Overview
- Independent teams from the SHARE Foundation, Citizen Lab and Amnesty International published findings in early September 2026 that confirm a Pegasus infection with high confidence on one iPhone and two infections by a new NoviSpy variant on Android devices.
- Investigators say at least 14 people in Serbia’s civil society — including student movement members, activists, an opposition MP and a local councilor — were targeted in what SHARE calls the largest documented spyware wave in the country.
- Forensics show the Pegasus case used an iMessage zero-click exploit active between December 2025 and January 2026, a vulnerability Apple patched in iOS 18.4.1 and later neutralized for users who installed updates.
- Amnesty and SHARE report that forensic traces and victim accounts point to NoviSpy installs occurring after phones were seized during police questioning, raising allegations of involvement by Serbian police or intelligence services in some cases.
- Rights groups and researchers are urging immediate expert screening for those who received Apple threat notifications, demanding official investigations, remediation for victims, and scrutiny of spyware vendors and state actors ahead of the October parliamentary vote.