Cdt Civil Society Demands Stronger Safeguards for Commercial Spyware
Article Content
- •25+ civil society organizations demand enforceable safeguards for commercial spyware.
- •The Pall Mall Industry Guidelines on CCICs are set to be finalized by November 2026.
- •Weak guidelines could legitimize serious human rights abuses linked to commercial spyware.
Over 25 civil society organizations have called for enforceable human rights and accountability safeguards in the upcoming Pall Mall Industry Guidelines on Commercial Cyber Intrusion Capabilities (CCICs), which include commercial spyware. The guidelines, being developed under the leadership of the UK and France, are expected to be finalized in November 2026. The joint statement warns that weak language in the guidelines could legitimize an industry already linked to serious human rights abuses, such as arbitrary surveillance and transnational repression. The organizations emphasize the need for strict limits on the sale and use of CCICs, requiring robust human rights due diligence and independent oversight. They also call for accountability mechanisms to address human rights abuses involving CCICs. The guidelines represent a historic opportunity to establish accountability as the industry norm, but significant risks remain if proper safeguards are not implemented.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Pegasus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…