Live data from Hacker News

US-backed Israeli company's spyware used to target European journalists

apnews.com

411–420 of 450 posts

Re: US-backed Israeli company's spyware used to target European journalists

#411

Earlier quoted context omitted.

The issue isn't the mere existence of spyware companies globally. The issue is that Israeli companies in particular have cornered the market on selling to the world's worst human rights abusers, with catastrophic consequences. Let's be specific: NSO Group sold Pegasus to Saudi Arabia, who used it to track Jamal Khashoggi's inner circle before his assassination. They sold to Mexico, where it was used to target journal…

I wonder how they find extremely talented exploit developers. The exploits they produce probably takes years to develop at minimum

Probably mostly the same way everybody finds extremely talented exploit developers? By bidding for them? Why do people think exploit developers are a strategic resource like rare earth metals? They're probably uniformly distributed across the world --- including in developing countries.

Re: US-backed Israeli company's spyware used to target European journalists

#412

Earlier quoted context omitted.

Not true. Please don't tell falsehoods in HN. The US, EU, UK, and individual countries have all determined no genocide. Moreover, civilian deaths stop in Gaza the moment Hamas surrenders and returns the remaining hostages. Remember, the tech revolution started in the US so have some respect for my country's opinion on the issue. Israel is a large supplier of tech including computer chip design. The unfortunate truth…

> The US, EU, UK, and individual countries have all determined no genocide https://news.un.org/en/story/2024/03/1147976 “Specifically, Israel has committed three acts of genocide with the requisite intent: causing seriously serious bodily or mental harm to members of the group, deliberately inflicting on the group conditions of life calculated to bring about its physical destruction in whole or in part, and imposing…

[dead]

Re: US-backed Israeli company's spyware used to target European journalists

#413

Earlier quoted context omitted.

This debate could continue forever since there's no single measure by which one can quantify how evil a nation is. I will leave our audience to consider the 20th Century and decide for themselves how America compared to Fascist Italy, Nazi Germany, Apartheid South Africa, the USSR, Maoist China, Spain under Franco, Imperial Japan... etc.

"In their moral justification, the argument of the lesser evil has played a prominent role. If you are confronted with two evils, the argument runs, it is your duty to opt for the lesser one, whereas it is irresponsible to refuse to choose altogether. Its weakness has always been that those who choose the lesser evil forget quickly that they chose evil." Crazy how well this Hannah Arendt quote applies to both you and…

'Anti US bias' (that's a direct quote, not a jingoistic insult I throw around) is different than a refusal to choose between evils.

Re: US-backed Israeli company's spyware used to target European journalists

#414

How does the exploit work, though? The article does some real handwaving around "now the device is yours and now it's not". They don't need to go too deep but isn't anyone reading that far into the article going to be curious?

I don't have a full answer for you, but I found some more info in the CitizenLab report [^1] about the incidents.

(Small aside, but CitizenLab is excellent and such a valuable resource)

CitizenLab states the zero-click iMessage attack — CVE-2025-43200 - used as one of the vectors was fixed by Apple in iOS 18.3.1.

Apple has an "About the security content of iOS 18.3.1 and iPadOS 18.3.1" [^2] page, and it contains the following:

---

Messages Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later

Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Description: This issue was addressed with improved checks.

CVE-2025-43200: Apple

---

1: https://citizenlab.ca/2025/06/first-forensic-confirmation-of...

2: https://support.apple.com/en-us/122174

Re: US-backed Israeli company's spyware used to target European journalists

#415
post #319

Earlier quoted context omitted.

You're not gonna find technical details in an AP article of all places. You will find it in CitizenLab's report: https://citizenlab.ca/2025/06/first-forensic-confirmation-of...

There isn’t much technical details there either. They list the servers it connected to and log entry but that’s it. It mentions a CVE number but the apple link is generic and mo details on the CVE database. Has this even been fixed by apple?

I replied to the parent comment with the info I found:

https://news.ycombinator.com/item?id=44274249

Tl;DR: yes, this was resolved in iOS 18.3.1

Re: US-backed Israeli company's spyware used to target European journalists

#416
post #98

Earlier quoted context omitted.

Deploying spyware against journalists in retaliation for their exposing racism in the governing party's youth wing is petty.

Sorry I misunderstood, I thought you were saying Fanpage's actions were petty.

[dead]

Re: US-backed Israeli company's spyware used to target European journalists

#417

This is my irritating reminder that there is a whole marketplace of implant/CNE products, most of which you have never heard of, produced in basically every jurisdiction in the world. It used to be NSO Group that got all the press, now it's Paragon, and I think it's all for the good that the spotlight gets shone on these companies, but do keep in mind that this is not an "Israeli" phenomenon. There are American compa…

The issue isn't the mere existence of spyware companies globally. The issue is that Israeli companies in particular have cornered the market on selling to the world's worst human rights abusers, with catastrophic consequences. Let's be specific: NSO Group sold Pegasus to Saudi Arabia, who used it to track Jamal Khashoggi's inner circle before his assassination. They sold to Mexico, where it was used to target journal…

[deleted]

Re: US-backed Israeli company's spyware used to target European journalists

#418

This is my irritating reminder that there is a whole marketplace of implant/CNE products, most of which you have never heard of, produced in basically every jurisdiction in the world. It used to be NSO Group that got all the press, now it's Paragon, and I think it's all for the good that the spotlight gets shone on these companies, but do keep in mind that this is not an "Israeli" phenomenon. There are American compa…

The issue isn't the mere existence of spyware companies globally. The issue is that Israeli companies in particular have cornered the market on selling to the world's worst human rights abusers, with catastrophic consequences. Let's be specific: NSO Group sold Pegasus to Saudi Arabia, who used it to track Jamal Khashoggi's inner circle before his assassination. They sold to Mexico, where it was used to target journal…

It's not the only market they've cornered.

If you are paying for a VPN, the odds are good that it's owned by Kape Technologies, another Israeli company staffed by former Unit 8200 personnel. PIA and a bunch of others are now under their purview.

They'll say they don't keep logs, but only an idiot would trust that.

Cellebrite also does questionable shit with phone forensics; newer products upload phone images to "the cloud." Supposedly it is instanced and law enforcement is just supposed to trust that yet another function the Justice Department outsources to Israel isn't backdoored by them, like Inslaw/PROMIS.

Re: US-backed Israeli company's spyware used to target European journalists

#419

Earlier quoted context omitted.

I've seen you reference these actors previously. Is there a reason you won't name them? Is this an industry code of silence, or fear of retribution?

There is a reason I won't name them --- the ones I know about, a fraction of the total market --- it's not interesting, and I'm not going to get into it.

I'm interested, and I'm sure I'm not alone. This isn't easily researched information, and it would be nice to have a list of organisations to put on my boycott list. These companies should be named and shamed. They have no positive influence on the world. If they disclosed instead of exploited the vulnerabilities they have knowledge of, they would improve the security of most of the world's population. Instead, they profit from the insecurity of the population. This is criminal behaviour and should be treated as such.

Re: US-backed Israeli company's spyware used to target European journalists

#420

Earlier quoted context omitted.

It’s not a productive label when used like that though.

Is it not? If someone is raised catholic it’s best to assume they’re still catholic unless they disavow catholicism - in which case they are an ex-catholic

Sound like you might be an a-stamp-collector.
Post reply on HN