Daily brief at 7am Melbourne. Unsubscribe any time.

Saturday 4 July 2026

The Spyware Investigator Who Became the Spied-Upon

A European politician was hacked with the exact spyware he was supposed to be investigating — and Citizen Lab has the forensics to prove it.

Lead story

The Spyware Investigator Who Became the Spied-Upon

If you wanted to design the most ironic cyberattack possible, you'd probably land somewhere close to this: hack a lawmaker with commercial spyware while he's sitting on the parliamentary committee investigating commercial spyware.

That's exactly what happened to Stelios Kouloglou, a former member of the European Parliament. Citizen Lab, the University of Toronto-based digital rights research group, has confirmed through forensic analysis of his device that Kouloglou was infected with NSO Group's Pegasus spyware — not once, but twice — while he was actively serving on the PEGA Committee, the EU's dedicated inquiry into spyware abuses.

What is Pegasus, and why does this matter?

Pegasus is a commercial spyware tool sold by Israeli firm NSO Group, marketed exclusively to government customers. It can silently compromise a phone — extracting messages, emails, call logs, location data, contacts, and even activating the microphone and camera — often without the target doing anything at all (so-called "zero-click" attacks). Its use against journalists, dissidents, lawyers, and politicians has been extensively documented since the Pegasus Project reporting in 2021.

The PEGA Committee was the EU's formal response to that reporting. Its mandate: investigate how member states were using tools like Pegasus, whether those uses violated EU law, and what reforms were needed. Kouloglou served on that committee. Someone with access to a government Pegasus licence decided to target him during that period.

Who did it?

Citizen Lab has not publicly attributed the attack to a specific government — that's standard practice until they have high confidence. But Pegasus is sold only to vetted nation-state customers, which means a government actor made a deliberate decision to surveil an EU parliamentarian investigating government surveillance. The circularity is almost too neat to be real.

Kouloglou's response was direct: "It is a direct attack on the rule of law." That framing matters. This isn't just a privacy violation — it's a potential attack on the integrity of a legislative oversight process.

Why it matters beyond the irony

There's a broader pattern here that's worth naming clearly. Commercial spyware vendors have long argued their tools are used only for legitimate law enforcement and national security purposes. The PEGA Committee's own findings told a different story — Pegasus was found on the phones of journalists, lawyers, and opposition politicians in Hungary and elsewhere.

Adding a sitting PEGA Committee member to that list is a data point that's hard to explain away. It also raises uncomfortable questions about whether EU member states are prepared to take meaningful action against a surveillance industry that has now, apparently, turned its tools on their own institutions.

What to watch

NSO Group has been on the US Commerce Department's Entity List since 2021, restricting American companies from doing business with it. The EU has moved more slowly. The PEGA Committee issued recommendations in 2023, but implementation has been patchy. Expect this disclosure to reignite calls for a harder EU-wide ban on commercial spyware procurement.

Australia isn't immune to these questions. The Australian Federal Police's relationship with commercial surveillance vendors has faced scrutiny, and the Attorney-General's Department has been under pressure to clarify the legal framework governing use of spyware against Australian persons. Citizen Lab has previously documented Pegasus infrastructure with links to Australian targets.

This one will have legs.

Also today

Google and FBI Cut Off 2 Million Devices From NetNut Botnet

A joint operation between Google and the FBI has dismantled NetNut, a residential proxy service that was quietly powered by roughly two million compromised Android devices — including smart TVs and streaming boxes. Residential proxy networks are valuable to attackers because traffic routed through them looks like it's coming from ordinary home internet connections, making it harder for defenders and platforms to block. NetNut was selling that cover to cybercriminals and, reportedly, nation-state actors. The takedown also flags a risk for other residential proxy brands that may have been drawing on the same infected device pool. Australian households with budget Android streaming hardware could be among the affected devices.

SecurityWeek

"Bad Epoll" Linux Kernel Flaw Hands Root to Any Unprivileged User

A newly disclosed Linux kernel vulnerability tracked as CVE-2026-46242 — dubbed Bad Epoll — allows an ordinary, unprivileged user to escalate their access to full root control on affected Linux desktops, servers, and Android devices. A patch is available, but the flaw is notable for two reasons: it sits in the same slice of kernel code where Anthropic's AI model recently found a separate bug, and it affects Android, which means billions of devices are technically in scope until carriers and manufacturers ship updates. Linux is the dominant server OS for Australian government and enterprise environments, and patching cadence for Android devices in Australia remains inconsistent across carriers.

The Hacker News

Medtronic Breach: 3.8 Million Patients' Medical Data Stolen

Medical device giant Medtronic has disclosed that ShinyHunters — the prolific ransomware and data extortion group — accessed its corporate IT systems in April and made off with personal and medical information belonging to 3.8 million people. The breach is one of the larger healthcare data incidents of the year and continues a trend of ShinyHunters targeting large institutions with valuable personal data. Medical records are particularly sensitive under Australian law: the Privacy Act and My Health Records Act impose strict handling obligations, and the OAIC takes a dim view of breaches at scale. Organisations with Medtronic devices or systems in their supply chain should verify whether any shared data may be affected.

SecurityWeek

Avalon Malware Framework: One Package, Every Stage of an Attack

Researchers have detailed Avalon, a newly discovered modular malware framework that bundles credential harvesting, lateral movement, remote access, backup disruption, and ransomware into a single, multi-stage phishing-delivered package. The framework, which carries the CrownX ransomware component, is designed to be mix-and-matched by affiliates depending on the target — making it harder to detect through any single indicator of compromise. The modular approach is increasingly common among professional ransomware operations, lowering the skill floor for attackers while raising the ceiling for damage. Defenders should treat any phishing-delivered document with unusual macro or script execution patterns as a potential Avalon precursor.

The Hacker News

North Korea Plants Fake npm Packages in Developer Toolchains

JFrog researchers have linked a fresh set of malicious npm packages to North Korea-affiliated threat actors. The packages — "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" — closely mimic a legitimate Rollup plugin, copying its description, README, and repository metadata to pass a quick visual inspection. Once installed, they enable remote access and data theft from developer machines. Supply chain attacks targeting npm are now a well-established North Korean playbook; what's notable here is the precision of the mimicry. Australian software teams using Rollup-based build pipelines should audit their dependency trees and enforce lockfile integrity checks.

The Hacker News

Critical RCE Flaws Found in Cursor AI Code Editor

Security researchers have disclosed a set of critical vulnerabilities in the Cursor AI code editor — branded DuneSlide — that allow zero-click prompt injection attacks to escape the editor's sandbox and execute arbitrary code at the operating system level. Cursor has become one of the most popular AI-assisted coding tools among professional developers, which makes this a meaningful attack surface: a malicious repository or document opened in the editor could silently compromise the entire developer machine. The flaws have been patched, but given how widely Cursor is used in Australian tech teams and startups, any deployment that hasn't updated recently should be treated as a priority.

SecurityWeek

AI-Hallucinated Report Falsely Tied Startup to Chinese Espionage — Now There's a Lawsuit

A startup called MeetingTV is suing Palo Alto Networks' Koi Security division after an AI-generated threat intelligence report allegedly identified the company as a Chinese espionage front — apparently without factual basis. The case is a sharp illustration of the liability risks attached to AI-generated analytical products, particularly in the high-stakes world of threat intelligence where a false positive can be company-ending. It also raises questions about the disclosure standards applied to AI-assisted reporting in the security industry. Expect this to become a frequently cited case as vendors scramble to define the acceptable use of generative AI in formal intelligence products.

The Register

ARToken PhaaS Gives Researchers a Peek Inside an M365 Phishing Operation

A newly identified phishing-as-a-service platform called ARToken appears to operate as an affiliate of the EvilTokens platform, and its discovery has given researchers an unusually detailed look at the infrastructure behind Microsoft 365 credential theft. The toolkit is built for adversary-in-the-middle phishing — capturing session tokens in real time to bypass multi-factor authentication — and is sophisticated enough to be sold to less technically capable attackers as a subscription service. Microsoft 365 is the dominant productivity suite in Australian enterprise and government, making M365-targeted PhaaS platforms a direct concern for local security teams and SOC analysts.

Bleeping Computer

Aussies Face Lower Cybercrime Risk — But the Burden Is Shifting to SMBs

A new analysis finds that improved regulatory frameworks and institutional investment have meaningfully reduced cybercrime risk for large Australian organisations — but that progress has a shadow side. Pressure and risk are now migrating toward small and medium-sized businesses, which lack the resources to meet increasingly sophisticated threats and are often the weakest link in larger organisations' supply chains. The pattern is consistent with the intent of frameworks like the SOCI Act and the revised Privacy Act, but the SMB sector has largely been left to navigate these obligations without commensurate support. Expect this to become a central tension in the forthcoming refresh of Australia's 2023–2030 Cyber Security Strategy.

Dark Reading

Zuckerberg Admits AI Agents Are Behind Schedule

In an internal all-hands meeting, Meta CEO Mark Zuckerberg reportedly told staff that the company's AI agent development efforts are not progressing as quickly as he had anticipated. The candid admission is notable given Meta's very public bet on agentic AI as a core product and revenue driver — the company has positioned AI agents as eventual replacements for human customer service and business operations. Coming the same week that security researchers demonstrated a fully autonomous AI ransomware attack, Zuckerberg's comment is a reminder that the gap between the threat frontier and the product frontier in agentic AI remains significant and poorly understood even by insiders.

TechCrunch

Anthropic Launches Claude Science, Eyes Drug Development

Anthropic has announced Claude Science, an AI workbench aimed at researchers that integrates fragmented datasets, tools, and visualisation into a single environment. The company says it ultimately wants to use the platform to participate directly in drug development — not just sell tools to pharmaceutical companies, but pursue healthcare interventions of its own. It's an ambitious pivot for a company still best known for its AI safety research and coding assistant, and puts Anthropic in direct competition with the AI-in-drug-discovery plays from Google DeepMind and startups like Recursion Pharmaceuticals. The announcement signals that frontier AI labs increasingly view scientific discovery as a direct business line, not just a capability demonstration.

The Verge

ATO Suffers Mass Work-From-Home Outage — Not Related to DXC Strikes, It Says

The Australian Taxation Office experienced a widespread IT outage affecting remote workers, with staff directed to come into the office if possible while the cause was investigated. The ATO was quick to clarify that the disruption is unrelated to ongoing industrial action at outsourcer DXC Technology, which holds significant government IT contracts. The timing is still awkward: DXC staff have been taking strike action over pay and conditions, and any outage during that period will invite scrutiny regardless of the stated cause. The incident underscores the concentration risk in government IT outsourcing arrangements — a recurring theme in Auditor-General findings on APS technology resilience.

The Mandarin

Sources consulted