NEW @citizenlab report:
Member of 🇪🇺 Euro Parliamentary committee (#PEGA) tasked with investigating spyware abuses, @SteliosKoul himself hacked with Pegasus spyware 🔽
https://t.co/JUDWJLrWqQ
Senior researcher @jsrailton spoke with @WIRED about comments from the CEO of spyware company Paragon Solutions revealing that it has no way to know if customers misuse its software, or of meaningfully preventing misuse.
Scott-Railton notes that this is “exactly the opposite of the picture that Paragon has painted for itself for years.”
Read here: https://t.co/xBNxu4ntUd
📢 We’re hiring! Interested in the intersection of law, technology, and human rights? Are you a law student or a graduate student with a law degree?
We’re looking for a research assistant to join the Citizen Lab’s spyware and digital targeted threats team to help maintain our spyware litigation database.
Learn more and apply by Dec 1: https://t.co/5aQiz6GbDO
It is unfortunate and cowardly that 🇨🇦 @GAC_Corporate withdrew their sponsorship of @DisinfoEU conference after 🇺🇸 @StateDept_RBX pressure.
This is not "elbows up".
It is what we call in hockey "turtling," and that's not a compliment
https://t.co/ZVlmHH8eOY
Athens prosecutors have ordered a preliminary investigation into a formal complaint by former MEP and journalist @SteliosKoul that his mobile phone was infected with #spyware.
https://t.co/PkcwkE5F9M
Citizen Lab director @RonDeibert is quoted in @guardian's article about Sheikh Tahnoon bin Zayed Al Nahyan’s increasing influence on AI dominance.
“For the last 20 years, democracy has been in decline,” says Deibert. “That happens to coincide with an enormous expansion of digital surveillance capabilities for both commercial and national security purposes. The epicentre of a lot of this is the UAE. And where do all roads lead in the UAE? They lead to Sheikh Tahnoon.”
https://t.co/GQGxoLRUpK
Oct 8: Join senior researcher Maia Scott at #Disinfo2026. She will be chairing a presentation on elections under attack in France. Learn more: https://t.co/ZWTmaqFwko
New: Through a series of complex agreements with cities, the White House built a massive license plate camera database accessible to the feds. The program aggregates data across license plate companies (Flock, Axon, more) & is searchable by many agencies:
https://t.co/hzrypYgCxX
Journalist and former MEP Stelios Kouloglou has filed a lawsuit against the Israeli executives of NSO Group, the manufacturers of Pegasus spyware
In July 2026, @citizenlab report discovered Stelios' phone had been hacked with Pegasus spyware https://t.co/JUDWJLsugo
BREAKING: @TheJusticeDept arrested US-based Oxygen Forensics CEO for concealing the tech company's Russian ties.
Civil society like @zairbekds & @OlgaNYC1211 have been sounding alarm for years about US law enforcement using this 🇷🇺 company for their sensitive operations! 🧵1/
Like I said, here we have a company creating viruses and malware but gets to market it’s products as machine gods and redirect the narrative away from accountability and being held criminally liable to making themselves sound like concerned citizens, with everyone parroting their CEOs 🙄
1/ Two UN reports citing Citizen Lab submissions have been published this month. The first, from the UN High Commissioner for Human Rights, describes digital risks to human rights defenders.
Read it here: https://t.co/olFSCnwgLb
The Citizen Lab submitted a response to a request for information from the Research Directorate at the Immigration and Refugee Board of Canada on the issue of the connection between state surveillance and repression in China and the Chinese government’s monitoring activity abroad.
Read it here: https://t.co/3NKEUkCu58
Join Citizen Lab director @RonDeibert in Toronto for his keynote speech at SecTor on October 7.
He will be speaking about the Citizen Lab’s decades of work acting as “counterintelligence for civil society.”
Register: https://t.co/n9JtG3nmZN
After reading another brilliant @citizenlab investigation, this time on an Israeli company’s activities in Angola, you can read about Israel’s decades-long security involvement there, as revealed in declassified Foreign Ministry cables. @the7i
https://t.co/CH6jbTYgN8
Thread 🧵
1/ 🚨 NEW RESEARCH: We identified a training program provided to government employees in Angola by the Israeli influence-for-hire company BlackCore.
Full report: https://t.co/ABjWCO1jrr
Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products. We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books — a point @FTC emphasized repeatedly during my tenure.
1. There is an extensive set of laws that govern dangerous and defective products. For example, releasing unvetted AI models or agents can violate consumer protection laws. Shipping flawed AI tools without implementing adequate measures to detect and stop rogue or defective AI agents can be an “unfair or deceptive” act or practice under the FTC Act (and analogous state laws). And some state AGs are already exploring holding AI firms and their CEOs criminally liable when their models participate in criminal activity.
2. Existing laws also prohibit “unfair methods of competition.” This covers instances where AI firms appropriate the competitively sensitive information of their customers, including through tracking their use of various tools. It can also cover instances where firms pursue dangerous behavior, aware that doing so may compel rivals to do the same.
As the Supreme Court has noted: “A method of competition which casts upon one's competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal, was thought to involve the kind of unfairness at which the [unfair methods of competition] statute was aimed."
3. The highly concentrated and interconnected structure of these markets could be creating major risks and conflicts of interest. We had started investigating these partnerships and cross-investments across the stack (and released a preliminarily overview of some findings: https://t.co/jJ5cS3Pin3).
Both federal and state enforcers should be scrutinizing these opaque relationships and inter-dependencies. We are already seeing how these relationships could undermine accountability. For example, OpenAI could face liability given the Hugging Face incident, but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this — given Nvidia’s strong incentive to see OpenAI continue full speed ahead.
4. As AI tools dramatically change the landscape of cybersecurity risks and hacks, all businesses should be doubling down on having core security protections in place. Firms that fail to invest in adequate data security measures or fix known vulnerabilities can also be breaking the law. A recent analysis showed that around 1/3 of Fortune 100 companies do not even have a way to notify them about security issues. During my @FTC tenure, we sued firms for poor data security practices and held CEOs liable when they were personally responsible.
https://t.co/nwZ5Av8fOK
https://t.co/KjRye8y9SY
5. As policymakers consider new legal regimes, we should be looking to lessons from prior efforts to govern major sectors, such as banking and other networks, platforms, and utilities. Tools like structural separations, nondiscrimination, and supervision could be key, and there’s a rich history of what works and what doesn’t. But we can and must pursue any new efforts alongside enforcing existing laws.
New: Researchers used AI models to build a powerful mobile worm that could fully compromise any WeChat account across iOS and Android in seconds, showcasing how AI is upending the cybersecurity ecosystem. The worm took barely more than a week to build.
The recent #spyware revelations are not the only reason why the EU needs to rethink its approach to the Serbian government. We have long criticised the increasing attacks on democratic institutions, the opposition and civil society.
More @CyberScoopNews: https://t.co/sXljyfi16h
Finally, Brussels needs to put away the carrots and bring out the sticks.
Vučić can’t spy on citizens, dismantle the rule of law and then come to the EU with a begging bowl.
No rule of law = no EU money. No more rewards for repression. 🇷🇸🇪🇺
Citizen Lab researchers Siena Anstis, @natynettle, and Kate Pundyk write in @lawfare about the U.K. Supreme Court’s ruling that Bahrain could not claim state immunity in a case involving the use of spyware against Bahraini dissidents living in the U.K.
Read: https://t.co/s7w1jJ7vTg