ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Israeli Spyware Vendor Ordered to Reveal Source Code to Meta

Kyle by Kyle
March 2, 2024
in Malware, Security
Reading Time: 3 mins read
Breaking news on cybersecurity: U.S. court orders NSO Group to reveal source code to Meta amidst ongoing legal battle. Sekoia uncovers new Predator spyware domains.
Share on FacebookShare on Twitter

In a landmark ruling, a U.S. judge has mandated that the NSO Group, an Israeli spyware firm, disclose its source code for Pegasus and other products to Meta. This forms a crucial part of Meta’s ongoing legal battle against the company.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

Meta’s Legal Victory

The court’s decision represents a significant win for Meta, which initiated the lawsuit in October 2019. The social media behemoth accused NSO Group of exploiting its infrastructure to disseminate the spyware to roughly 1,400 mobile devices during April and May. Notably, the victims included two dozen Indian activists and journalists.

The Spyware Attack

The attackers exploited a zero-day vulnerability in the instant messaging app (CVE-2019-3568, CVSS score: 9.8), a severe buffer overflow bug in the voice call feature, to deploy Pegasus. Intriguingly, the spyware could be installed merely by placing a call, even if the recipient did not answer.

Furthermore, the attack sequence incorporated measures to delete the record of the incoming call from the logs, thereby evading detection.

Court Documents Reveal NSO Group’s Obligations

According to court documents unveiled recently, NSO Group has been instructed to “produce information concerning the full functionality of the relevant spyware.” The timeframe specified for this information spans one year before and after the alleged attack, i.e., from April 29, 2018, to May 10, 2020.

However, the company is not required to “provide specific information regarding the server architecture at this time” as WhatsApp “would be able to glean the same information from the full functionality of the alleged spyware.” Importantly, it has been exempted from revealing the identities of its clients.

Reactions to the Court’s Decision

Donncha Ó Cearbhaill, head of the Security Lab at Amnesty International, expressed both satisfaction and disappointment at the court’s decision. He stated, “While the court’s decision is a positive development, it is disappointing that NSO Group will be allowed to continue keeping the identity of its clients, who are responsible for this unlawful targeting, secret.”

NSO Group’s Sanctions

In 2021, the U.S. imposed sanctions on NSO Group for creating and supplying cyber weapons to foreign governments. These tools were maliciously used to target government officials, journalists, businesspeople, activists, academics, and embassy workers.

Meta’s Privacy Controversy

Meanwhile, Meta is under increasing pressure from privacy and consumer groups in the European Union. The company’s “pay or okay” (aka pay or consent) subscription model is being criticized as a choice between paying a “privacy fee” and agreeing to be tracked by the company.

Critics argue that this approach turns privacy into a luxury rather than a fundamental right, reinforcing existing discriminatory exclusion from digital access and control over personal data. They further contend that this practice undermines GDPR.

New Developments in Mobile Spyware

In related news, Recorded Future has disclosed a new multi-tiered delivery infrastructure linked to Predator, a mercenary mobile spyware managed by the Intellexa Alliance.

The infrastructure network is likely associated with Predator customers in countries such as Angola, Armenia, Botswana, Egypt, Indonesia, Kazakhstan, Mongolia, Oman, the Philippines, Saudi Arabia, and Trinidad and Tobago. It’s noteworthy that no Predator customers in Botswana and the Philippines have been identified until now.

“Although Predator operators respond to public reporting by altering certain aspects of their infrastructure, they seem to persist with minimal alterations to their modes of operation; these include consistent spoofing themes and focus on types of organizations, such as news outlets, while adhering to established infrastructure setups,” the company stated.

Sekoia’s Findings on Predator Spyware Ecosystem

In a separate report, Sekoia, a cybersecurity firm, shared its findings on the Predator spyware ecosystem. The company discovered three domains linked to customers in Botswana, Mongolia, and Sudan.

Interestingly, Sekoia noted a “significant increase in the number of generic malicious domains” in its investigation. These domains do not provide any indications about the targeted entities and potential customers, making it challenging to determine the scope and impact of these cyber threats.

Tags: Meta
Previous Post

Lazarus Hackers Exploit Zero-Day Vulnerability in Windows AppLocker

Next Post

Russia’s Latest Stance on VPNs

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.