Daniel Roethlisberger
droethlisberger.bsky.social
Daniel Roethlisberger
@droethlisberger.bsky.social
security & software engineering · cyber defense · civil society

https://infosec.exchange/@droe
Reposted by Daniel Roethlisberger
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
Intellexa’s Global Corporate Web
www.recordedfuture.com
December 4, 2025 at 4:18 AM
Reposted by Daniel Roethlisberger
A short explainer for the Paragon software story in Italy:

1. Italy is specialised in "dossieraggio" where everyone and his dog collects "dossiers" (aka "dirt") on everyone else,
2. There is a long history of using information services for the preparation of said dossiers,

[…]
November 7, 2025 at 9:00 AM
Reposted by Daniel Roethlisberger
NOW: US court permanently bans Pegasus spyware maker from hacking WhatsApp.

NSO Group can't help their customers hack WhatsApp etc. ether. Must delete exploits & R&D.

Bad news for NSO. Huge competitive disadvantage for the notorious company.

Big additional win for WhatsApp 1 /
October 17, 2025 at 11:37 PM
Reposted by Daniel Roethlisberger
The video of @droethlisberger.bsky.social and my @reconmtl.bsky.social 2025 talk, "A Trip to Ancient BABYLON", is now online! It's a fun story about a 2017-era iOS persistence exploit that we found in a Pegasus sample -- on VT (!!)
Recon 2025 - A Trip to Ancient BABYLON: Unearthing a 2017 Pegasus Persistence Exploit
YouTube video by Recon Conference
www.youtube.com
October 16, 2025 at 5:15 PM
Recording of our REcon talk about a 2017 iOS persistence exploit used by NSO's Pegasus—and other threat actors too—is out. @billmarczak.org and me of @citizenlab.ca at @reconmtl.bsky.social.

youtu.be/ZlopMtjsVRw
Recon 2025 - A Trip to Ancient BABYLON: Unearthing a 2017 Pegasus Persistence Exploit
YouTube video by Recon Conference
youtu.be
October 16, 2025 at 2:45 PM
Reposted by Daniel Roethlisberger
NEW: Spyware installed on Kenyan filmmakers' phones in police custody @citizenlab.ca confirms cpj.org?p=516177
Spyware installed on Kenyan filmmakers' phones in police custody - Committee to Protect Journalists
New York, September 10, 2025—The Committee to Protect Journalists is gravely alarmed by the installation of spyware on two Kenyan filmmakers’ phones while the devices were in police custody, and calls...
cpj.org
September 10, 2025 at 2:02 PM
Reposted by Daniel Roethlisberger
Excited to talk today at @reconmtl.bsky.social with @droethlisberger.bsky.social about a 2017 iOS persistence exploit used by NSO's Pegasus (and, interestingly, other threat actors too)! 10:00AM in the Grand Salon cfp.recon.cx/recon-2025/t...
June 29, 2025 at 1:45 PM