Lorenzo Franceschi-Bicchierai

Real-time cyber historian of the late capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies.

Posts about infosec, surveillance by day. 🍕, ⚽️, 🎸, 🎮 by night. 


☎️ Signal: +1 917 257 1382
💻 Keybase/Telegram: @ lorenzofb
✉️ lorenzo@techcrunch.com


Previously: VICE Motherboard, Mashable, WIRED's Danger Room.

Lorenzo Franceschi-Bicchierai boosted:
Zack Whittakerzackwhittaker
2025-11-21

New, by me and @lorenzofb: CrowdStrike has confirmed it fired a "suspicious insider" who passed screenshots of company systems to a prolific hacking group — which then went on to post them publicly.

More: techcrunch.com/2025/11/21/crow

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-21

NEW: Google says the new wave of supply chain attacks by Scattered Lapsus$ Hunters impacted more than 200 companies' Salesforce-stored data.

This wave of breaches of Gainsight customers was caused by a previous breach at Salesloft Drift, ShinyHunters told us.

Hackers said they breached Atlassian, CrowdStrike, Docusign, F5, Gitlab, Linkedin, Malwarebytes, Sonicwall, Thomson Reuters, Verizon.

Malwarebytes said it is investigating.

CrowdStrike said company is "not affected."

techcrunch.com/2025/11/21/goog

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-20

@DJGummikuh @krypt3ia ha! I never noticed that

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-20

NEW: Salesforce says said it’s investigating an incident where hackers compromised some of its customers' data after breaching customer experience company Gainsight.

Notorious hacking group ShinyHunters has reportedly claimed responsibility for this new wave of data breaches.

techcrunch.com/2025/11/20/sale

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-20

@DJGummikuh @krypt3ia Wait, where do they tell you that?

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-20

@DJGummikuh @krypt3ia My favorite was the one that sorta explains Kusanagi's childhood, very well done.

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-19

@DJGummikuh @krypt3ia I loved them. Obviously lots of filler episodes but lots of great episodes too.

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-19

@krypt3ia I was thinking that I should rewatch that saga

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-19

NEW: The classic anime "Ghost in the Shell," one of the most influential hacking movies of all time, turned 30 years old this week.

Despite coming out at the dawn of the internet, it was incredibly prescient in terms of imaginig a future where governments use hackers for espionage, people use malware to spy on their loved ones, and much much more.

The story of the “infamous mystery hacker” the Puppet Master has many fascinating bits of speculative fiction related to hacking that are worth reflecting on.

techcrunch.com/2025/11/19/how-

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-18

NEW: Internet infrastructure giant Cloudflare blamed this morning's massive internet outage on a "latent bug."

This is another stark reminder that the internet depends on just a handful of companies. According to an estimate, Cloudflare is used by 20% of all websites on the internet.

techcrunch.com/2025/11/18/clou

Lorenzo Franceschi-Bicchierai boosted:
Zack Whittakerzackwhittaker
2025-11-17

New, by me: Protei, a Russian-founded telecoms provider and supplier of surveillance and web monitoring technologies, was breached, its website defaced, and its servers raided.

"Another DPI/SORM provider bites the dust," read the company's defaced website.

techcrunch.com/2025/11/17/surv

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-17

NEW: Delivery giant DoorDash disclosed a data breach impacting an unspecified number of users.

Hackers stole names, emails, phone numbers, and physical addresses, but DoorDash said that “no sensitive information was accessed by the unauthorized third party." 🤔

techcrunch.com/2025/11/17/door

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-14

The Cyber Police Department of Ukraine sent this email to me, @zackwhittaker, and some other cyber journalists.

Basically, it seems they are asking for help going after hackers expecting journalists to share information we would never share with law enforcement. Nope, this is not how it works.

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-14

NEW: Five people who live in the U.S. pleaded guily for "facilitating" and helping the North Korean regime place fake remote IT workers inside American companies.

U.S. Department of Justice said their actions affected 136 U.S. companies and netted Kim Jong Un’s regime $2.2 million in revenue.

techcrunch.com/2025/11/14/five

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-13

NEW: Authorities from nine countries took down three cybercrime operations, including the Rhadamantys infostealer, which allegedly had access to the crypto wallets of more than 100,000 victims.

This is the latest round of the ongoing Operation Endgame, which is starting to feel like "whack-a-mole forever," as one security researcher involved in the operation put it.

techcrunch.com/2025/11/13/poli

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-12

NEW: Cybersecurity firm Deepwatch laid off around 80 people citing AI the reason.

CEO John DiLullo said the company “is aligning our organization to accelerate our significant investments in AI and automation.”

A current employee said that Deepwatch is “doing something with AI and agentic AI but it sounds like bullshit.”

techcrunch.com/2025/11/12/cybe

Lorenzo Franceschi-Bicchierai boosted:
Zack Whittakerzackwhittaker
2025-11-12

Looks like Elon Musk botched X's passkey and security key switchover, and users are reporting that they're getting stuck in endless loops and, in some cases, getting locked out of their accounts.

techcrunch.com/2025/11/12/elon

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-12

NEW: A group of Senators and Congresspeople are warning Governors that their states are providing ICE “with frictionless, self-service access to the personal data of all of your residents.”

The data sharing is managed by a nonprofit called Nlets, which is managed by state police agencies.

techcrunch.com/2025/11/12/lawm

Lorenzo Franceschi-Bicchierai boosted:
Zack Whittakerzackwhittaker
2025-11-11

We used to think of government spyware targeting only a select few, like terrorists and organized criminals.

But over years, government spyware has been used to hack the phones of journalists, activists, lawyers, politicians, and seemingly regular people — and the pool of victims targeted by governments is quite wide, and larger than people might think.

Here's an explainer by @lorenzofb as to why.

techcrunch.com/2025/11/10/why-

Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-11-10

NEW: I tried to explain why there are so many victims of spyware, despite the fact that its makers have been telling us for years that the tech is only intended to be used in limited cases.

There are several reasons, including how the spyware systems are designed, how powerful and easy to use they are.

techcrunch.com/2025/11/10/why-

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst