Lorenzo Franceschi-Bicchierai

8.5K Followers
1.8K Following
1.2K Posts

Real-time cyber historian of the late capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies.

Also writing a book about Hacking Team and the history of government spyware.

Posts about infosec, surveillance by day. 🍕, ⚽️, 🎸, 🎮 by night. 


☎️ Signal: +1 917 257 1382

💻 Keybase/Telegram: @ lorenzofb

✉️ [email protected]

Previously: VICE Motherboard, Mashable, WIRED's Danger Room.

Twitterhttps://twitter.com/lorenzofb
Personal Sitehttps://lorenzofb.com
PronounsHe/him
Searchable viatootfinder
TechCrunchhttps://techcrunch.com/author/lorenzo-franceschi-bicchierai/

UPDATE: The FBI has confirmed the hack of director Kash Patel's personal gmail account, says the leaked data "is historical in nature and involves no government information."

https://techcrunch.com/2026/03/27/iranian-hackers-claim-breach-of-fbi-director-kash-patels-personal-email-account/

NEW: Iranian-linked hackers claim to have breached the personal Gmail account of FBI director Kash Patel, leaking emails and photos.

We were able to confirm that at least a portion of the emails are authentic.

The U.S. has accused Iran's government of being behind the hacking group Handala.

https://techcrunch.com/2026/03/27/iranian-hackers-claim-breach-of-fbi-director-kash-patels-personal-email-account/

Iranian hackers claim breach of FBI director Kash Patel's personal email account | TechCrunch

Handala, a pro-Iranian hacking group allegedly working for Iran’s government, published emails it said were taken from the Gmail account of FBI director Kash Patel.

TechCrunch

SCOOP: Apple says it's not aware of anyone using Lockdown Mode getting hacked with spyware, on all kinds of devices.

There have already been a couple of documented cases of Lockdown Mode stopping spyware attacks. And there's been one case where an advanced hacking toolkit was designed to bail out if it detected Lockdown Mode on the target device.

If you're worried about spyware, you should use turn this security feature on.

https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/

Apple says no one using Lockdown Mode has been hacked with spyware | TechCrunch

The tech giant's claim that it has not seen any successful spyware attacks targeting Apple devices with Lockdown Mode enabled comes amid a leak of hacking tools targeting users running devices with older software.

TechCrunch
I may have to post this on X unfortunately.
Who is the Chaouki of the zero-day industry these days?

NEW: We spoke to a few iPhone security experts about what the discovery of DarkSword means to the long-held assumption that iPhones are very hard to hack.

The answer is nuanced, and not simple. Apple has made significant strides in making iPhones more secure, but DarkSword may change how we think.

http://techcrunch.com/2026/03/26/apple-made-strides-with-ios-26-security-but-leaked-hacking-tools-still-leave-millions-exposed-to-spyware-attacks/

Apple made strides with iOS 26 security, but leaked hacking tools still leave millions exposed to spyware attacks | TechCrunch

Leaked hacking tools threaten the security of millions of older iPhones. Cybersecurity experts weigh in.

TechCrunch

A former Trenchant employee told us that when Triangulation was first revealed, other employees at the company believed that at least one of the zero-days caught by Kaspersky “were from us."

Also both Kaspersky and Trenchant seemed to wink at the fact that they both knew.

https://techcrunch.com/2026/03/10/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine/

Kaspersky has linked Coruna with Operation Triangulation. This somes a few weeks after we reported that L3Harris Trenchant was the company behind some components of Coruna.

And we also reported that it was possible Coruna was used in Operation Triangulation.

https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/

Coruna: the framework used in Operation Triangulation

Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the Operation Triangulation exploit.

Kaspersky

NEW: Here's everything you need to know about the new iPhone hacking tool DarkSword.

What is DarkSword? How does it work? Where did it come from? How did it leak online? What can you do about it?

We break it all down in this explainer.

http://techcrunch.com/2026/03/26/a-major-hacking-tool-has-leaked-online-putting-millions-of-iphones-at-risk-heres-what-you-need-to-know/

A major hacking tool has leaked online, putting millions of iPhones at risk. Here’s what you need to know. | TechCrunch

Here’s what we know, and what you need to know, about Coruna and DarkSword, two advanced iPhone hacking tools discovered by security researchers. DarkSword has now leaked online.

TechCrunch

NEW: Russian state media says police have arrested an unnamed person that's alleged to be the creator and founder of cybercrime forum LeakBase.

Europol, which shut down LeakBase earlier this month, said it did not cooperate with Russia on this arrest.

https://techcrunch.com/2026/03/25/russia-arrests-alleged-owner-of-cybercrime-forum-leakbase-report-says/

Russia arrests alleged owner of cybercrime forum LeakBase, report says | TechCrunch

Russian state-owned media reported that police in Russia arrested the administrator of LeakBase, a large hacking forum.

TechCrunch