www.gov.uk Pall Mall Process Launched to Address Spyware Abuse Globally
Article Content
- •The Pall Mall Process aims to curb the abuse of commercial cyber intrusion capabilities.
- •Around 100 countries are reported to have procured CCICs, raising global security concerns.
- •A non-binding Code of Practice for States was adopted by 27 countries to guide CCIC usage.
In July 2026, the Pall Mall Process (PMP) was officially launched by France and the UK to combat the irresponsible use of commercial cyber intrusion capabilities (CCICs), including spyware. This initiative follows a significant increase in the global procurement of CCICs, with reports indicating that around 100 countries have acquired such tools. A non-binding Code of Practice for States was adopted in April 2025, signed by 27 countries, to guide governmental actions regarding CCICs. The PMP aims to foster collaboration between governments, industry, and civil society, emphasizing the need for public-private partnerships. The initiative is a response to the growing concerns over human rights violations linked to spyware, particularly highlighted by cases involving the NSO Group. Currently, a Code of Practice for Industry is under development, expected to be finalized at the Paris Peace Forum in November 2026. The consultation process revealed uneven implementation of customer vetting and supply chain due diligence across the market. The PMP seeks to create a focused dialogue among like-minded states to effectively address the risks posed by CCICs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Pegasus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…