Former FBI Special Agent Chris Tarbell and ex-Anonymous/LulzSec blackhat hacker Hector Monsegur (aka Sabu) faced off as adversaries in cyberspace before becoming close friends and podcast co-hosts. Listen to Tarbell, co-founder of the elite cybersecurity firm NAXO, and Monsegur, a top network penetration tester and security engineer, break down the must-know cybersecurity news and topics of the week. You’ll walk away from each episode with unique perspectives on keeping your family, your company, and yourself safe from cyber attacks.

Similar Podcasts

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ThunderCast

ThunderCast
An inside look at the making of Mozilla Thunderbird, and community-driven conversations with our friends in the open-source software space.

A Hack-Back Lands a CEO in Prison, Repo Jacking, and When to Use a VPN

June 30, 2023 1:12:32 0.0 MB Downloads: 0

This week on Hacker And The Fed a CEO did a hack back and was sentenced to prison, Reddit hackers demanded a price roll back, repo jacking and fake Github repositories, and we answer listener questions about Hector's old hacks and VPNs. Links from the episode: I Was Sentenced to 18 Months in Prison for Hacking Back - My Story twitter.com/silascutler/status/1671144482769608705 -> https://hackernoon.com/i-was-sentenced-to-18-months-in-prison-for-hacking-back-my-story   Reddit hackers demand $4.5 million ransom and API pricing changes theverge.com/2023/6/19/23765895/reddit-hack-phishing-leak-api-pricing-steve-huffman   GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking   Attackers Create Synthetic Security Researchers to Steal IP darkreading.com/attacks-breaches/attackers-create-synthetic-security-researchers   Google announces $20 million investment for cyber clinics cyberscoop.com/google-investment-cyber-clinics/   Listener Questions https://fidoalliance.org/   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off

A Massive Ongoing Ransomware Attack, Google Claims to Catch Chinese Hackers, and the Feds Arrest a Russian Hacker in Arizona

June 22, 2023 1:09:50 0.0 MB Downloads: 0

This week on Hacker And The Fed a ransomware group hacked a widely used file transfer software and began leaking stolen data, Google claims it caught Chinese government hackers red-handed breaking into hundreds of networks, the Feds arrest a ransomware perpetrator in Arizona, and we nerd out on security researchers taking over various countries domains. Links from the episode: MOVEit Cyber Attack: Personal Data Of Millions Stolen From Oregon, Louisiana, U.S. Agency forbes.com/sites/maryroeloffs/2023/06/16/moveit-cyber-attack-personal-data-of-millions-stolen-from-oregon-louisiana-us-agency/?sh=3cf2b1b46b05   US govt offers $10 million bounty for info on Clop ransomware bleepingcomputer.com/news/security/us-govt-offers-10-million-bounty-for-info-on-clop-ransomware/amp/ Google claims it caught China government hackers redhanded breaking into hundreds of networks around the world fortune.com/2023/06/15/china-hacking-networks-cybersecurity-google-mandiant/amp/   20-Year-Old Russian LockBit Ransomware Affiliate Arrested in Arizona thehackernews.com/2023/06/20-year-old-russian-lockbit-ransomware.html   Can I speak to your manager? hacking root EPP servers to take control of zones hackcompute.com/hacking-epp-servers/   Darknet Parliament is now a thing cybernews.com/security/darknet-parliament-killnet-hackers/ -- Support our sponsor: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off -- For more information on Chris and his current work visit naxo.com and follow him on LinkedIn. Follow Hector @hxmonsegur

China's Tik Tok "God Credential" Allegation, a New Phishing and Email Takeover Campaign, and Listener Questions

June 15, 2023 1:06:13 0.0 MB Downloads: 0

This week on Hacker And The Fed we discuss the latest development in the Tik Tok controversy, how to detect and mitigate a new phishing and email takeover campaign, Google's new top-level domain, and some interesting statistics in the new Verizon breach investigation report. Links from the episode: Former exec at TikTok's parent company says Communist Party members had a 'god credential' that let them access Americans' data businessinsider.com/communist-party-god-credential-data-bytedance-tiktok-former-executive-alleges-2023-6   Detecting and mitigating a multi-stage AiTM phishing and BEC campaign microsoft.com/en-us/security/blog/2023/06/08/detecting-and-mitigating-a-multi-stage-aitm-phishing-and-bec-campaign/   America’s Most Cybersecure Companies forbes.com/lists/most-cybersecure-companies   Hackers claim to have crippled Russia’s banking system cybernews.com/cyber-war/infotel-hack-impacts-russian-banks/   Verizon 2023 Data Breach Investigations Report verizon.com/business/resources/reports/dbir/ -- Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off -- For more information on Chris and his current work visit naxo.com and follow him on LinkedIn. Follow Hector @hxmonsegur

Zero-click Exploits Attacking iPhones, PC Motherboards Downloading Malware, and a New Dutch Mandate

June 08, 2023 1:05:46 0.0 MB Downloads: 0

This week on Hacker And The Fed we discuss another zero-click exploit attacking iPhones via the iMessage app, millions of PC motherboards may be downloading malware, the FTC slams another company for violations, security researchers find a vulnerability in Gmail's checkmark system that is already being abused. And the Dutch government now mandates an easy way to contact website administrators. Links from the episode: Operation Triangulation: iOS devices targeted with previously unknown malware securelist.com/operation-triangulation/109842/ thehackernews.com/2023/06/new-zero-click-hack-targets-ios-users.html  Millions of PC motherboards were sold with a firmware backdoor arstechnica.com/security/2023/06/millions-of-pc-motherboards-were-sold-with-a-firmware-backdoor/ FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring thehackernews.com/2023/06/ftc-slams-amazon-with-308m-fine-for.html Bug in Gmail twitter.com/chrisplummer/status/1664075886545575941 twitter.com/ChristopheDary/status/1664907465924681728 linkedin.com/posts/christophe-dary-85330561_spf-dmarc-bimi-activity-7070510499196489728-pPTh?utm_source=share&utm_medium=member_desktop Security.txt now mandatory for Dutch government websites netherlands.postsen.com/trends/198695/Securitytxt-now-mandatory-for-Dutch-government-websites.html securitytxt.org -- Support our sponsors: Go to HelloFresh.com/hatf16 and use code hatf16 for 16 free meals plus free shipping! Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off -- For more information on Chris and his current work visit naxo.com and follow him on LinkedIn. Follow Hector @hxmonsegur

An Insider Exploits A Ransomware Attack, AI Photos, And Hector's Indonesian Hack

June 01, 2023 0:57:08 0.0 MB Downloads: 0

This week on Hacker And The Fed we dive into the world of ransomware. An insider exploits a ransomware attack for personal gain and a CISO's biggest lessons from quarterbacking a ransomware attack. We discuss AI generated photos and what happened to the stock market. And then we answer listener questions about geopolitics, Hector's hack on the Indonesian government and victims keeping their hacks a secret.  Links from the episode: IT employee impersonates ransomware gang to extort employer bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/ AI Generated Photos twitter.com/jsrailton/status/1660679743266607105 Suspicion stalks Genesis Market’s competitors following FBI takedown therecord.media/genesis-market-russian-market-2easy-shop-cybercrime-fraud FBI releases warning about fake crypto job advertisements ic3.gov/Media/Y2023/PSA230522 Bridgestone CISO: Lessons From Ransomware Attack Include Acting, Not Thinking darkreading.com/ics-ot/bridgestone-ciso-lessons-ransomware-attack-acting-thinking

Pig Butchering And Crypto Crime-fighting With Erin West

May 25, 2023 0:47:33 0.0 MB Downloads: 0

This week on Hacker And The Fed we speak with Erin West, a Santa Clara County Deputy District Attorney, Founder of the “Crypto Coalition” an over 800-member group of active law enforcement partners sharing cryptocurrency crime-fighting techniques, and the very tip of the spear for Pig Butchering – the latest online romance scam. Erin educates us on what Pig Butchering is and how we can protect ourselves and our loved ones from being victimized. Links from the episode: SCARS: Society of Citizens Against Relationship Scams againstscams.org Advocating Against Romance Scammers advocatingforu.com This podcast is sponsored by BetterHelp. Visit BetterHelp.com/HATF today to get 10% off your first month. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Vehicle Location Data Leaked For Over 2 million Drivers, Another US Government Breach, And D.B. Cooper

May 18, 2023 1:00:05 0.0 MB Downloads: 0

This week on Hacker And The Fed, up to 10 years of your location data may have been exposed if you’ve driven vehicles from a certain manufacturer, stolen private keys may lead to insecure boot ups of your computer, Congress gets another notification of a US government breach, and we answer more listener questions about failed hacks and intentional exploits. And we talk about D. B. Cooper! Links from the episode: Toyota: Car location data of 2 million customers exposed for ten years bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/ Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security securityonline.info/intel-oem-private-key-leak-a-blow-to-uefi-secure-boot-security/ Data of 237,000 US government employees breached reuters.com/world/us/data-237000-us-government-employees-breached-2023-05-12/ Mastermind Behind Twitter 2020 Hack Pleads Guilty and Faces up to 70 Years in Prison ustice.gov/opa/pr/uk-citizen-extradited-and-pleads-guilty-cyber-crime-offenses T-Mobile Worker Joked About Adding Extra Phone Lines and Tablet to a Customer’s Account Without Them Knowing twistedsifter.com/2023/05/a-t-mobile-worker-joked-about-adding-2-extra-phone-lines-and-a-tablet-to-a-customers-account-without-them-knowing/ Google Cybersecurity Certificate grow.google/certificates/cybersecurity/#?modal_active=none -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Chinese State Hackers, Ransom Negotiation, And Listener Questions

May 11, 2023 0:59:55 0.0 MB Downloads: 0

This week on Hacker And The Fed we discuss private data leaking due to a misconfiguration, and no one is listening to the researchers. We are shown the mindset of hackers during a ransom negotiation, a cell phone provider is hacked for the 9th time in 6 years, there are 50 Chinese state hackers for every FBI cyber agent, and using AI to help hack. And finally, we answer listener questions about .xyz, pen testing tools, and possible Hacker And The Fed swag. Links from the episode: Many Public Salesforce Sites are Leaking Private Data krebsonsecurity.com/2023/04/many-public-salesforce-sites-are-leaking-private-data/ Hackers Claim Vast Access to Western Digital Systems techcrunch.com/2023/04/13/hackers-claim-vast-access-to-western-digital-systems/ T-Mobile Discloses 2nd Data Breach of 2023, This One Leaking Account PINs and More arstechnica.com/information-technology/2023/05/t-mobile-discloses-2nd-data-breach-of-2023-this-one-leaking-account-pins-and-more/ Chinese Hackers Outnumber FBI Cyber Personnel 'By At Least 50 to 1,' Wray Testifies foxnews.com/politics/chinese-hackers-outnumber-fbi-cyber-personnel-wray-testifies Capturing the Flag with GPT-4 micahflee.com/2023/04/capturing-the-flag-with-gpt-4/ The Cyber Police Exposed an Attacker in the Sale of Databases with Personal Data of Citizens of Ukraine and the EU cyberpolice.gov.ua/news/kiberpolicziya-vykryla-zlovmysnyka-u-zbuti-baz-iz-personalnymy-danymy-gromadyan-ukrayiny-ta-yes-6598/ -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Cyber Insurance With Michelle Chia, Head Of Cyber Insurance At Zurich North America

May 04, 2023 0:47:02 0.0 MB Downloads: 0

This week on Hacker And The Fed we sit down with Michele Chia, Head of Cyber Insurance at Zurich North America. We ask a number of questions including what is cyber insurance? Who needs it? And How much coverage is needed? Does cyber insurance cover an insider threat attack? What does a ransomware attack look like when you have cyber insurance? And finally, we find out how our guest cultivated such a successful career in cyber insurance. Link from the episode: zurichna.com/knowledge/experts/michelle-chia -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Search Engine Vulnerabilities, Ghost Tokens, Anna Kournikova

April 27, 2023 0:58:24 0.0 MB Downloads: 0

This week on Hacker And The Fed security researchers find a vulnerability allowing them to run code on Search Engine computers, ghost tokens could be used to totally control Search Engine Workplace accounts, we let you know what a Pumpkin Sandstorm and a Spandex Tempest are, how long does it take to crack your password in 2023, we answer listener questions about the FBI and diversity in cyber security appliances, and we talk about Anna Kournikova. Links from the episode: Remote Code Execution Vulnerability in Google They Are Not Willing To Fix giraffesecurity.dev/posts/google-remote-code-execution/ 'GhostToken' Opens Google Accounts to Permanent Infection darkreading.com/remote-workforce/-ghosttoken-opens-google-accounts-to-permanent-infection Hacker Group Names Are Now Absurdly Out of Control wired.com/story/hacker-naming-schemes-spandex-tempest/amp How Long It Would Take A Hacker To Brute Force Your Password In 2023 hivesystems.io/blog/are-your-passwords-in-the-green Support this episode's sponsors: DeleteMe: Visit JoinDeleteMe.com/FED and use promo code FED20  BetterHelp: Visit BetterHelp.com/HATF and get 10% off your first month -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

The Classified Document Leak, A Hacker Gets Hacked, And Can A Video Silently Hack Your Phone?

April 20, 2023 0:56:08 0.0 MB Downloads: 0

This week on Hacker And The Fed internet videos may be able to silently hack your phone with a "Near Ultrasound Inaudible Trojan” (NUIT). Companies have more access to your data than you may know, including pictures of you. We also discuss how better access controls may have prevented the recent classified documents leak and share a story about a hacker getting hacked. Links from the episode: Hey Siri, use this ultrasound attack to disarm a smart-home system https://www.theregister.com/2023/04/04/siri_alexa_cortana_google_nuit/ Tesla workers shared sensitive images recorded by customer cars https://www.reuters.com/technology/tesla-workers-shared-sensitive-images-recorded-by-customer-cars-2023-04-06/ Hacked: Russian GRU officer wanted by the FBI, leader of the hacker group APT 2 https://informnapalm.org/en/hacked-russian-gru-officer/ Support this episode's sponsors: DeleteMe: Visit JoinDeleteMe.com/FED and use promo code: FED20 -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Hackers Stealing Your Car And Internet Bandwidth, And A Massive Corporate Security Breach

April 13, 2023 1:00:39 0.0 MB Downloads: 0

This week on Hacker And The Fed a researcher gains access to millions of Office 365 accounts, cyber criminals are stealing and selling your internet bandwidth, and now hackers can remotely open your garage door and start your car in order to steal it. Links from the episode: Researcher gained access to millions of Office365 accounts: https://twitter.com/hillai/status/1641146508639600646 https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration  Cybercriminals may be stealing and selling your Internet bandwidth: https://sysdig.com/blog/proxyjacking-attackers-log4j-exploited/ And now hackers can remotely open your garage and start your car in order to steal it: https://www.vice.com/en/article/pkadqy/hackers-can-remotely-open-smart-garage-doors-across-the-world-simpaltek https://kentindell.github.io/2023/04/03/can-injection/ Finally the FBI has taken down another hacking forum full of stolen credentials: https://finance.yahoo.com/news/fbi-seizes-genesis-market-notorious-123039527.html?guccounter=1 -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

City Cyber Security with NYC CISO Kelly Moan

April 06, 2023 0:46:49 0.0 MB Downloads: 0

This week on Hacker And The Fed we speak with Kelly Moan, who serves as the Chief Information Security Officer (CISO) of New York City. We talk trends and cyber threats against the city. She also details the significant volume of attacks against the city on a weekly basis and gives us tips for getting into cyber security. Links from the episode: nyc.gov/content/oti/pages/meet-the-team/cyber-command nyc.gov/jobs More info on the JSOC + Cyber Command’s authorities via Executive Order 10: nyc.gov/office-of-the-mayor/news/088-22/mayor-adams-governor-hochul-joint-security-operations-center-combat-cybersecurity#/0 nyc.gov/office-of-the-mayor/news/010-002/executive-order-10 Support this episode's sponsor: HelloFresh: Visit HelloFresh.com/hatf50 and use code hatf50 for 50% off, plus your first box ships free! -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Who Can Read Your Emails, And Busting DDoS For Hire

March 30, 2023 1:00:44 0.0 MB Downloads: 0

This week on Hacker And The Fed we discuss what email security should look like over the next 12 months, who has the ability to read your emails, and law enforcement busting people using DDoS for hire. Links from the episode: Email Security Nightmare as 75% Of CISOs Expect a Severe Email-Borne Attack in the Next 12 Months cpomagazine.com/cyber-security/email-security-nightmare-as-75-of-cisos-expect-a-severe-email-borne-attack-in-the-next-12-months/ Who reads your email? twitter.com/jschauma/status/1634032554603945984 netmeister.org/blog/mx-diversity.html Fake ChatGPT Chrome Browser Extension Caught Hijacking Facebook Accounts thehackernews.com/2023/03/fake-chatgpt-chrome-browser-extension.html U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals thehackernews.com/2023/03/uk-national-crime-agency-sets-up-fake.html Support this episode's sponsor: BetterHelp: Hacker and the Fed is sponsored by BetterHelp. Visit BetterHelp.com/HATF today to get 10% off your first month. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Listener Questions: How To Protect Your Kids Online, Advanced Personal Cybersecurity, And What A “Red Team” Is

March 23, 2023 1:05:36 0.0 MB Downloads: 0

This week on Hacker And The Fed we catch up on some questions from our listeners: we discuss what a red teamer does, how the FBI works with other law enforcement agencies, how to upgrade your personal cyber security once you’ve got the basics down, and protecting children on the Internet. Support this episode's sponsors: Drata: Listeners of Hacker and the Fed can get 10% off Drata and waived implementation fees at drata.com/partner/hacker-fed BetterHelp: Hacker and the Fed is sponsored by BetterHelp. Visit BetterHelp.com/HATF today to get 10% off your first month. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur