HACKER Q&A
📣 Mordisquitos

Do you know of any good sources on the technical side of Pegasus?


There has been a lot of news lately regarding Pegasus spyware, whose devices were found to have been infected, whether it was via 0-click exploits or spear-phishing, as well as speculations on the guilty part(y|ies), etc. Also, I'm sure there's a lot of discussion going around in IT security communities regarding this or that CVE that was exploited and how.

However, I'm really missing something in between: moderately in-depth technical explanations aimed at non-security-professionals, i.e. something that the "educated layperson" may find interesting.

Is there anything of the sort, for those of us who are curious as to what Pegasus does and how, and how it has been detected, but who are neither satisfied with the mainstream news glossing over any technical detail nor have the time or the knowledge to delve into detailed professional analyses? Or is it all being handled at such levels that there's nothing really approachable at the moment?


  👤 sysadm1n Accepted Answer ✓
https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...

Pegasus breaks out of the 'blastdoor' and does an RCE