The images in this article were generated with artificial intelligence. How we publish
The Canadian Citizen Lab laboratory has once again placed an uncomfortable reality at the heart of public debate: surveillance with commercial espionage tools is not only a technical abstraction, but a real and concrete threat to democratic supervision. According to his report, former European Member Stelios Kouloglou was repeatedly infected with Pegasus spyware while he was part of the European Parliament committee responsible for investigating precisely the use and abuse of these products. The fact that a member of the commission of inquiry is a direct objective of the object of the investigation reveals a serious gap between regulatory theory and operational practice.
Forensic findings indicate infections in October 2022 and March 2023, taking advantage of a zero-click explosion in the implementation of Apple's smart home function, known by researchers such as PWNYOURHOME and corrected in later iOS updates. In addition, the researchers identified operational matches with a previous campaign for journalists and exiled activists in Europe, suggesting that the client who bought the espionage service was authorized to operate in several Member States. This crossing of jurisdictions, which is possible through commercial licences, makes regulatory frameworks that depend only on national borders insufficient..

The case presents several simultaneous lessons. On the one hand, the technical sophistication of these exploits - zero- click, abuse of IoT implementations and threat notifications that are late or not followed by immediate measures - shows that the individual safety of the device is no longer sufficient guarantee. On the other hand, research also highlights another way of risk: telecommunications networks have been exploited by actors who manipulate protocols such as SS7 and Diameter or send SMS messages with hidden commands to convert a phone into a tracker without installing visible malware. Privacy security combines software, hardware and network architecture factors; mitigation requires technical and regulatory intervention.
For legislators and public institutions, the first obligation is to assume the political scope of the problem. It is essential to establish mandatory intrusion notification mechanisms for public offices and commissions of inquiry, to provide Parliament and administrations with independent forensic capacity and clear response procedures, and to review the permits for the use of surveillance technologies. The European Union already has forums and committees on these issues, such as the PEGA committee itself whose work can be consulted on the European Parliament's website, but making incidents public, auditing suppliers and conditioning spyware export licences are steps that need to be accelerated(see general information on PEGA - European Parliament).

For journalists, activists and high-risk officials, digital hygiene must be complemented by institutional policies: to segregate working devices for sensitive deliberations, to implement security updates as soon as they are available, to verify and act on manufacturer threat reports, and to use reputable forensic laboratories when there are signs of commitment. Citizen Lab and other specialized groups have published guides and analysis on how this type of intrusion is detected and mitigated; their work remains accessible in Citizen Lab. Receiving a notification from Apple or another supplier is not a conclusion, but the start of a coordinated response chain.
At the technological level there are specific measures that reduce the attack surface: separate accounts and devices for critical tasks, minimize the exposure of metadata in communications, use hardware security control solutions and verify the supply chain of security providers. Even so, the structural and political lesson is deeper: the existence of digital mercenaries and suppliers who sell capacities to violate fundamental rights requires contractual transparency, licensing, independent audits and effective sanctions against abuse. Apple has published information on its response to vulnerabilities and iOS updates that correct exploited vectors; it is important to verify these updates in the company's official repositories and apply them without delay ( Apple security updates).
Finally, the Kouloglou case illustrates that technology can undermine the capacity of institutions to monitor their own use. If those investigating cannot have safe channels to deliberate, the deterrent effect on institutional research will be profound. Respond requires combining technical measures, legal reforms and political will to control a trade that now operates in a grey area between security and abuse. Meanwhile, citizens and public officials must act quickly: to audit risk devices, demand transparency on spyware contracts and strengthen forensic and incident response capacities to regain confidence in democratic control over these technologies.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...