New Pegasus spyware abuses identified in Mexico
citizenlab.ca
citizenlab.ca
https://darknetdiaries.com/episode/99/ https://darknetdiaries.com/episode/100/
The gist is that the NSO group is a company that sells malware which they claim is only ever used to catch bad guys, but the podcast makes a pretty compelling case that they know that repressive governments and even companies use it to target journalists and activists.
If you are NSO, you can openly commit computer fraud/abuse and even sell it as a product/service.
Poland's "Law and Justice" regime has apparently used Pegasus to spy on opposition senator Krzysztof Brejza[1] and other opposition politicians[2]
[1] https://news.yahoo.com/ap-exclusive-polish-opposition-senato...
https://techcrunch.com/2022/03/11/europe-pegasus-investigati...
https://www.theverge.com/2021/12/27/22855390/poland-pegasus-...
[2] https://www.theguardian.com/world/2022/feb/17/more-polish-op...
https://democratic-europe.eu/2022/01/18/citizen-lab-there-is...
NSO, NSA, MI5... boys like their toys and can hardly help themselves.
And cyber-weapons - which are persistent, portable, infinitely reprodicble at zero cost, reusable, indiscriminate and liable to blowback - will always fall into the hands of assholes, common or garden thugs and bullies. There is not even the merest possibility of strategic limitation of such knowledge hazards.
So how about stop blaming the spooks. That's a distraction.
What does matter is that the entire ecosystem of "smartphone" technology is compromised to the hilt. And it was built that way to make few extra bucks. Our desperate, suicidal stampede to make ourselves totally dependent on it is the problem.
Digital self defence starts with not sticking your dick in a meat-grinder.
NSO is just a commercial company buying and looking for 0-day exploits, 0-click or 1-click, it doesn't matter. There are probably hundreds of people with knowledge of said 0-days in the company who can turn around and start their own company the next day, or sell the 0-day instructions to 20 other companies
There are definitely many other players in this realm who no one talks about, using the same exact tools and exploits. Just not PR hungry like NSO is
^ The article links to this Catalangate rundown, which has more details on the various exploits involved.
There's a big wiretapping scandal going on Greece since the beginning of August, accompanied by an equally big attempt to cover it up.
What happened is that a Greek MEP discovered that there was an attempt by someone to infect his phone with Predator. Later it was confirmed that he was also being spied upon by the Greek Intelligence Agency during a period that he was running for leader of the 3rd largest party of the country (which he won).
This came as an addition to reports from a journalist that he being targeted by the intelligence agency when they were investigating the scandalous legislation that gave the country's bankers immunity.
The PM had admitted the spying of the MEP stating that "it was lawful, but wrong" and he fired the director of the intelligence agency as well as his nephew that was the director of the PM's office.
It's worth pointing out that the the first piece of legislation passed by the current government was one that transferred the intelligence agency directly under the PM. They also legislated more laxed criteria for the position of the agency's director to fit the profile of a person the PM had already chosen. It's worth pointing out that the PM claims that he didn't know the reason the MEP was being targeted and that he it would be outrageous if he knew.
Relevant news articles:
https://www.bbc.co.uk/news/world-europe-62822366
https://www.nytimes.com/2022/07/27/world/europe/eu-spyware-p...
https://www.theguardian.com/world/2022/aug/07/greek-pm-kyria...
https://www.theguardian.com/world/2022/aug/08/greek-pm-denie...
The problem is NSO, not the tech stack, but I guess this is the tech equivalent of looking for lost keys under the street lamp because that's where the light is.