GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

ICE Signs $2M Deal for Zero-Click Phone Hacking Tool

A federal contract reveals immigration enforcement is buying spyware capable of breaching phones without any user interaction.

Reports indicate that U.S. Immigration and Customs Enforcement has entered a $2 million contract for spyware with zero-click exploit capabilities, meaning the tool can compromise a target's phone without the victim clicking a link or opening a file.

Zero-click exploits are considered the most dangerous class of mobile attack because they leave almost no trace of user error to blame, exploiting flaws deep in how phones process incoming data like messages or calls. This type of technology has historically been associated with nation-state intelligence operations and controversial vendors like NSO Group, whose Pegasus tool has been used against journalists and activists worldwide.

The contract raises questions about oversight, since these tools are engineered to bypass encryption and OS-level protections that Apple and Google have spent years hardening.

Why it matters: Zero-click spyware sold to domestic agencies signals that offensive mobile exploits are becoming normalized tools of everyday law enforcement, not just spy agencies. It also puts pressure on Apple and Google to keep patching the exact vulnerability classes these contracts depend on, since every acquisition funds demand for fresh exploits.

Sources: Hacker News