Citizen Lab discovered an actively exploited zero-click vulnerability in iPhones, which was used to deliver NSO Group's Pegasus spyware. The exploit, called BLASTPASS, involved sending malicious images via iMessage and could compromise iPhones running the latest version of iOS without any user interaction. Apple has issued patches for the vulnerability and recommends that users update their devices immediately. The discovery highlights the importance of supporting civil society organizations in identifying and reporting security threats.