The Pegasus exploit that hit a Serbian student activist was patched eight months before the infection
2026-09-03Security
Citizen Lab and the SHARE Foundation confirmed an iMessage zero-click delivered Pegasus to a member of Serbia's student protest movement between December 2025 and January 2026. Apple fixed the flaw in iOS 18.4.1, in April 2025. The tool is identified; the operator is not.