In regards to the whole NSO thing, I’m completely baffled how their principals and employees are not on a sanctions list and don’t have arrest warrants out for them. Consider how much trouble non-malicious hackers have gotten in for pointing out security holes publicly. What we have here is a company actively conducting espionage against some of the most valuable public companies in the United States. Even more egregious, they are targeting those companies’ customers, illegally.
The parties responsible with sanctions and warrants are their clients.
Lemme see if I can communicate this without committing karmic suicide like the other responder.... putting an Israeli cybersecurity firm on a sanctions list, or issuing arrest warrants, is simply a political non-starter in the US. It would be career suicide for most Congresspeople to take such a position.