Sign in

Lorenzo Franceschi-Bicchierai

@lorenzofb.bsky.social
19K followers 2.6K following 1.1K posts

Real-time historian of the late cyber capitalist era, writing about the intersection of hackers, human rights, and spies. Writing a book about Hacking Team and the history of government spyware. ☎️ Signal: @LorenzoFB.1337 (+1 917 257 1382) lorenzofb.com

PostsRepliesMedia
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 21h
If you're still running iOS, iPadOS, or macOS 26 (which is still the majority of Apple users!) then update today: Apple says hackers may be abusing a bug to target some users' devices. Bypass for ad-block users: web.archive.org/web/20260929...
techcrunch.com
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
01312
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 28/09/2026
Apple has released a security update for iPhones and iPads running the older iOS/iPadOS 26 software, fixing a bug that Apple says was "exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta discovered the flaw/attack.
support.apple.com
About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support
This document describes the security content of iOS 26.7.1 and iPadOS 26.7.1.
01611
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 28/09/2026
Spyware maker Paragon is reportedly going public. "Paragon and REDLattice generated combined revenue of $267 million in the 12 months ended June 2026, representing a 29% increase from the same period a year earlier." www.calcalistech.com/ctechnews/ar...
calcalistech.com
Israeli cyber company Paragon to go public through Nasdaq SPAC merger at $1.25 billion valuation | CTech
The company and U.S. partner REDLattice generated $267 million in combined revenue over the past year, up 29%.
197
Reposted by Lorenzo Franceschi-Bicchierai
Joseph Cox @josephcox.bsky.social · 28/09/2026
New from 404 Media: the group that hacked the FBI and stole data on "all FBI employees" says it won't publish the data. The group gave the FBI a one week countdown. Now says won't publish at all. Still represents a massive national security/counterintelligence risk www.404media.co/fbi-hackers-...
404media.co
FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data
ShinyHunters, the group that stole data on “all FBI employees” including addresses and details on their spouses, told 404 Media on Monday “Since the very beginning we had made our decision that we wou...
79531
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/09/2026
Italian zero-day maker Dataflow Security generated €63 million in revenue in three years, and the company also has strong ties with former Israeli intelligence veterans, according to an investigation by @irpimedia.eu. irpimedia.irpi.eu/en-inside-th...
irpimedia.irpi.eu
Inside the secretive cyberweapons company that won over Israel’s intelligence elite
Founded in Italy by a young hacker, Dataflow develops code to break into computers and smartphones. Since January, its operations in Israel have been led by Eyal Tsir Cohen, a former senior Mossad off...
0147
Reposted by Lorenzo Franceschi-Bicchierai
Joseph Cox @josephcox.bsky.social · 23/09/2026
New: from 404 Media. The catastrophic FBI hack also exposed the FBI's own hacking unit. The Remote Operations Unit is a highly secretive part of the FBI, responsible for making tools to break into peoples' devices. Some of their names and addresses are in the data www.404media.co/fbi-hack-exp...
404media.co
FBI Hack Exposed FBI’s Own Hacking Unit
The FBI's Remote Operations Unit (ROU) is a highly secretive team of hackers making exploits and tools to break into target’s devices. Some of its members just got exposed.
13324128
Reposted by Lorenzo Franceschi-Bicchierai
Joseph Cox @josephcox.bsky.social · 22/09/2026
New: hackers say they have personal data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk www.404media.co/we-hacked-th...
404media.co
‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.
1351367582
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/09/2026
~ Personal news ~  I left TechCrunch. I will now focus on finishing my book about Hacking Team and the history of government spyware. After that, and in the meantime as well, I will be freelancing. Contact me: Lorenzofb.writes@gmail.com or Signal @LorenzoFB.1337 (+1 917 257 1382)
A masked puppet comes out of a keyboard.
89624
Reposted by Lorenzo Franceschi-Bicchierai
Joseph Cox @josephcox.bsky.social · 14/09/2026
New from 404 Media: humans are reading ChatGPT conversations. OpenAI has hired an army of contractors who read real ChatGPT users' chats. I've seen internal docs, the review system, and real user prompts. Sometimes they contain very personal and sensitive information www.404media.co/inside-proje...
404media.co
Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats
Humans are reading ChatGPT users’ prompts to improve OpenAI’s models, and those chats can include sensitive, personal information, according to leaked internal documents and real prompts seen by 404 M...
561998985
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 12/09/2026
Last night I paid $40 (plus tip) for a pizza margherita. I am reporting the pizzeria to the Italian authorities. No pizza should cost that much.
4270
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 01/09/2026
New: Florida and Texas are moving to block or end their use of license plate surveillance tech, like Flock, citing privacy concerns and police abuse. The backlash against Flock is both growing and increasingly bipartisan. Bypass for ad-blockers: web.archive.org/web/20260901...
techcrunch.com
Florida and Texas move to block Flock cameras over privacy concerns | TechCrunch
Flock's searchable network of 130,000 license plate cameras around the U.S. have sparked bipartisan privacy and civil liberties concerns.
56231
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 31/08/2026
NEW: Could AI make software so secure that it will make it harder for governments to use hacking tools and spyware? To try to answer that question, I spoke to cybersecurity and privacy experts, and people with experience finding and exploiting security flaws that can be then sold to governments.
techcrunch.com
How AI could make it harder for governments to use hacking tools | TechCrunch
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.
068
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 30/08/2026
In this.weekinsecurity.com: Medical device maker Boston Scientific hit by destructive hack; Aussie cops nab TeamPCP hackers; GTA 6 leaks are breaking the web; how journalists used a website bug to trace a prolific scammer; and the DOJ walks back Chinese botnet hack claims; plus, much more.
this.weekinsecurity.com
this week in security — august 30 2026 edition
Boston Scientific knocked offline in major hack, U.S. seizes Chinese botnet, Australia arrests PCPTeam hackers, U.S. water hacks broader than first disclosed, Grand Theft Auto VI hit by leaks, Russia ...
1165
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 29/08/2026
Imagine going out for a chill night out and this happens. www.vice.com/en/article/i...
vice.com
I Played 'The Boys Are Back in Town' on a Bar Jukebox Until I Got Kicked Out
The boys were back in town, but I was out of the bar, because they asked me to leave.
191
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 27/08/2026
NEW: I recapped all the times AI agents went “rogue”—so to speak—and hacked third parties. There have been 17 cases already, with OpenAI and Anthropic leading the race, per a website keeping tally. And those are the ones we know about. I apologize for all the whoopses that appear in this article.
techcrunch.com
Here’s all the times AI has gone rogue and hacked other companies | TechCrunch
A recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet.
1299
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 24/08/2026
NEW: Alabama launched an investigation into OpenAI's Hugging Face hack, saying “this AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical.” techcrunch.com/2026/08/24/a...
techcrunch.com
Alabama launches investigation into OpenAI's hack of Hugging Face | TechCrunch
Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.
11310
Reposted by Lorenzo Franceschi-Bicchierai
Retro Computers @retrocomps.bsky.social · 23/08/2026
You've stumbled into an unknown computer system. Now what? (Source.)
An image for Hacker, from the October 1985 issue of Amstrad Action. Top left: "HACKER. You've stumbled into an unknown computer system. Now what?" Center, a man looks over his commodre 64 late at night and chews his pen, an unfamiliar interface on the screen. Bottom: "'Logon'. One word appears on your screen. What do you do now? You don't know the password. You don't even know what computer system you've hacked into. But you do know that you must find out more. There are no instructions. No rules. No clues. You're completely on your own. You've found your way in. But is there a way out?"
98419
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/08/2026
I know spyware is not exactly a mainstream issue. But having the chance to interview Giorgia Meloni, and not ask her about the spy scandal her intelligence agencies are likely responsible for, is such a missed opportunity. www.nytimes.com/2026/08/21/w...
nytimes.com
Giorgia Meloni Cuts the Hard Right a Path to Power (Gift Article)
In a rare interview, the onetime political outcast reflects on her route from “the uncomfortable side of history” to the threshold of leading Italy’s most durable postwar government.
1308
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 21/08/2026
New, by me: Private equity giant Apollo Global says hackers stole personal information, including Social Security numbers, during a July breach. The hack comes after Google researchers warned that an extortion gang targeted financial giants. Ad-block bypass: archive.is/BucaL (Wayback not working)
techcrunch.com
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants | TechCrunch
The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.
0205
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/08/2026
NEW: Sen. Ron Wyden is asking a U.S. government watchdog to review how federal law enforcement agencies are using hacking tools and spyware in their investigations. Wyden is worried about federal agents abusing them, the risk of dangerous leaks like the Peter Williams/Trenchant case, and more.
techcrunch.com
Senator asks US government watchdog to review how feds use hacking tools | TechCrunch
Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans.
12510
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/08/2026
I just made chickpea pasta with garlic, kale, chipotle mayo, and parmigiano. Not bad. Not bad at all. I recommend it. Hopefully I don't get my Italian passport revoked.
2110
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 20/08/2026
NEW: Someone tried to hack cybersecurity researchers inviting them to a fake cryptocurrency conference. The hacker used a real Google Doc, and a legitimate Google platform that allows developers to customize the user interface of documents, to try to trick targets into downloading malware.
techcrunch.com
Someone targeted security researchers using a fake crypto conference as a lure | TechCrunch
A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware.
0125
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 19/08/2026
NEW: OpenAI mistakenly revoked several security researchers' access to its limited cybersecurity program “Trusted Access for Cyber.” They now have to reapply and submit a government ID again. The company blamed it on “a technical issue” that affected “a limited set of users.”
techcrunch.com
Researchers complain that OpenAI revoked their access to limited cyber program | TechCrunch
Multiple cybersecurity researchers said they suddenly lost access to OpenAI’s Trusted Access for Cyber (TAC) program, which offers models with fewer guardrails for vetted users.
0125
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 18/08/2026
Apropos of what I was talking about yesterday.
3299
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 17/08/2026
Since chatbots, LLMs, and the use of AI to craft legal arguments are back in the news again, I thought I'd re-up this piece I wrote for paid subscribers of this.weekinsecurity.com on if, and how, privilege applies during legal cases. It depends!
this.weekinsecurity.com
When AI chatbots and LLMs get legal, check your privilege
Using AI tools and LLMs for sensitive matters, such as for legal and medical uses, raises important questions about where that data goes and who can access it.
0159
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 17/08/2026
It's good that Apple sends these threat notifications to spyware victims as it offers *some* transparency to who gets attacked by gov'ts. But it's also not great to see the number of threat notifications at "unprecedented" levels as it shows spyware use continues to prolifierate.
1228
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 17/08/2026
NEW: An "unprecedented" number of people have received Apple's latest notifications alerting them they were targeted with mercenary spyware, according to security researchers. A soldier fighting in Ukraine told us he knows of other soldiers getting them. Lots of posts on social media too.
techcrunch.com
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators | TechCrunch
Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.
13831
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 17/08/2026
I reluctantly have to admit that since X toggled with the algorithm recently (don't remember when exactly) my timeline is now again filled with cybersecurity posts. There's much less spam and random posts. I can also confirm that most of the infosec industry is either back there or never left.
18282
Reposted by Lorenzo Franceschi-Bicchierai
Emanuel Maiberg @emanuelmaiberg.bsky.social · 17/08/2026
We put a tracking device in a shipment of rare books acquired by an anonymous buyer. It ended up at an Amazon facility where the company scans books for training data and destroys them in the process: www.404media.co/we-tracked-a...
404media.co
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.
391572914
Reposted by Lorenzo Franceschi-Bicchierai
TechCrunch @techcrunch.com · 17/08/2026
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
techcrunch.com
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
The hacks at shipping companies used to mail out hardware wallets puts crypto owners at greater risk of real-world attacks.
2185
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 16/08/2026
My hot take about the Strokes, since you’ve asked, is that of all those bands of that era, they’re kinda the only one still worth listening to. Like they’re so much better than all others.
150
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 15/08/2026
Every Sunday in my newsletter this.weekinsecurity.com, I hand-curate all the most important cyber stories you need to know from the week, and deliver it up with good news and a reader-submitted cyber cat (or friend). No slop, and no email open/link tracking (for your privacy!) Sign up/RSS below. 🐈‍⬛
this.weekinsecurity.com
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
0228
Reposted by Lorenzo Franceschi-Bicchierai
Danny Moore @moore.bsky.social · 14/08/2026
These kinds of attacks, which are loud, aggressive, and have limited real-world effects, are basically a form of psychological terrorism. It's much more about fear and pressure than it is casualties.
2197
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 14/08/2026
NEW: Here's what we know, and don't know, about the cyberattacks that have hit water plants across at least 12 states in the U.S. in the last couple of weeks. The wave of attacks, allegedly carried out by Iran's government, are more widespread than previous attacks on critical infrastructure.
techcrunch.com
What we know about the alleged Iranian hacks on U.S. water utilities | TechCrunch
Over the last couple of weeks, hackers have targeted and broken into the systems of several water plants in the United States. Here’s what we know and don’t know about this wave of attacks allegedly c...
04326
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 14/08/2026
NEW: U.S. courts will start publishing data on how many times the feds do wiretaps using spyware and hacking tools, starting in 2029. As of now, we knew the FBI and others used spyware, but we had no idea how many times that was happening. Change comes after several requests from Sen. Ron Wyden.
techcrunch.com
US courts will start publishing how often the government uses spyware | TechCrunch
The Administrative Office of the U.S. Courts told TechCrunch that it will start disclosing how many times judges authorized the use of spyware to wiretap suspected criminals.
615561
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 13/08/2026
New, by me: Apple told me it's sending out threat notifications to customers in 110 countries saying they've been targeted with spyware. This latest batch also features a new push notification, warning users to take action and what to do next. Bypass for ad-blockers: web.archive.org/web/20260813...
techcrunch.com
If Apple sends you a push notification alerting you to a spyware attack, take it seriously | TechCrunch
Apple now sends out push notifications to iPhone lock screens when the company identifies government spyware targeting someone's devices.
213888
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 13/08/2026
NEW: Flock announced new changes that it claims will help stop cops from abusing its license plate reader cameras, including a now mandatory feature called Audit Assistance. But the company isn’t explaining exactly how the tool works. A spokesperson told us it does not use machine learning or AI.
techcrunch.com
Flock says its new tool will help identify police abuse, but hasn’t explained how it works | TechCrunch
The surveillance company announced it's making a tool called "Audit Assistance" mandatory for all customers, claiming it's already helped catch abuse. But the company has yet to explain how the tool w...
2167
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 13/08/2026
Apple is reportedly sending a new batch of notifications alerting targets of spyware. If you have received one, we wrote a post on what to do next, and how to get help. You can also contact me directly on Signal at +1 917 257 1382. techcrunch.com/2025/12/29/y...
210354
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 12/08/2026
New: A security researcher called Nightmare Eclipse has published details of a new zero-day bug in Windows, seemingly undettered by Microsoft's legal threat earlier this year. The bug affects latest versions of Windows, and currently no patch. Bypass for ad-blockers: web.archive.org/web/20260812...
techcrunch.com
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
23914
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 13/08/2026
New, by me: For the first time, the Trump administration says it's going to allow some vetted U.S. private companies to launch cyberattacks and surveillance operations against overseas criminals and hackers, like ransomware gangs. Ad-block bypass: web.archive.org/web/20260813...
techcrunch.com
In a first, US will allow some private firms to carry out cyberattacks | TechCrunch
The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.
115428
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 11/08/2026
NEW: The FBI is warning of cybercriminals hacking into accounts to steal intimate and explicit images, in attempts to extort or then sell the stolen media. These crimes have been happening for a long time, but this alert suggests the FBI has seen a recent rise.
techcrunch.com
FBI says cybercriminals are hacking into victims' online accounts to steal their intimate pictures | TechCrunch
In a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns.
195
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 11/08/2026
NEW: Someone jammed the in-flight Wi-Fi on a Delta plane after the Def Con hacking conference in Las Vegas and replaced it with a malicious network. Pilots alerted air traffic control: “We believe they are trying to scam the [other passengers].” Delta said it will investigate along with the feds.
techcrunch.com
Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch
The Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.
1329
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 11/08/2026
Join me and @runasand.bsky.social for a Reddit AMA (Ask Me Anything) on Weds 5pm PT about the first-of-its-kind prosecution of an American who allegedly gave border agents a "duress" password that wiped his phone. Raises big q's about constitutional rights & what you can & can't do at the border. 👀
reddit.com
From the pwnhub community on Reddit: We are TechCrunch security editor Zack Whittaker and security researcher Runa Sandvik. Ask us anything about the American charged with a felony for wiping his phon...
Explore this post and more from the pwnhub community
1259
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 10/08/2026
NEW: I spoke to Google's @shanehunt.bsky.social about why hacking groups get codenames, and why that's an important step in not only tracking their attacks, but also understanding how to counter them. In 2026, this is not an easy job. Google now tracks more than 5,000 "activity clusters."
techcrunch.com
Google's top hacker hunter explains why hacking groups get codenames | TechCrunch
Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codena...
1168
Reposted by Lorenzo Franceschi-Bicchierai
Runa Sandvik @runasand.bsky.social · 10/08/2026
ICYMI I’m hosting a Reddit AMA with @zackwhittaker.com on Wednesday to answer questions about US border searches, device security, and protecting your digital data. I'll be posting as runasand_. www.runasandvik.com/p/waypoints-...
runasandvik.com
Waypoints: About Reddit AMA, China’s shadow war, and restaurant recommendations
I’m hosting a Reddit AMA with Zack Whittaker of TechCrunch on r/pwnhub on Wednesday, August 12 at 5PM PT!
01711
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 10/08/2026
Bill Swearingen spent the past year developing a pattern that can block surveillance camera detections, including vehicles and people. At Def Con, for the first time, he demoed the pattern printed on a car against a Flock camera to prove it works. Ad-blocker bypass: web.archive.org/web/20260810...
techcrunch.com
This 'adversarial' pattern can prevent surveillance cameras from detecting you | TechCrunch
A security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras.
98418
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 09/08/2026
For those who have already played it: does Death Stranding 2 get significantly better after the first few missions? I loved the first one and I get that you have to do a bit of tutorial, but so far I have found this a bit boring and samey. Should I stick with it?
210
Reposted by Lorenzo Franceschi-Bicchierai
Zack Whittaker @zackwhittaker.com · 09/08/2026
In today's this.weekinsecurity.com: The best from Black Hat, Def Con, and BSides Vegas (if you didn't go!); inside a China police spy dashboard; AI notetaker app exposed call recordings; Apple Private Relay leaked IP addresses; hackers predicted a hardware wallet's seed passwords; and much more. 🐈‍⬛
this.weekinsecurity.com
this week in security — august 9 2026 edition
Hackers descend on Las Vegas, U.S. water system hacks are spreading, Samsung bans resproxy apps, offline hardware wallet hacked and crypto stolen, inside a Chinese police surveillance dashboard, AI no...
1227
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 07/08/2026
NEW: Modular computer maker Framework notifies “all” customers that hackers stole their names, email addresses, phone numbers, and physical addresses. Company said all its customers were affected, but declined to say how many. Number of victims is like 10s of thousands or even 100s of thousands.
techcrunch.com
Computer maker Framework notifies 'all customers' of a data breach | TechCrunch
Framework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach.
1124
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 07/08/2026
NEW: Another AI model escaped its supposedly isolated environment in a cybersecurity test. This time it was the model Kimi K3, made by Chinese company Moonshot. At least this time it didn't hack anyone. This is the latest incident of its kind after incidents at OpenAI, Anthropic, Meta and AISI.
techcrunch.com
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say | TechCrunch
In the Kimi test, the sandbox designed to contain the experiment was not properly configured.
4153