//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0251 EDT (UTC-04), Monday 06 July 2026

Contents

9 stories from 40 sources across 33 organizations


KEY JUDGMENTS

Adversary operations are outpacing Western containment mechanisms across nuclear, cyber, and communications domains. At least one party to the June 17 US-Iran Memorandum of Understanding (MOU) will likely characterize the agreement as violated or requiring renegotiation before October 4. Satellite imagery confirms Iran reinforcing tunnels at the undeclared Pickaxe Mountain complex while leaving bombed enrichment sites unrepaired, and Washington's warning to Tehran of Israeli assassination plots against negotiators exposes a US-Israel rift compounding the pressure. Moderate confidence reflects documented construction converging against a framework both parties have incentive to preserve; an International Atomic Energy Agency (IAEA) access demand or congressional challenge would accelerate the timeline.

Additional compromised developer tools will very likely surface within 60 days as researchers map TeamPCP's self-replicating supply chain worms across Node Package Manager (npm) and Python Package Index (PyPI). High confidence rests on the worm's autonomous propagation and existing indicator volume. Google's NetNut proxy botnet takedown removed command infrastructure but left the reseller architecture serving other proxy brands intact. European official communications face compounding penetration: Pegasus infected a European Parliament member investigating spyware abuse, while Russian-linked pranksters used email spoofing to extract intelligence travel plans from Greece's national security adviser, extending a campaign that targeted Lithuania's presidential security adviser days earlier.


IC Technology & Cyber

FBI Warns TeamPCP Compromised Developer Tools in Large-Scale Supply Chain Campaign Targeting Cloud Credentials

BLUF: Additional compromised packages will very likely surface within 60 days, as TeamPCP's self-replicating worms have seeded infections far beyond the four tools named in the FBI alert.

The FBI issued a FBI Liaison Alert System (FLASH) alert on July 2 attributing a large-scale software supply chain campaign to a group it calls TeamPCP, which compromised widely used developer and security tools including Trivy, KICS, LiteLLM, and the Telnyx Python Software Development Kit (SDK) to plant credential-stealing malware in Continuous Integration/Continuous Deployment (CI/CD) pipelines 1. The alert identifies four malware families: CanisterWorm and SANDCLOCK, which harvest AWS, GCP, and Azure credentials along with Kubernetes ServiceAccount tokens and SSH keys, and Mini Shai-Hulud and its Miasma variant, self-replicating worms that spread autonomously across npm and PyPI registries while poisoning configuration files 12. The FBI ties the campaign to exploitation of stale npm maintainer recovery-email domains and flags two GitHub repositories, tpcp-docs and docs-tpcp, created by the worm using stolen credentials 23. The indicator set, drawn from Palo Alto Unit 42 research, lists six IP addresses, 27 file hashes, and four CVEs, and the FBI states TeamPCP has published victim names on a leak site and threatened data disclosure as part of an extortion effort 13.

Analyst Note: Additional compromised packages or registries will very likely surface within the next 60 days as researchers continue mapping TeamPCP's footprint across npm and PyPI. Analytic confidence is high, resting on the worm's demonstrated self-replicating spread mechanism and the volume of indicators Unit 42 has already tied to the group's infrastructure. Organizations that treat this as a closed incident after patching the four named tools will miss downstream infections seeded through the same stale-recovery-email takeover technique. Stolen credentials remain exploitable indefinitely, so exposure will continue accumulating even after initial remediation.

Sources:

1: FLASH-20260702-01: Indicators of Compromise Associated with TeamPCP - FBI/IC3

2: FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials - Security Affairs

3: FBI Warns TeamPCP Hackers Compromise Developer Tools in Large-Scale Supply Chain Attacks - Cyber Security News

FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets - GBHackers

Ransom-ISAC Reveals US Government Entity Paid One Million Dollars to Data Extortion Group Kairos

BLUF: Kairos's million-dollar payday without deploying any encryptor validates pure data-extortion as a viable model and will draw lower-skilled actors toward under-resourced local governments.

Ransom-Information Sharing and Analysis Center (ISAC) published a case study by researcher Rakesh Krishnan, corroborated by The Hacker News and TheNextWeb, reporting that a U.S. government entity paid roughly $1 million in Bitcoin on June 13, 2025 to a group calling itself Kairos after a 28-day negotiation that opened at $3 million 123. Kairos claimed initial access on May 19, 2025 through a brute-force credential attack, listed the victim on its leak site two days later citing over 1.6 million stolen files across 2TB, and has never been linked to a ransomware sample or encryptor 1. Security Affairs' research ties the case to a breach Union County, Ohio disclosed in May 2025, notifying 45,487 residents and employees that Social Security numbers, financial details, fingerprints, and passport data were taken after network access between May 6 and 18, though neither the county nor Kairos has confirmed the link 1. Blockchain tracing found the roughly 9.44 BTC payment split within hours toward exchanges including ByBit, OKX, and a Russian exchange called BELQI 1.

Analyst Note: Kairos's success without any confirmed ransomware capability demonstrates to other data-theft actors that leak-site pressure and staged deadlines can extract seven-figure payments from resource-constrained local governments, a model that lowers the capability threshold for targeting small public-sector entities through the rest of 2026. The unverifiable "proof of deletion" means Union County's exposure risk persists regardless of payment, since exchange-linked funds moving through OKX, ByBit, and a Russian exchange give investigators leads but no enforcement mechanism to compel actual data destruction. Confidence in the significance of this precedent is moderate, resting on a single detailed case reconstruction rather than a broader sample of confirmed copycat incidents.

Sources:

1: U.S. Government Agency Paid $1M to Data Extortion Group Kairos - Security Affairs

2: U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case - The Hacker News

3: US government body paid $1M in data-theft extortion - TheNextWeb

Kairos Ransomware: Data-Extortion Case Study Involving a U.S. Government Entity - Ransom-ISAC

IC Operations & Tradecraft

Google and FBI Disrupt NetNut Residential Proxy Network of Two Million Infected Devices Used by Cybercriminal and Espionage Groups

BLUF: Disrupting Google-hosted Command and Control (C2) degrades NetNut's current infrastructure, but intact reseller and whitelabeling channels make reconstitution by early October likely given durable criminal and espionage demand for residential proxy access.

Google, in coordination with the FBI, Lumen Technologies, and the Shadowserver Foundation, disrupted the NetNut residential proxy network on July 3, disabling Google accounts and services NetNut used for malware command-and-control and triggering an FBI takedown of the netnut.com domain 12. Google Threat Intelligence Group estimates NetNut, also known as Popa, controls at least two million infected devices worldwide, including smart TVs and streaming boxes compromised through trojanized applications and Badbox 2.0 botnet plugins 23. Google Threat Intelligence Group (GTIG) recorded 316 distinct threat clusters using suspected NetNut exit nodes over a single week in June, including both cybercriminal and espionage groups conducting password-spray attacks and masking access to victim environments 23. Google also pushed Play Protect updates to automatically warn users and disable Android applications carrying NetNut SDKs, and it shared technical intelligence on NetNut's SDKs and backend infrastructure with platform providers and law enforcement 3. NetNut's operator is linked to publicly-traded Israeli firm Alarum Technologies, which rented the residential proxies to cybercriminal and espionage groups 1. The action follows Google's disruption of the IPIDEA proxy network in January. NetNut's reseller and whitelabeling program means several other popular residential proxy brands may run on the same botnet 23.

Analyst Note: Google's takedown strips NetNut's Google-hosted command-and-control and Play Protect access but leaves the reseller and whitelabeling architecture intact, and independent researchers will likely document NetNut or a rebranded successor sharing its botnet base operating again by October 4. Confidence in that judgment is moderate, given reporting rests on Google Threat Intelligence Group's own disclosure as the sole primary account, with only secondary amplification from outlets like SecurityWeek and BleepingComputer rather than independent verification. The January IPIDEA precedent shows operators buying replacement capacity from competitors rather than shutting down, and GTIG's own count of 316 threat clusters using NetNut's nodes in one week signals demand deep enough to favor reconstitution over collapse, though simultaneous pressure across infrastructure, domains, and Android distribution from Google, the FBI, Lumen, and Shadowserver together could yet prevent the network's rapid return. Confirmation of a resurfacing would force platform providers and ISPs to treat residential-proxy disruption as requiring sustained, coordinated follow-up rather than one-time takedowns.

Sources:

1: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices - SecurityWeek

2: NetNut proxy network disrupted, 2 million infected devices cut off - BleepingComputer

3: Google's Continued Disruption of Malicious Residential Proxy Networks - Google Cloud Blog (Threat Intelligence Group)

US Officials Warned Iran That Israel Plotted to Assassinate Foreign Minister and Parliament Speaker During Ceasefire Talks

BLUF: Washington's decision to warn Tehran of a suspected Israeli assassination plot against its own negotiators signals that preserving the Iran diplomatic channel now takes operational priority over US-Israeli intelligence coordination.

The New York Times first reported that US officials feared Israel might assassinate Iranian Foreign Minister Abbas Araghchi or Parliament Speaker Mohammad Bagher Ghalibaf during ceasefire negotiations this spring, prompting Washington to relay warnings to Tehran through regional intermediaries 12. Two US officials independently confirmed the account to CNN, saying there was no immediate indication that US intelligence had identified a specific plot behind the warning, while noting Israel's defense minister has spoken publicly about wanting to kill senior Iranian leaders 1. Arab News, citing the Times, reported that Iran tightened security around its delegation and secured Pakistani fighter-jet escorts for an April 12 trip to Islamabad for talks with US Vice President JD Vance; Ghalibaf's return flight made an emergency landing in Mashhad after Iranian security services warned of Israeli aircraft in Iranian airspace, and the delegation continued to Tehran by land 2. The Israeli Prime Minister's Office called the report "fake news" and "a complete fabrication of reality," and an Israeli embassy spokeswoman in Washington declined to comment 1.

Analyst Note: The episode exposes a rift between Washington and Jerusalem over Iran policy, with US officials warning Tehran of a suspected Israeli threat to its negotiators rather than deferring to Israel's targeting campaign, showing the negotiating channel now outweighs solidarity with Israel's stated ambitions against Iranian leadership. Israel's blanket denial sits against corroborated defensive measures, including Pakistani fighter-jet escorts and Ghalibaf's diverted return flight, tradecraft details absent from earlier reporting even as Israel's response hardened from silence into explicit denial. The underlying facts of any plot remain unconfirmed, and Iranian security measures may instead reflect residual threat perception from earlier Israeli strikes rather than a new targeting decision. Sourcing rests on a single New York Times original account, with CNN and Arab News amplifying rather than independently corroborating. The disclosure hands Iran a public argument that Israel is straining the ceasefire framework.

Sources:

1: US officials attempted to warn Iran of fears that Israel would assassinate mediators - CNN/KRDO

2: US asked regional allies to warn Iran of Israeli plot to kill negotiators: report - Arab News

U.S. Believed Israel Was Plotting to Kill Iranian Negotiators - The New York Times

Prior Reporting - [The Secret Assassination Alert: United States Warned Iran of Mid Negotiation Israeli Strike Targeting Araghchi and Ghalibaf](https://www.jfeed.com/news-world/us-warned-iran-israeli-assassination-plot) (2026-07-02) - [US officials attempted to warn Iran of fears that Israel would assassinate mediators](https://www.cnn.com/2026/07/03/politics/assassination-warning-us-israel-iran) (2026-07-03) - [US feared plot to kill Iranian negotiators – NYT](https://www.rt.com/news/642546-iran-us-israel-ghalibaf/) (2026-07-03)

Adversary Intelligence

Satellite Imagery Shows Iran Resumes Construction at Pickaxe Mountain Nuclear Tunnel Complex in Apparent Violation of MOU

BLUF: Iran's decision to reinforce an undeclared, IAEA-inaccessible tunnel complex while leaving damaged enrichment sites untouched signals a concealment priority that will stress the MOU well before any overt enrichment breach does.

Satellite imagery collected by Vantor Tech in late June and analyzed by the Institute for Science and International Security shows vehicles and construction crews reinforcing tunnel entrances at Iran's Pickaxe Mountain complex near Natanz, activity Institute for Science and International Security (ISIS) says is inconsistent with the June 17 US-Iran memorandum of understanding requiring Iran to maintain the status quo at nuclear-related sites 12. ISIS senior fellow Spencer Faragasso said the western tunnel portals show ongoing vehicle activity and hardening work, while the eastern portals remain partially backfilled with dirt, and a smaller internal tunnel complex has been fully sealed with its contents unknown 23; Faragasso assessed the complex is likely large enough to hold an enrichment plant 3. The same imagery found no repair activity at Natanz, Fordow, or Isfahan, the three sites damaged in the June 2025 US-Israeli strikes, with tunnel entrances still sealed or backfilled and Fordow's approach roads blocked by earthen defensive mounds installed in May 13. The IAEA has not been granted access to Pickaxe Mountain and, per Fox News, declined to say in late June whether it would seek entry 3. Iran has restored access to 50 of 69 tunnel entrances across 18 underground missile facilities damaged in the conflict 1.

Analyst Note: Iran's satellite-documented reinforcement of tunnel entrances at Pickaxe Mountain contrasts sharply with the absence of any repair activity at Natanz, Fordow, or Isfahan, indicating Tehran is investing in an undeclared, IAEA-inaccessible facility rather than restoring known enrichment infrastructure. The fully sealed internal tunnel complex, contents unconfirmed, sits alongside continued IAEA access denial, compounding uncertainty about whether relocated enrichment-related material is being stored there. A US or Israeli military strike against Iranian nuclear facilities, including Pickaxe Mountain, is unlikely within the next 90 days. Moderate confidence reflects the absence of any observable pre-strike indicator in current reporting: the MOU remains nominally in force, no enrichment escalation is detected at known sites, and the three damaged facilities show no repair activity suggesting Iran is racing to reconstitute. Parallel restoration of 50 of 69 missile tunnel entrances signals a broader reconstitution posture that extends beyond the nuclear file, but none of the sequential preconditions for an escalation to kinetic action has activated.

Sources:

1: Satellite Imagery Shows Construction Resumes at Irans Pickaxe Mountain Nuclear Tunnel Complex - The Defense News

2: Recent satellite imagery from late June 2026 of Natanz and Pickaxe Mountain - Institute for Science and International Security

3: Experts warn Pickaxe Mountain nuclear site could be used to build atomic weapon - Fox News

Satellite images show Iran reconstructing Pickaxe Mountain tunnel complex, in apparent MOU violation - The Times of Israel

What Is Iran Building Now in the Zagros Mountains? - RedState

Satellite imagery shows continued work at Iran's Pickaxe Mountain site - Iran International

Syria Arrests Former Military Intelligence General Who Headed Qamishli Branch and Transferred Detainees to Palestine Branch

BLUF: Damascus's accelerating roundup of mid-tier Assad security officials signals a methodical campaign driven by internal target lists, laying groundwork for accountability proceedings that double as political consolidation.

Syria's Interior Ministry announced Friday the arrest of former Major General Ali Saleh Dhiab, who headed the military intelligence (also rendered military security) branch in Qamishli from 2008 to 2018 12. The ministry said internal security forces carried out a "special security operation" based on surveillance and intelligence gathering, and described Dhiab as a prominent officer in the former government's security apparatus with close ties to senior Assad-era commanders 12. According to the ministry's initial investigations, Dhiab pursued and arrested large numbers of young men in Hasakah province and Qamishli before transferring many to the Palestine Branch and Saydnaya military prison 12. The New Arab reported the arrest follows the Interior Ministry's recent detentions of Adnan Riyad Hamada in Damascus countryside and former Republican Guard Brigadier General Youssef Habib in Aleppo 2.

Analyst Note: Damascus's arrest of Dhiab, who ran Hasakah and Qamishli detentions before feeding detainees into the Palestine Branch and Saydnaya pipeline, extends a pattern following the Hamada and Habib arrests suggesting the Interior Ministry is working a target list built from surveillance and internal security records rather than isolated tips. Sourcing rests on a single Syrian Arab News Agency (SANA) account, with Anadolu and The New Arab repackaging the same Interior Ministry statement without independent corroboration. The documented transfer trail hands the new administration evidentiary material for accountability proceedings, though the announcement may serve as much to burnish the government's transitional-justice credentials to domestic and international audiences as to reflect a purely investigative operation.

Sources:

1: Syria arrests former Assad-era military intelligence general - Anadolu Agency

2: Assad-era military security official arrested in Syria - The New Arab

Deposed regime's military intelligence chief in Qamishli arrested in al-Hasakah - SANA (Syrian Arab News Agency)

Allied Intelligence

German Defense Minister Calls to Exclude AfD-Led States from Federal Intelligence Sharing Over Alleged Moscow Ties

BLUF: Berlin's exclusion threat carries more pre-election signaling value than operational weight, since the Alternative for Germany (AfD) remains very unlikely to capture the Saxony-Anhalt governorship in September 2026 (low confidence).

German Defense Minister Boris Pistorius said in a Bild am Sonntag interview that Berlin is "intensively examining" who should retain access to classified information, and stated flatly that no such information will go to AfD officials should the party enter a state government 123. Pistorius cited AfD's "undeniable" closeness to Putin and said suspicions of Russian money flowing to the party are "in the room" 23. The remarks follow the AfD's party congress in Erfurt; t-online noted the practical trigger: Saxony-Anhalt hosts several Bundeswehr sites, and a state election in September could hand the AfD the governor's office, giving it a seat on the Bundesrat with access to federal classified material 2. Handelsblatt reported that Green Bundestag intelligence-oversight committee vice chair Konstantin von Notz backed the warning, calling the AfD "the parliamentary arm of Moscow in Germany" and warning of a real risk of highly sensitive data reaching "a dictatorial regime hostile to us"; von Notz called for the National Security Council to take up the issue and cited Austria's precedent, where data on more than 30,000 security-agency personnel was allegedly passed to Russia after a far-right party entered government 3.

Analyst Note: Pistorius's exclusion threat previews a federalism fight that Berlin cannot easily win through defense-ministry channels alone, since Bundesrat access rights for state governors flow from the Basic Law rather than ministerial discretion. The AfD is very unlikely to actually capture the Saxony-Anhalt governorship in the September 2026 election and trigger this scenario. Low confidence in this assessment reflects the absence of current public polling in the reporting and the party's strong but historically non-winning performance in prior eastern German state elections: Thuringia's 2024 election delivered AfD a plurality, yet the remaining parties formed a minority government rather than concede the seat. Pistorius's remarks function now as a pressure tactic shaping the pre-election narrative rather than a policy Berlin expects to implement.

Sources:

1: Berlin wants to withhold classified info from states ruled by opposition - Pravda EN

2: Pistorius: Keine Geheiminformationen an AfD-Minister - t-online

3: Erfurt: Nach AfD-Parteitag: Pistorius will AfD keine geheimen Informationen geben - Handelsblatt

German defense chief opposes sharing intel with AfD ministers - Politico EU

Russian Intelligence-Linked Pranksters Penetrate Greek National Security Adviser Communications via Social Engineering

BLUF: Athens' insistence on an "advanced AI" breach narrative obscures the actual failure, a lack of basic contact verification protocols that handed Moscow a low-cost window into Greek pre-election political calculations.

Russian pranksters Vovan and Lexus published a recorded video call in which Greek National Security Adviser Thanos Dokos believed he was speaking with Ukrainian presidential security aide Rustem Umerov, discussing the timing of upcoming Greek elections, a mission by the National Intelligence Service (Greece) (EYP) intelligence chief to Kyiv, and the risk of another Ukrainian drone incident near Lefkada during tourist season 12. Prankster Vladimir Kuznetsov said the ruse began with a simple email exchange, disputing the Greek government's account that the incident was a "hybrid attack" carried out with advanced artificial intelligence that breached security protocols 3. Greek officials said no classified information was disclosed and noted similar hoaxes have targeted other senior European officials 34. Opposition parties including Panhellenic Socialist Movement (PASOK), Coalition of the Radical Left (SYRIZA) and the Communist Party of Greece (KKE) called for Dokos' resignation over the breach 124.

Analyst Note: The breach exposes Athens's pre-election vulnerability to Russian-linked social engineering rather than a technical intrusion; Dokos disclosed election timing, an EYP director's Kyiv mission, and drone-incident anxieties to callers he believed were Ukrainian counterparts, handing Moscow insight into Greek political calculations independent of any classified material. The government's "advanced AI" framing looks like defensive posturing against a simpler failure: basic verification protocols for incoming official contacts. Whether Dokos leaves office in the coming two months is genuinely uncertain, since opposition pressure lacks any procedural lever absent coalition defections that current reporting does not show forming. Confidence in this judgment is low, resting on a single primary account with no independent corroboration of internal government deliberations.

Sources:

1: Greek Security Chief Duped by Russian Pranksters; Opposition Demands Resignation - Greek Reporter

2: Greek PM's Security Advisor Duped by Russian Pranksters - To Vima

3: Russian Pranksters Target Greek National Security Adviser - Greek City Times

4: National Security Advisor of Greek PM falls victim to Russian pranksters (Video) - Keep Talking Greece

Russian pranksters published conversation with Th. Dokos: elections in the coming months - Sigmalive

Prior Reporting - [Lithuanian presidents adviser targeted by fake Ukrainian official call, suspects Kremlin](https://www.lrt.lt/en/news-in-english/19/2978098/lithuanian-president-s-adviser-targeted-by-fake-ukrainian-official-call-suspects-kremlin) (2026-07-02) - [Kremlin pranksters posed as Umerov in a conversation with an adviser to the Lithuanian president](https://news.liga.net/en/politics/news/kremlin-pranksters-posed-as-umerov-in-a-conversation-with-an-adviser-to-the-lithuanian-president) (2026-07-02) - [Lithuanian President's Advisor Falls Victim to Russian Pranksters](https://nashaniva.com/en/398991) (2026-07-01) - [Matulionis: tai buvo Rusijos tarnybų provokacija](https://kauno.diena.lt/naujienos/lietuva/politika/matulionis-tai-buvo-rusijos-tarnybu-provokacija-1763829) (2026-07-01) - [Matulionis tapo pokštininkų „Vovan ir Lexus" taikiniu: manau, tai Rusijos tarnybų bandymai](https://www.lrt.lt/naujienos/lietuvoje/2/2977276/matulionis-tapo-pokstininku-vovan-ir-lexus-taikiniu-manau-tai-rusijos-tarnybu-bandymai) (2026-07-01)

IC Technology & Surveillance

Citizen Lab Confirms Pegasus Spyware Infected EU Parliament Member Investigating Spyware Abuse

BLUF: Confirmed Pegasus infections of a sitting European Parliament Committee of Inquiry to Investigate the Use of Pegasus and Equivalent Surveillance Spyware (PEGA) Committee member's device mean spyware operators had real-time visibility into the EU body designed to regulate them, functionally neutralizing its oversight capacity.

Citizen Lab found that the iPhone of former Greek Member of the European Parliament (MEP) Stelios Kouloglou was infected with Pegasus spyware twice, on October 21, 2022 and March 6-7, 2023, both via the zero-click "PWNYOURHOME" exploit delivered through Apple's HomeKit 12. Kouloglou served on the European Parliament's PEGA Committee, formed in 2022 to investigate Pegasus abuse in the EU; the first intrusion hit while he was hospitalized in Athens days before major PEGA hearings on spyware, and the second struck during final drafting of the committee's report while he was in Brussels 2. Apple sent Kouloglou three separate threat notifications, in March 2023, August 2023, and April 2024, months after each intrusion, and Citizen Lab found no evidence implicating the Greek government while linking the likely operator to a campaign that also targeted Russian and Belarusian-speaking opposition figures elsewhere in Europe 2. Citizen Lab said the intrusions could have exposed confidential PEGA Committee communications and Kouloglou's medical information, including to parties under the committee's own investigation 2.

Analyst Note: Citizen Lab's forensic report, the sole primary source behind multi-outlet pickup, shows spyware operators reached inside the very committee built to constrain them, exposing PEGA deliberations, member sources, and Kouloglou's medical records to parties the panel was investigating. Failure to attribute the intrusions leaves Parliament's oversight mechanism without a target for accountability even as its findings gain credibility, and a detection lag of months between each intrusion and Apple's notification suggests other targeted parliamentarians may remain unaware absent forensic review. A Pegasus client government other than Greece, rather than Athens itself, more plausibly sits behind the operation, monitoring the body probing its own conduct. The disclosure has already prompted PEGA member Hannah Neumann to demand a formal European Parliament investigation into the breaches.

Sources:

1: European Parliament Member Investigating Spyware Was Hacked With Pegasus - The Hacker News

2: EU lawmaker investigating surveillance hacked by Israeli spyware, report says - Al Jazeera

Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab

Prior Reporting - [Frühere Staatstrojaner-Untersuchungen der EU: Ausschussmitglied mehrfach mit Pegasus-Software infiziert](https://netzpolitik.org/2026/fruehere-staatstrojaner-untersuchungen-der-eu-ausschussmitglied-mehrfach-mit-pegasus-software-infiziert/) (2026-07-03) - [Spyware found on phone of European Parliament member probing it](https://therecord.media/pegasus-spyware-european-parliament-pega-committee-member) (2026-07-03) - [Politician who investigated spyware abuses had his phone hacked with Pegasus spyware](https://techcrunch.com/2026/07/02/politician-who-investigated-spyware-abuses-had-his-phone-hacked-with-pegasus-spyware/) (2026-07-02)

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE