BoletimSecSeptember 4, 2026🇵🇹Translated from Portuguese

Pegasus Spyware Returns in Serbian Surveillance Campaign via Zero-Click iMessage Exploit

A member of the Serbian student movement had their iPhone infected with the Pegasus spyware through a zero-click exploit delivered via iMessage, requiring no clicks on links or file openings. The compromise was verified by Citizen Lab working with the SHARE Foundation, with indicators of compromise detected between December 2025 and January 2026.

The target subsequently received an official notification from Apple warning of a possible mercenary spyware attack attempt. Researchers determined that the exploit leveraged iMessage to install Pegasus silently, granting operators access to photos, notes, messages, files, and other stored data on the device.

The spyware could also secretly activate the microphone and camera, significantly expanding surveillance capabilities against individuals of interest. The exploited vulnerability was patched by Apple starting with iOS 18.4.1, released on April 16, 2025, which addressed security flaws used in highly sophisticated attacks against specific targets.

This case is part of an intensified surveillance campaign in Serbia. At least 14 people, including students, activists, a parliament member, and a local political representative, received Apple alerts regarding potential mercenary spyware attacks. Other members of the movement were also targeted with Android spyware variants, including those related to NoviSpy.

Investigations indicate a broader escalation of operations against Serbian civil society members.

Related articles

SecuritylabPrivacy & Surveillance

Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks

Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.

HabrPrivacy & Surveillance

New Obfuscation Method Dissolves Personal Data Records in Layer of Plausible Variants

A Russian information security researcher has proposed a data protection technique that renders stolen personal records unusable even after full compromise. The approach mixes real data such as phone numbers, emails, passports, addresses, INN and SNILS with vast numbers of semantically valid alternatives. Attackers receive nearly complete information including a 361-character message containing PIN codes and word order, yet lack the secret vector space and reconstruction algorithm required to identify the correct record. Without these components, brute-force attempts produce millions of plausible results with no architectural method to verify accuracy. The method is presented as an alternative to traditional encryption when data must remain accessible yet protected against extraction. A public sandbox is available for testing the approach.

HabrPrivacy & Surveillance

Hydrat Project Builds Automated WireGuard Gateway for Resilient VLESS and Tor Routing

A developer has released Hydrat, a self-hosted gateway that connects devices via WireGuard while automatically managing VLESS and Tor backends to survive server blocks and quality degradation. The system maintains a pool of tested proxies, performs continuous health checks, and switches routes without requiring client-side profile changes. Two Go processes handle control logic and network enforcement separately, using SQLite for state and nftables plus Xray for traffic routing. TCP and UDP can be assigned independent exits, with geoip.dat support and custom rules to keep marketplace apps functional. The project emphasizes stability over direct connections and is designed for deployment on servers in Russian jurisdiction.

AntiMalwarePrivacy & Surveillance

OpenAI Contractors Manually Review Real User Chats in Project Lily

OpenAI has engaged hundreds of external contractors to analyze actual user conversations with ChatGPT as part of its model improvement efforts. The reviewers, working under project Lily, examine real queries that may contain personal, medical, or other sensitive information despite the use of a Privacy Filter. Contractors summarize prompts, compare four model responses, and assign ratings from one to seven while flagging behaviors such as excessive sycophancy or inappropriate emojis. User identities are hidden and some data is filtered, yet OpenAI acknowledged that not all personal information is reliably removed. The same human review process is also employed by Anthropic for its Claude model. Users can opt out of future training use through account settings, although prior data remains unaffected.