PrivacySignal
News

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

CyberScoop · · US Federal · Surveillance & Civil Liberties

Citizen Lab has confirmed the first Pegasus infection of 2026, found on devices belonging to Serbian activists. The SHARE Foundation described the campaign, which also involves a NoviSpy variant, as the largest wave of spyware surveillance targeting Serbia to date.

Why this matters: Pegasus does not end up on an activist's phone by accident. Someone with access to very expensive, tightly controlled surveillance software made a deliberate choice to use it against civil society. Serbia has been in Citizen Lab's sights before. This latest wave suggests the targeting is getting broader, not narrower. When spyware scales up against activists, it tends to follow: journalists, lawyers, opposition figures, anyone inconvenient. The tool is the same. Only the target list changes.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

News
EFF — Deeplinks · · International

Judge Rules DOD Unlawfully Retaliated Against Anthropic

A federal judge ruled that the Department of Defense unlawfully retaliated against Anthropic after the AI company refused to allow its technology to be used for mass surveillance of U.S. citizens. The court found that labeling Anthropic a 'supply chain risk' in response to that refusal violated the First Amendment.

Who should care: Lawyers · Compliance · Privacy officers · Cybersecurity · General readers · AI governance · Policy

#regulation#surveillance#ai#privacy Read original →
News
S Security Boulevard · · International

NYC Bill Seeks to Curb MSG Use of Facial Recognition

A proposed New York City bill would restrict the use of facial recognition technology at Madison Square Garden, the arena that has drawn scrutiny for deploying the technology to identify and exclude individuals from its venues.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →
News
A ABC News & Headlines – Australian Broadcasting Corporation · · International

Facial recognition technology 'scope creep' is upon us, experts warn

Experts are warning that facial recognition technology is expanding beyond its original stated purposes, a pattern known as scope creep. The concern is that systems deployed for one use are quietly being applied in ways the public was never told about.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →
News
EFF — Deeplinks · · International

Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

Five states — Connecticut, Maryland, New Jersey, Oregon, and Virginia — have passed new laws restricting commercial location data practices, marking a measurable shift in how state legislatures are approaching location privacy. A policy analysis finds progress but also identifies gaps that leave enforceable protections incomplete.

Who should care: Lawyers · Compliance · Privacy officers · Cybersecurity · General readers · Policy

#regulation#surveillance#privacy Read original →
News
S securityinformed.com · · International

Facial Recognition Tech By RecFaces At FSIE 2026

RecFaces, a facial recognition technology company, is set to exhibit at the FSIE 2026 security industry event. The appearance signals continued commercial expansion of facial recognition into physical security markets.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →