These are solid & reflect reality that spyware is a global problem & doesn't always begin or end within EU borders.
Also, a joint EU-US strategy! Interesting recognition of the major strides made by US #spyware.
This is the big takeaway: the @pega report provides a basis of action, and a clear sign that something is very wrong with #spyware abuses like #Pegasus within the EU.
Now it's time for the rest of the mechanisms to do their work. We'll all be watching.
Real talk: popular encrypted apps are a major target for zero-click exploits.
An untested video calling stack pushed onto the devices of the most influential ppl in the world w/ built in discovery + Twitter's threadbare security team = disaster waiting to happen.
Encrypted calling apps are great targets for a lot of reasons.
They are on many phones + typically have good user discovery features. And many other exploit-friendly surfaces around call handling, handshakes etc.
NSO's #Pegasus etc got onto phones via WhatsApp, iMessage, etc.
In the 2019 #Pegasus breach of WhatsApp, the company was thankfully watching logs. They spotted, investigated, notified victims & sued NSO Group.
Similar story w/Apple.
In both cases a world class threat intelligence & security team was in the house.