
Lorenzo Franceschi-Bicchierai
@lorenzofb
Followers
52K
Following
17K
Media
2K
Statuses
22K
Senior reporter @TechCrunch, writing a book on Hacking Team and the industry of government spyware. ☎️ +1 917 257 1382
lorenzofb.com
Joined July 2009
Do you have any tips about cybersecurity, surveillance, spyware, zero-days...all things cyber? Contact me here: ☎️ Signal: + 1 917 257 1382 📷Keybase/Telegram: lorenzofb
0
8
20
@lorenzofb I decided to test whether EXIF data is removed from images sent over X's new encrypted chat feature like Signal and other messengers do. I can confirm it is not. I was able to extract information including GPS coordinates from a test image sent to me.
1
13
20
Breaking my X abstinence to post a quick PSA on X Chat, the supposedly end-to-end encrypted chat here. Experts told me that nobody should trust it at this point.
2
8
30
I am at SummerCon today too, and ~ extremely ~ easy to find, so come say hi. If you prefer, I’m also on Signal (+1 917 257 1382)
0
2
13
If you are at SummerCon and want to say hi, I’m here. DM me or ping me on Signal +1 917 257 1382
2
2
12
Read the story of what Kaspersky calls a “legendary” hacking group here: https://t.co/eGKXgJaes0
techcrunch.com
The elusive hacking group Careto was never publicly linked to a specific government, but TechCrunch has learned researchers concluded privately that the Spanish government was behind the group.
1
8
41
NEW: More than a decade ago, Kaspersky discovered a mysterious "elite" hacking group it called Careto (“The Mask”), which then vanished and only resurfaced last year. We can now reveal that researchers who investigated it were confident that the Spanish government was behind it.
7
63
138
Hacker Conference HOPE Says U.S. Immigration Crackdown Caused Massive Crash in Ticket Sales 🔗 https://t.co/TIhZ6BwHaT
https://t.co/TIhZ6BwHaT
404media.co
One scheduled speaker has also pulled out of the New York-based event and specifically pointed to Trump’s mass deportation efforts.
2
14
37
1989: FBI Director William Sessions said "Viruses are easy to create and propagate, require little expertise, and may be nearly impossible to prevent or detect."
0
4
16
In case you are wondering, this chart shows what U.S. carriers do if they receive a government surveillance request.
1
1
5
NEW: Sen. Ron Wyden says AT&T, T-Mobile, and Verizon were not notifying senators of surveillance requests, despite being required to do so. Wyden also revealed — without naming it — that one carrier secretly turned over Senate data to law enforcement. https://t.co/IQSQaeDBal
techcrunch.com
Sen. Ron Wyden said in a letter that one U.S. phone carrier turned over Senate data to law enforcement without notifying the target.
4
31
61
NEW: Coinbase says its recent data breach affected at least 69,000 customers. Compmay said breach dates back to Dec. 26, 2024 and continued until earlier this month. Stolen data is great for doxing or even physical attacks. https://t.co/5QjKLQ8LVC
techcrunch.com
The crypto giant said the unauthorized access to customer data dates back to late December 2024.
0
15
21
WaPo reports that NSO wanted to pitch its spyware to be used in Trump's immigration crackdown.
0
1
7
More bad news for NSO Group after it lost the lawsuit with WhatsApp.
NEW: Pegasus spyware maker NSO Group is rebuffed by the WH in its efforts to get off a trade blacklist. US officials tell WaPo they have no plans to seek the firm's removal from the Entity List. https://t.co/l5B3QFlMGg
2
6
15
NEW: A Massachusetts student plead guilty to hacking and extorting a U.S. education tech company. Prosecutors said the hacker stole personal data on 60 million students and 10 million teachers. And all signs point to that victim being PowerSchool. https://t.co/wvGcou9jcO
techcrunch.com
Prosecutors say the hacker stole information on 60 million students, an incident that matches the data breach at PowerSchool.
1
1
4
Despite what CISA says, Google told me: "there has been no reports of or evidence of exploitation of the vulnerability. We are reaching out to CISA for clarification of their categorization."
Google just patched a serious ⚠️ vulnerability (CVE-2025-4664) that allows attackers to steal sensitive tokens (like OAuth or session IDs) when you simply visit a malicious site. No clicking. No downloading. Just loading the page is enough. What makes this so dangerous? The
6
15
29
The pope's funeral, now Cannes. I expected Assange to spend most of his time posting on Twitter but I guess is all about IRL experiences these days.
Julian Assange's t-shirt at Cannes lists the names of 4,986 Palestinian children aged five and under, killed by Israeli forces since 2023. [Photos by David Fisher]
0
2
4
The last time the UAE did this it ended up poorly for most people involved, so I'm sure it will go well this time.
New: UAE is trying to recruit Pentagon workers displaced by DOGE to move to Abu Dhabi to work on AI for UAE military. A UAE brig general met last month with two former staffers of Defense Digital Service and tried to recruit them and their entire DDS team
2
7
23
NEW: Cocospy, Spyic and Spyzie, the stalkerware apps that were breached earlier this year and caught spying on millions of people's phones, now appear to have shut down. The apps not working, their websites gone, and Amazon-hosted cloud storage deleted. https://t.co/2bAVQRTf8k
techcrunch.com
The trio of spyware apps — hacked earlier this year — no longer work.
1
28
50
NEW: The U.S. Department of Justice announced that Eric Council Jr. was sentenced to 14 months in prison for the hack of the U.S. Securities and Exchange Commission's X account. https://t.co/mryvHLA1Pv
techcrunch.com
The Department of Justice announced Eric Council Jr. was sentenced to 14 months in prison for the hack.
1
18
23