TRENDING
Close-up of the Rosetta Stone showing the Demotic script above and the Greek script below, the same text written in two different scripts
October 6, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
A row of green and grey fibre broadband street cabinets on a pavement beside a fence in Iver, England
October 6, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
An ornate cast-iron wall mailbox with its door hanging open, stuffed with colorful flyers and a yellow flyer bulging out of the top slot
October 6, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions
Chronophotograph by Étienne-Jules Marey of a man riding a bicycle, showing five snapshots of the same ride taken at regular intervals
October 6, 2026
How to Find Slow Python Code With the Python 3.15 Tachyon Sampling Profiler
Close-up of an airport baggage tag reading Stockholm Arlanda and ARN
October 6, 2026
Cloudflare Traces Turns Distributed Tracing Into a Trust Decision at the Edge
06 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Shelves of old books fastened by iron chains in the Francis Trigge Chained Library in Grantham, England, a picture of data that can be read but not changed
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Row of capsule hotel pods with white pillows and folded blankets, each capsule an idle sleeper packed into a shared rack
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark’s oldest church book, from Holmens parish, open on a stack of books; its handwritten pages record births between 1617 and 1639
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 226 Posts
News 228 Posts
Learning Hub 198 Posts
Home/Articles/Paragon’s CEO Turns Spyware Ethics Into a Promise the Vendor Cannot Audit
Articles

Paragon’s CEO Turns Spyware Ethics Into a Promise the Vendor Cannot Audit

In an exclusive WIRED interview, REDLattice and Paragon CEO Andy Boyd said the spyware maker cannot see who its customers target, has no kill switch and dropped Italy as a risk decision, days after...

October 1, 2026 10 Min Read
18

Paragon Solutions has long presented itself as the spyware vendor that can be trusted. It says it will not sell to authoritarian governments, and it promises to cut off any customer caught using its tools against journalists, dissidents or other illegitimate targets. An exclusive interview that WIRED’s Kim Zetter published on October 1 shows how little technical machinery sits behind that promise. REDLattice and Paragon CEO Andy Boyd, a former director of the CIA’s Center for Cyber Intelligence, told WIRED that the company cannot see who its customers target, has no kill switch, and ended its Italian contracts because keeping them “just was not worth it, from a risk perspective,” which WIRED reads as meaning the allegations were never investigated.

Table Of Content

  • What Boyd told WIRED
  • A vendor that cannot see how its tools are used
  • Vetting stands in for monitoring
  • One allegation as proof
  • How the claims compare with NSO’s own reports
  • Italy is the test case
  • Why the Nasdaq listing raises the stakes
  • The US market and the offensive-cyber contracts
  • What this means for buyers and defenders

The timing is notable. On Monday, September 28, REDLattice announced that it will go public by merging with Bold Eagle Acquisition Corp., a Nasdaq-listed special purpose acquisition company (SPAC), in a deal that values it at a $1.25 billion pre-money enterprise value. If it closes around the end of the year, as The Record reports is planned, Paragon will sit inside a listed company with public disclosure duties. This article sets Boyd’s admissions against NSO Group’s own published safeguards and against what the Italian case has shown so far, because that record tests the oversight model more directly than any marketing claim can.

What Boyd told WIRED

A vendor that cannot see how its tools are used

According to WIRED’s account, Paragon has no technical way to know whether customers misuse its software, because it cannot see who they target or what data they extract from targeted devices. It learns about misuse only if a customer admits to it or a third party uncovers it. Boyd said WhatsApp and Citizen Lab did the company a great service when they exposed the alleged Italian misuse.

There is also no kill switch. The only levers Paragon has are halting a customer’s 24-hour support and its system updates. Boyd said those updates are frequent and essential, and that without them the system is rendered ineffective in about 12 hours. “Things start falling apart quite quickly,” he said.

Logging is the customer’s decision. Boyd said customers can enable logging on some systems if they choose to, but Paragon has no access to the logs and does not want any, because in his framing no one would buy a product whose maker could see their targeting data. Government oversight bodies can use the logs to investigate their own agencies, as an Italian parliamentary committee did last year. “There’s a balancing act between privacy and security and being able to ensure that our customers are using these things correctly,” Boyd said. “And I think we’ve landed on the best balance.”

Vetting stands in for monitoring

Without visibility after the sale, Paragon leans on screening before it. Boyd said an internal risk committee, chaired by him and other board members, weighs political and government stability, human rights record, corruption ratings, the strength of a country’s legal system and whether a prospective customer has a record of obeying its own laws. The approved list holds between 20 and 30 countries, and the company has more than 100 customers in 23 countries, a figure REDLattice repeats in its own release. He said the process “usually works 99 out of 100 times,” and that contracts and a zero-tolerance policy are meant to deter the remaining cases.

Contracts bar targeting journalists, civil society members, opposition politicians and anyone who is not the subject of a legitimate intelligence or criminal investigation, WIRED reports. Systems sold to non-US customers also include a block on targeting any phone number that requires the US +1 country code, which US law enforcement agencies holding a warrant can have disabled, Boyd said.

One allegation as proof

Boyd argued that having only one public allegation of misuse shows the model works. WIRED’s rebuttal is a base-rate point: the odds that anyone uncovers misuse are low, particularly because the company takes care that its spyware is hard to detect on infected devices. Citizen Lab’s John Scott-Railton made the same point. “We only find a very, very, very small subset [of infections], and the total numbers are always larger,” he told WIRED. “These companies spend millions trying to hide from us.” Senator Ron Wyden put it more bluntly: “It’s easy to claim your powerful hacking tool isn’t being misused if you go out of your way to ensure you don’t know how customers use it.”

How the claims compare with NSO’s own reports

WIRED frames Paragon against NSO Group, the maker of Pegasus, and Scott-Railton says Paragon’s admissions mean “less oversight, less transparency, less contractual protection against abuses than NSO Group.” NSO’s transparency reports let that comparison be checked against the company’s own words, with one caveat: they are self-reported.

Control Paragon, as Boyd described it to WIRED NSO, as described in its own reports
Remote disable No kill switch. Paragon can halt 24-hour support and system updates, and Boyd says the system is ineffective after about 12 hours. The 2024 report describes a kill switch “designed to immediately and remotely disable our Pegasus system in the event of unauthorized usage.” The 2025 report says NSO “maintains the capability to suspend or disable systems where credible concerns of misuse arise.”
Activity logs Customers can enable logging on some systems. Paragon has no access to the logs and does not want it. The 2024 report describes an “immutable audit log” stored on the customer’s system that “can be reviewed by the Company during an investigation subject to customer consent.” The 2025 report says NSO “does not have routine access to operational data or audit logs.”
Duty to cooperate Contracts bar targeting journalists and other illegitimate targets. WIRED’s account describes no duty to share logs or cooperate with a review. The 2025 report says “Customers must notify NSO of suspected misuse and cooperate with internal review processes.”

The comparison is narrower than the headline contrast suggests. NSO also says it has no routine access to logs and may review them only with the customer’s consent. The differences that remain are a claimed remote disable, logging described as a built-in product feature rather than an option, and a contractual duty to notify and cooperate. Those are meaningful, but all of them rest on NSO’s own description. When NSO published its 2025 report in January, Access Now’s Natalia Krapiva told TechCrunch it was “nothing but another attempt at window dressing,” and TechCrunch noted that the report offered no concrete evidence for its human rights promises.

Italy is the test case

Italy is the one place where the oversight model has been exercised in public, and the record shows both its value and its limits.

  • January 2025. WhatsApp notified around 90 people, including journalists and members of civil society, that they had been targeted with Paragon’s Graphite spyware, according to TechCrunch.
  • Early June 2025. Italy’s parliamentary security committee, COPASIR, acknowledged that the country’s intelligence services had used Graphite against activists and found no evidence it was used against journalist Francesco Cancellato. The report said activists Luca Casarini and Giuseppe Caccia were targeted legally because of their alleged role in fueling illegal immigration, The Record reported.
  • June 9, 2025. Paragon said it had ended its Italian contracts. Its statement to Haaretz said it had offered the Italian government and parliament a way to determine whether its system had been used against the journalist, and that the authorities “chose not to proceed with this solution.” Italian outlets reported that the Department of Information for Security, which oversees the intelligence agencies, had rejected an offer to check Graphite system logs as “invasive practices, unverifiable in scope, results and method.”
  • June 12, 2025. Citizen Lab published forensic confirmation that Graphite was used against Fanpage journalist Ciro Pellegrino and a second, anonymous European journalist, and linked both cases to the same Paragon operator. Apple told Citizen Lab the zero-click attack was mitigated as of iOS 18.3.1 and assigned it CVE-2025-43200.
  • March 5, 2026. Prosecutors in Rome and Naples said a technical report found traces of infection on the phones of Cancellato, Casarini and Caccia in the early hours of December 14, 2024. Judicial authorities who inspected the Paragon spyware server used by the intelligence agency AISI found operations against Casarini and Caccia but none against Cancellato, so who hacked him remains unclear. The same report found no evidence of spyware on Pellegrino’s phone. “How is it possible that Citizen Lab, an authority on spyware, found evidence that Paragon’s Graphite was on my phone, while the Italian prosecutors’ experts did not?” Pellegrino asked TechCrunch.
  • April 28, 2026. Prosecutors had sent Paragon a formal request for information through the Israeli government and, a year after the investigation opened, had received no response, according to Wired Italy as summarized by TechCrunch. Italy’s government has denied hacking either journalist.

Two points follow. First, the one case in which investigators inspected a vendor system’s records shows how far log-based oversight can go and where it stops. The records on the intelligence agency’s Paragon server matched two of the three confirmed infections and not the third. Logs held by a customer can answer whether that customer ran an operation. On their own, they cannot rule out that someone else did.

Second, the vendor’s explanation has moved. In 2025 Paragon told Haaretz it ended the contracts because Italy declined its offer to verify whether its system had been used against the journalist. In 2026 Boyd tells WIRED the relationship was not worth the risk, and WIRED reports that Paragon did not follow up with WhatsApp or Citizen Lab to learn more about the alleged abuse. Both can be true: a vendor can offer a check, be refused, and then drop a customer for business reasons. They still leave a practical question open. Boyd says Paragon has no access to customers’ logs and does not want any, while Italian outlets described the 2025 offer as a check of Graphite system logs. If both statements hold, any verification would have depended on the customer’s consent, which is the same consent-based arrangement NSO describes.

Why the Nasdaq listing raises the stakes

REDLattice’s announcement describes a company that sells exclusively to government agencies at the national or federal level, with more than 100 customers in 23 countries and $267 million of revenue in the twelve months to June 30, up 29 percent. The deal carries $335 million of committed capital anchored by Loomis, Sayles & Co., including a $60 million common stock investment led by existing investor AE Industrial and Eagle Equity Partners. Proceeds are earmarked to refinance REDLattice’s debt and to fund the final cash earnout payment from its acquisition of Paragon, and Boyd stays on as chief executive.

For oversight, the effect cuts both ways. Jen Roberts of the Atlantic Council told The Record that public companies face disclosure requirements and that shareholders gain real levers, “from proxy votes to divestment,” to shape how a company behaves. She also said that for policymakers trying to curb the proliferation of these capabilities, “this isn’t a good sign.” The registration and proxy materials that typically accompany a SPAC merger are the first place to look for how REDLattice describes misuse risk, customer terminations and export licensing in writing, and for how much revenue the Italian contracts represented. Boyd told WIRED that cancelling them cost the company revenue in the “seven figures,” while Israeli media have estimated the contracts were worth “tens of millions of dollars.”

The US market and the offensive-cyber contracts

WIRED describes a company that is “American on paper” but “still effectively Israeli.” Paragon was founded in 2019 by a former commander of Israel’s Unit 8200, and Boyd told WIRED it could not “make any substantial headway” in the US, so the company looked for an American buyer. AE Industrial bought it in December 2024 and merged it with REDLattice. It keeps its name and offices in Israel, where it has more than 600 employees. Products built by Paragon still need Israeli licensing approval to be sold abroad, while REDLattice-made products sold to non-US customers fall under the US International Traffic in Arms Regulations. Asked whether Washington objected to the deal, Boyd said there were no objections and that no one imposed conditions.

On the demand side, WIRED reports that Paragon signed a $2 million contract with Homeland Security Investigations, a division of Immigration and Customs Enforcement, shortly before the acquisition, and that no other government contracts for the companies appear in public databases, although classified contracts would not. TechCrunch reported in April that ICE told lawmakers HSI is using Paragon’s spyware to counter terrorism and drug trafficking. Boyd indicated the company is especially interested in Pentagon and CIA work, and said REDLattice will pursue the contracts the Trump administration announced for private firms to conduct offensive cyber operations against cybercriminal groups. That program comes from the August 12 presidential memorandum we covered earlier. Asked what would happen if a US customer were accused of misuse, Boyd pointed to inspectors general and congressional committees, so the same outside-in model applies at home.

What this means for buyers and defenders

The interview is a case study in the gap between a governance claim and a control. Three questions separate the two, and they apply to any vendor selling a dual-use security capability, not only spyware makers:

  • Can the vendor act without the customer’s help? A kill switch is a control. A policy that says misuse will be punished is a promise. Paragon’s only lever, withholding support and updates, takes about 12 hours to bite by Boyd’s own account.
  • Who can read the logs? Logs that only the customer can read answer the customer’s questions. Independent review needs a record that a third party can inspect under defined conditions.
  • Who finds the abuse? By Boyd’s account, misuse surfaces only if a customer admits it or an outsider such as WhatsApp or Citizen Lab finds it, and Scott-Railton says Citizen Lab sees only a small subset of infections.

For people and organizations at risk of targeted attacks, the practical defenses sit on the device. The Graphite flaw Citizen Lab documented, CVE-2025-43200, involved a logic issue when processing “a maliciously crafted photo or video shared via an iCloud Link,” according to the National Vulnerability Database, and Apple fixed it in iOS 18.3.1 and related releases. Apple describes Lockdown Mode as “an optional, extreme protection” for the few people who might be personally targeted, one that reduces the attack surface that “highly targeted mercenary spyware” could exploit. Apple’s patch this week for a Meta-reported CoreGraphics zero-day, which Apple says may have been exploited in a targeted attack on iOS, is covered here and is a reminder that this class of bug keeps arriving.

Before the interview, REDLattice founder John Ayers told WIRED the company was “not looking for a favorable write-up.” He wrote: “If the honest assessment is still damning, that’s a conversation we’re prepared to have.” The merger paperwork is the next place that conversation will have to happen.

Tags:

National SecurityNSO GroupParagon SolutionsSpywaresurveillance

Share

Close-up of the intertwined exposed roots of two birch trees spreading across a forest floor, a visual pun on gaining root access
Previous Post

DIVD Says Two Zammad Zero-Days Let an AI Agent Climb From Session Hijack to Root in Seconds

Large naval binoculars whose two lenses each reflect the same sunset scene of a ship and a helicopter
Next Post

How to Build Hybrid Search in Python With BM25, Local Embeddings, and Reciprocal Rank Fusion

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
05 Oct
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
05 Oct
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
Trending
October 5, 2026
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
October 5, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
October 5, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
A person with a laptop and smartphone, representing digital attention and AI-assisted work
Articles

AI Chatbots Are Making Attention a Design Problem

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026