinite money on bespoke exploits — so they can murder journalists. https://twitter.com/...
  • @mweissenstein Michael Weissenstein on x
    Government spyware from Israel's NSO Group has been able to gather emails, call records, social media posts, passwords, contacts, images, sound recordings, browsing and geolocation data on new iPhones despite Apple's self-promotion of devices' privacy. https://www.washingtonpost.…
  • @chasingcrumbs Courtney Kan on x
    The Pegasus Project | Forensic examinations found evidence of attempted or successful hacks against 34 iPhones. Of those, 23 showed signs of successful infection, and 11 showed signs of attempted penetrations. https://www.washingtonpost.com/ ...
  • @matthew_d_green Matthew Green on x
    Good new article in the NSO series. This one talks more about the technical impact of Pegasus exploitation and what it means for Apple. https://www.washingtonpost.com/ ...