There's obviously money to be made from selling offensive cybersecurity tools to governments. And you can hardly blame governments for buying these services in the age of end-to-end encryption in the hands of every criminal and terrorist.
While I definitely don't condone spying on human rights activists, journalists, or even regular citizens for that matter, pegasus really is a weapon and as such should definitely be heavily regulated.
But as with other types of weapons, the responsibility for its use (or rather misuse) should lie with the weapon's user first and foremost, not the manufacturer. If NSO/HackingTeam were in the business of selling physical weapons to foreign governments, would they have been responsible for a government killing journalists with said weapons? If they were selling to North Korea, sure. But what about the legitimate governments of stable countries not under sanctions?