More information here: Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. We found high-confidence indicators of infection from a period across December 2025 – January 2026, however this does not preclude the possibility of additional infections. https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/