Lorenzo Franceschi-Bicchierai

@lorenzofb.bsky.social

Real-time historian of the late cyber capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies. Also writing a book about Hacking Team and the history of government spyware. ☎️ Signal: +1 917 257 1382

“The litigation has revealed a clear pattern: Uber’s lawyers scour women’s private communications, medical records, therapy notes and other sources for sensitive details, including other sexual assaults, childhood abuse and domestic violence. They grill the women about those issues…”

Uber’s Strategy for Fighting Sexual Assault Suits: ‘What Were You Wearing?’

The ride-hailing giant promised to handle legal claims “in a way that is best for the survivor.” Its lawyers are pursuing a far more aggressive strategy.

nytimes.com

NEW: Several hackers have been stealing $130 million — and counting — in Bitcoin from the owners of supposedly secure offline hardware wallets. By knowing how to make the keys, the hackers did not need to break into the safe that holds them. They essentially figured out how to cut keys at scale.

Hackers steal over $130 million by exploiting bug in offline hardware wallets | TechCrunch

A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to b...

techcrunch.com

NEW: We spoke to hacking law experts to learn if OpenAI and Anthropic could be prosecuted for their AI agents’ hacks against four companies. We are in “uncharted territory,” as one lawyer put it. But another attorney said there is a potential avenue to hold the two AI giants liable for negligence.

Who's legally to blame for Anthropic and OpenAI's autonomous AI hacks? It's complicated | TechCrunch

OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the...

techcrunch.com

NEW: After the UK government sent a secret legal request to access users’ encrypted iCloud data, Apple has reportedly filed a new legal challenge against it. This is the latest in a legal fight that started early last year. Critics see these demands as a threat to Apple users worldwide.

Apple challenges UK government’s latest demand for iCloud backdoor: report | TechCrunch

Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.

techcrunch.com

New, by me: Samsung has banned smart TV apps that enlist owners' internet connections into residential proxy networks, which are increasingly linked to cybercrime. Samsung told me it's also removing apps containing resproxy code. Bypass for ad-blockers: web.archive.org/web/20260803...

Samsung bans smart TV apps that share users' internet connections with strangers | TechCrunch

New security research offers a rare view inside residential proxy networks, which rely on apps that share a person's internet connection with someone else.

techcrunch.com

IMPACT: that company that was offering to buy books for AI companies’ training data — and probably destroy them in the process — says it will no longer offer this service following 404 Media’s exposure of it www.404media.co/ai-company-t...

Company Offering Printed Books to Train AI Stops After 404 Media Coverage

Citing backlash, ISBNdb removed its webpages about training AI, denied ever buying, scanning, or selling a book for AI training, and said the site was a "test of market interest."

404media.co

NEW: Since the advent of LLMs experts have warned that AI would usher in an era of countless bugs, putting pressure on defenders to keep up with hackers. We are starting to see hard data backing up that prediction. In just one month, Google fixed as many bugs in Chrome as in the previous two years.

Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI | TechCrunch

As experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and ...

techcrunch.com

NEW: OpenAI’s hack against Hugging Face was novel because it was fully autonomous and AI-powered, but the rogue agent acted mostly human-like. And Hugging Face could have done a better job at spotting and stopping the attack with better traditional cybersecurity defenses, experts explained.

In the Hugging Face breach, OpenAI's hacker was noisy and fast — but not unstoppable | TechCrunch

Cybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.

techcrunch.com

Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.

Kevin Beaumont (@GossiTheDog@cyberplace.social)

Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...

cyberplace.social

This is a great explainer of the OpenAI hack against Hugging Face, particularly of the report that the latter published earlier this week. If you had trouble parsing the highly technical report, this article can walk you through it.

The Hugging Face AI break-in, as told through an increasingly committed bear metaphor | TechCrunch

Another way to think about the whole thing is to picture a bear at a campsite. (Really, we are going there.)

techcrunch.com

NEW: After Redditors and journalists found an untold number of Claude chats publicly available on Google, Anthropic blamed the users. The company told us that share links only appear in search results when they’ve been posted somewhere search engines can see, like a forum or on social media.

PSA: Your Claude shared chats and Artifacts may have ended up on Google | TechCrunch

An untold number of Claude chats and Artifacts — the interactive mini apps and documents users can build inside Claude — were found publicly searchable on

techcrunch.com

NEW: I delved into the mystery of Phineas Fisher, probably the most prolific and public hacker never to have gotten caught. This is what we know about the infamous hacktivist and their spectacular hacks against spyware makers FinFisher and Hacking Team. There will be even more in my upcoming book.

The hacker who humiliated spyware makers and was never caught | TechCrunch

An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?

techcrunch.com

NEW: I spoke to several offensive cybersecurity researchers, including zero-day developers, about how the guardrails imposed by OpenAI and Anthropic on AI models are impeding their work. Most complained the guardrails are inconsistent and too strict, which pushes them to use open source models.

How AI guardrails are impeding the work of offensive cybersecurity researchers | TechCrunch

We spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work.

techcrunch.com

"An entire generation of young creatives were paid to dump terabytes of posts and videos in a black hole, trying to entertain users long enough to be surveilled and train AI. And not only do they have nothing to show for it professionally, they have nothing to show for it creatively, as well."

Ryan Broderick@ryanhatesthis.bsky.social · 2w ago

I wrote about the lost decade of millennial creativity www.garbageday.email/p/you-get-wh...

U.S. says Iranian hackers are upping their hacks on American water and energy providers to "cause disruptive effects within the United States." FBI, NSA & CISA say the critical infrastructure breaches are in response to the Iran war (no shit). Bypass for ad-blockers: web.archive.org/web/20260723...

US government says Iran-linked hackers are disrupting American water and energy providers | TechCrunch

An updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.

techcrunch.com

Zero-day startup Paradigm Shift took down the blog post and corresponding Proof-of-Concept code for the iPhone flaw they dubbed Usbliter8. Takedown comes following a judge order in the lawsuit filed by Magnet Forensics, which alleges a former employee now at the startup stole the flaw.

Bild

NSO Group spent at least $67,500 on lobbying 🇺🇸Congress and U.S. federal agencies in Q1 and Q2 of 2026, through its executive chairman, David Friedman – the former US ambassador to Israel – according to the latest lobbying disclosure filings.

BildBild

NEW: OpenAI said it built a “highly isolated” environment to test a model that then went rogue and autonomously hacked Hugging Face. According to cybersecurity experts, the company made a human mistake—one expert called "a massive control failure"— that led to the unprecedented AI-enabled attack.

How an OpenAI’s human mistake led to the AI-powered hack on Hugging Face | TechCrunch

OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Huggin...

techcrunch.com

Woof. That data breach at Suno AI last year but only just disclosed last week, affected over 55 million users, including their names, physical addresses, and phone numbers, according to Have I Been Pwned. Bypass for ad-blockers: web.archive.org/web/20260721...

AI music generator Suno breach affects 55M users, per Have I Been Pwned | TechCrunch

A hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.

techcrunch.com

Today at 12 pm ET: 404 Media's @jasonkoebler.bsky.social and @josephcox.bsky.social are taking your questions about Flock. Recently, 404 reported on how cops use Flock cameras to track people, how the company leaked cops' license plate searches, and pushback from communities. Join our AMA 👇

From the pwnhub community on Reddit: We're Jason Koebler and Joseph Cox of 404 Media. We broke the story on Flock leaking cops' license plate searches. Ask us anything about surveillance, ALPRs, and i...

Explore this post and more from the pwnhub community

reddit.com

The fact that *this* Spain — a team where kids whose parents are from Africa are some of the best in the squad — won in front of Donald Trump is kind of poetic. Spain still has huge problems with racism, but this team reflects a new beautiful reality that deserves to be celebrated.

Dom Ervolina@dominicervolina.com · 2w ago

Nico Williams Jr. presenting his World Cup medal to his mother She crossed the Sahara while pregnant with his older brother, Iñaki, to make a better life for her children

NEW: Hackers are currently exploiting two critical WordPress flaws, which were patched on Friday, to remotely hack and take over websites, according to several cybersecurity firms. Around 90 million websites could still be vulnerable, according to an estimate by a security researcher.

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch

Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

techcrunch.com

NEW: The FBI arrested a 21-year-old student accused of uploading malware-laden video games on Steam, infecting thousands of victims, and then stealing $220,000 in crypto from some of them. The man, Zyaire Wilkins, worked with unnamed co-conspirators to publish at least five malware-embedded games.

FBI arrests man accused of using Steam games to drain victims' crypto wallets | TechCrunch

Prosecutors accused 21-year-old student Zyaire Wilkins of publishing on Steam several fake video games that contained malware, infecting thousands of victims, and stealing crypto from some of them.

techcrunch.com