Lorenzo Franceschi-Bicchierai
@lorenzofb.bsky.social
18K followers 2.4K following 510 posts
Real-time historian of the late cyber capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies. 🍕, ⚽️, 🎸, 🎮 by night. ☎️ Signal: +1 917 257 1382 Past lives: VICE Motherboard, Mashable, WIRED.
Posts Media Videos Starter Packs
Pinned
lorenzofb.bsky.social
Do you have any tips about cybersecurity, surveillance, spyware, zero-days...all things cyber?

Contact me here:

☎️ Signal: + 1 917 257 1382

📷Keybase/Telegram: lorenzofb
The hacker antagonist in Ghost in the Shell known as The Laughing Man.
lorenzofb.bsky.social
NEW: ICE purchased custom-made vans from a company called TechOps Specialty Vehicles (TOSV) that are equipped with fake cellphone towers designed to spy on phones.

TOSV president said the company integrates the cell-site simulators into their vans, but does not manufacture the surveillance tool.
ICE bought vehicles equipped with fake cell towers to spy on phones  | TechCrunch
The federal contract shows ICE spent $825,000 on vans equipped with “cell-site simulators” which allow the real-world location tracking of nearby phones and their owners.
techcrunch.com
lorenzofb.bsky.social
NEW: Blockchain monitoring firm Elliptic says North Korean hackers have stolen more than $2 billion in crypto this year, an all-time record, with three more months to go.

The estimate is based on more than thirty hacks against crypto exchanges and also “high-net-worth individuals.”
North Korean hackers stole over $2 billion in crypto so far in 2025, researchers say | TechCrunch
Blockchain monitoring firm Elliptic said this year’s total is already an all-time record for the North Korean regime.
techcrunch.com
Reposted by Lorenzo Franceschi-Bicchierai
zackwhittaker.com
SCOOP: India's income tax authority has fixed a major bug that was exposing taxpayers' sensitive data to any other signed-in user, according to the researchers who found it.

TechCrunch's @journalistjagmeet.com verified the data exposure by asking the researchers to check his own records.
Exclusive: Bug in India's income tax portal exposed taxpayers’ sensitive data
TechCrunch verified that the security bug in the Indian Income Tax Department's e-Filing portal exposed taxpayers' data to other users. The security researchers who found the flaw say the data leak is...
techcrunch.com
Reposted by Lorenzo Franceschi-Bicchierai
zackwhittaker.com
Several hacked companies, including Workday, don't appear on the hackers' dark web leak site.

I asked the hackers why, such as if the companies paid them a ransom. ShinyHunters acknowledged that "there are numerous other companies that have not been listed," but declined to say why.
Hacking group claims theft of 1 billion records from Salesforce customer databases | TechCrunch
The hacking group claims to have stolen about a billion records from companies, including FedEx, Qantas, and TransUnion, who store their customer and company data in Salesforce.
techcrunch.com
lorenzofb.bsky.social
NEW: The predominantly English-speaking amorphous hacking group known as Scattered Spider/Lapsus$/etc has launched a website to publicize their victims and extort them.

This is the first time the group has such a public presence, indicating an escalation in their strategy.
Hacking group claims theft of 1 billion records from Salesforce customer databases | TechCrunch
The hacking group claims to have stolen about a billion records from companies, including FedEx, Qantas, and TransUnion, who store their customer and company data in Salesforce.
techcrunch.com
Reposted by Lorenzo Franceschi-Bicchierai
lorenzofb.bsky.social
NEW: Chinese tech giant Anker offered users of its Eufy cameras to upload videos of package and car thefts to train its AI systems in exchange for money.

At least a hundred users participated, but the company did not share the final numbers. Eufy has a similar initiative that offers other rewards.
Anker offered to pay Eufy camera owners to share videos for training its AI | TechCrunch
Hundreds of Eufy customers have donated hundreds of thousands of videos to train the company’s AI systems.
techcrunch.com
lorenzofb.bsky.social
UPDATE: Apple told us that it is "gravely disappointed" that it still cannot offer Advanced Data Protection (ADP) to users in the United Kingdom.

The company did not address the report that says the U.K. government sent it a new order to enable backdoor access to end-to-end encrypted iCloud.
UK government tries again to access encrypted Apple customer data: report | TechCrunch
The U.K. Home Office is seeking access to Apple users’ encrypted iCloud backups for a second time, after an earlier attempt failed earlier this year.
techcrunch.com
Reposted by Lorenzo Franceschi-Bicchierai
josephcox.bsky.social
New from 404 Media: ICE to buy tool that tracks locations of hundreds of millions of phones every day. Billions of pieces of location data. ICE previously stopped using data remotely harvested from smartphones. Now it's buying it again. Usually used w/o warrant
www.404media.co/ice-to-buy-t...
ICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every Day
Documents show that ICE has gone back on its decision to not use location data remotely harvested from peoples' phones. The database is updated every day with billions of pieces of location data.
www.404media.co
lorenzofb.bsky.social
NEW: The U.K. government is reportedly once again requesting Apple build a backdoor so government officials can access end-to-end encrypted iCloud backups in the U.K.

Last time this happened, Apple disabled iCloud's Advanced Data Protection, the opt-in feature that lets users encypt cloud backups.
UK government tries again to access encrypted Apple customer data: report | TechCrunch
The U.K. Home Office is seeking access to Apple users’ encrypted iCloud backups for a second time, after an earlier attempt failed earlier this year.
techcrunch.com
Reposted by Lorenzo Franceschi-Bicchierai
jsrailton.bsky.social
NEW: turns out the EU helped finance a bunch of spyware companies with..public money.

Extremely bad look.

Group of MEPs calls for action.👇

apache.be/2025/10/01/e...
Reposted by Lorenzo Franceschi-Bicchierai
lorenzofb.bsky.social
NEW: A cyberattack has forced Japan's beer maker Asahi to suspend operations at its plants in the country since Monday.

For now, the company said it's experiencing a "system failure" but did not confirm "leakage of personal information or customer data to external parties."
Japan's beer-making giant Asahi stops production after cyberattack  | TechCrunch
A day after one of Japan's biggest brewers, Asahi Group, announced it suspended production due to a cyberattack, the company said it has no timeline for its recovery.
techcrunch.com
lorenzofb.bsky.social
One step closer to AGI. Amazing.
techmeme.com
OpenAI rolls out Instant Checkout to let users make single-item purchases directly in ChatGPT, starting with US Etsy sellers, and plans to add Shopify merchants (Ashley Capoot/CNBC)

Main Link | Techmeme Permalink
lorenzofb.bsky.social
For the record this is a non original copy of the sock puppet we used for the video interview
lorenzofb.bsky.social
I am not an AI expert nor I write about it that much at all. But y’all, chatbots don’t and never will have opinions. Stop pretending they do.
kashhill.bsky.social
Not the point of this piece exactly but a great example of how chatbot validation could increase polarization

www.nytimes.com/2025/09/26/w...
lorenzofb.bsky.social
Alternative headline: app based on a terrible idea didn’t even bother taking care of the most basic of precautions to protect its users.
zackwhittaker.com
NEW: Neon, an app that pays you to record your calls so your audio can be used to train AI, and already rose to the top #5 free apps on Apple's App Store, has gone offline after a security lapse.

We found the app exposed users' phone numbers, call recordings, and text transcripts of those calls.
Exclusive: Neon takes down app after exposing users' phone numbers, call recordings, and transcripts
Call recording app Neon was one of the top-ranked iPhone apps, but was pulled offline after a security bug allowed any logged-in user to access the call recordings and transcripts of any other user.
techcrunch.com
Reposted by Lorenzo Franceschi-Bicchierai
zackwhittaker.com
NEW: Neon, an app that pays you to record your calls so your audio can be used to train AI, and already rose to the top #5 free apps on Apple's App Store, has gone offline after a security lapse.

We found the app exposed users' phone numbers, call recordings, and text transcripts of those calls.
Exclusive: Neon takes down app after exposing users' phone numbers, call recordings, and transcripts
Call recording app Neon was one of the top-ranked iPhone apps, but was pulled offline after a security bug allowed any logged-in user to access the call recordings and transcripts of any other user.
techcrunch.com
lorenzofb.bsky.social
This is how we lose.
joelevard.com
Jody, I hate to tell you this, but your husband is not being creative
Moderator, Katherine Miller
And of course, A.I.: Is it good for society, bad, neutral, mixed?


Jody, 32, Mo., white, Republican, construction
I’m torn on that one. I see a lot of really good and positive things that can come from A.I. My husband is using it to really get into his creative side. He’s used it to write songs and to even write a book and things like that. But on the flip side, people who have that natural talent, it cheapens a little bit when somebody else can just go and do it. For the average user, it probably really is allowing them to do something new that they maybe wouldn’t have been able to do before.
Reposted by Lorenzo Franceschi-Bicchierai
joelevard.com
Jody, I hate to tell you this, but your husband is not being creative
Moderator, Katherine Miller
And of course, A.I.: Is it good for society, bad, neutral, mixed?


Jody, 32, Mo., white, Republican, construction
I’m torn on that one. I see a lot of really good and positive things that can come from A.I. My husband is using it to really get into his creative side. He’s used it to write songs and to even write a book and things like that. But on the flip side, people who have that natural talent, it cheapens a little bit when somebody else can just go and do it. For the average user, it probably really is allowing them to do something new that they maybe wouldn’t have been able to do before.
lorenzofb.bsky.social
Y’all keep saying honeypot. How do you even set up a good iOS honeypot?
lorenzofb.bsky.social
Do I have anyone who follows me and works for PWC in cyber?
lorenzofb.bsky.social
Me planning my next trip to visit family in Meloni's Italy.
lorenzofb.bsky.social
Well to be fair, you can't stay away from ransomware either.