A 23-year-old Serbian activist’s Android phone was hacked by a zero-day exploit developed by Cellebrite, according to Amnesty International. The exploit exploited vulnerabilities in Android USB drivers, which had been patched for Linux but not Android. The activist’s phone was unlocked and an unknown Android app was attempted to be installed, consistent with previous NoviSpy spyware incidents. Cellebrite denies facilitating cyber activity and has stopped software use by Serbia.

Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools
New research reveals that cyber attacks are increasingly using trusted services to carry out malicious activities instead of relying primarily on malware. This shift in