Former FBI Special Agent Chris Tarbell and ex-Anonymous/LulzSec blackhat hacker Hector Monsegur (aka Sabu) faced off as adversaries in cyberspace before becoming close friends and podcast co-hosts. Listen to Tarbell, co-founder of the elite cybersecurity firm NAXO, and Monsegur, a top network penetration tester and security engineer, break down the must-know cybersecurity news and topics of the week. You’ll walk away from each episode with unique perspectives on keeping your family, your company, and yourself safe from cyber attacks.

The Classified Document Leak, A Hacker Gets Hacked, And Can A Video Silently Hack Your Phone?

April 20, 2023 0:56:08 0.0 MB Downloads: 0

This week on Hacker And The Fed internet videos may be able to silently hack your phone with a "Near Ultrasound Inaudible Trojan” (NUIT). Companies have more access to your data than you may know, including pictures of you. We also discuss how better access controls may have prevented the recent classified documents leak and share a story about a hacker getting hacked. Links from the episode: Hey Siri, use this ultrasound attack to disarm a smart-home system https://www.theregister.com/2023/04/04/siri_alexa_cortana_google_nuit/ Tesla workers shared sensitive images recorded by customer cars https://www.reuters.com/technology/tesla-workers-shared-sensitive-images-recorded-by-customer-cars-2023-04-06/ Hacked: Russian GRU officer wanted by the FBI, leader of the hacker group APT 2 https://informnapalm.org/en/hacked-russian-gru-officer/ Support this episode's sponsors: DeleteMe: Visit JoinDeleteMe.com/FED and use promo code: FED20 -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Hackers Stealing Your Car And Internet Bandwidth, And A Massive Corporate Security Breach

April 13, 2023 1:00:39 0.0 MB Downloads: 0

This week on Hacker And The Fed a researcher gains access to millions of Office 365 accounts, cyber criminals are stealing and selling your internet bandwidth, and now hackers can remotely open your garage door and start your car in order to steal it. Links from the episode: Researcher gained access to millions of Office365 accounts: https://twitter.com/hillai/status/1641146508639600646 https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration  Cybercriminals may be stealing and selling your Internet bandwidth: https://sysdig.com/blog/proxyjacking-attackers-log4j-exploited/ And now hackers can remotely open your garage and start your car in order to steal it: https://www.vice.com/en/article/pkadqy/hackers-can-remotely-open-smart-garage-doors-across-the-world-simpaltek https://kentindell.github.io/2023/04/03/can-injection/ Finally the FBI has taken down another hacking forum full of stolen credentials: https://finance.yahoo.com/news/fbi-seizes-genesis-market-notorious-123039527.html?guccounter=1 -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

City Cyber Security with NYC CISO Kelly Moan

April 06, 2023 0:46:49 0.0 MB Downloads: 0

This week on Hacker And The Fed we speak with Kelly Moan, who serves as the Chief Information Security Officer (CISO) of New York City. We talk trends and cyber threats against the city. She also details the significant volume of attacks against the city on a weekly basis and gives us tips for getting into cyber security. Links from the episode: nyc.gov/content/oti/pages/meet-the-team/cyber-command nyc.gov/jobs More info on the JSOC + Cyber Command’s authorities via Executive Order 10: nyc.gov/office-of-the-mayor/news/088-22/mayor-adams-governor-hochul-joint-security-operations-center-combat-cybersecurity#/0 nyc.gov/office-of-the-mayor/news/010-002/executive-order-10 Support this episode's sponsor: HelloFresh: Visit HelloFresh.com/hatf50 and use code hatf50 for 50% off, plus your first box ships free! -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Who Can Read Your Emails, And Busting DDoS For Hire

March 30, 2023 1:00:44 0.0 MB Downloads: 0

This week on Hacker And The Fed we discuss what email security should look like over the next 12 months, who has the ability to read your emails, and law enforcement busting people using DDoS for hire. Links from the episode: Email Security Nightmare as 75% Of CISOs Expect a Severe Email-Borne Attack in the Next 12 Months cpomagazine.com/cyber-security/email-security-nightmare-as-75-of-cisos-expect-a-severe-email-borne-attack-in-the-next-12-months/ Who reads your email? twitter.com/jschauma/status/1634032554603945984 netmeister.org/blog/mx-diversity.html Fake ChatGPT Chrome Browser Extension Caught Hijacking Facebook Accounts thehackernews.com/2023/03/fake-chatgpt-chrome-browser-extension.html U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals thehackernews.com/2023/03/uk-national-crime-agency-sets-up-fake.html Support this episode's sponsor: BetterHelp: Hacker and the Fed is sponsored by BetterHelp. Visit BetterHelp.com/HATF today to get 10% off your first month. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Listener Questions: How To Protect Your Kids Online, Advanced Personal Cybersecurity, And What A “Red Team” Is

March 23, 2023 1:05:36 0.0 MB Downloads: 0

This week on Hacker And The Fed we catch up on some questions from our listeners: we discuss what a red teamer does, how the FBI works with other law enforcement agencies, how to upgrade your personal cyber security once you’ve got the basics down, and protecting children on the Internet. Support this episode's sponsors: Drata: Listeners of Hacker and the Fed can get 10% off Drata and waived implementation fees at drata.com/partner/hacker-fed BetterHelp: Hacker and the Fed is sponsored by BetterHelp. Visit BetterHelp.com/HATF today to get 10% off your first month. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Jobs, Academics, And The Future Of Cybersecurity With Professor Bill Gardner

March 16, 2023 0:58:58 0.0 MB Downloads: 0

This week on Hacker And The Fed we sit down with Bill Gardner, professor and Chair Department of Cyber Forensics & Security at Marshall University. Bill offers insight into the professional and academic path into the industry and the future of cybersecurity. Links from the episode: Follow Bill Gardner: Twitter: https://twitter.com/oncee Linkedin: https://www.linkedin.com/in/304blogs/ Marshall University Prospective Students Two papers written by Bill Gardner “I Did What I Believe Is Right”: A Study of Neutralizations among Anonymous Operation Participants Social Engineering in Non-Linear Warfare Support this episode's sponsors: Drata: Get 10% off and waived implementation fees at drata.com/partner/hacker-fed DeleteMe: Visit JoinDeleteMe.com/FED and use promo code: FED20 -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Fake Google Ads, Law Firms Under Attack, And The White House Announces New National Cybersecurity Strategy

March 09, 2023 0:51:48 0.0 MB Downloads: 0

This week on Hacker And Fed we discuss fake Google advertisements, law firms under attack from cyber criminals, and the Whitehouse announcing a new national security strategy. Support this episode's sponsors: Drata: Get 10% off and waived implementation fees at drata.com/partner/hacker-fed DeleteMe: Visit JoinDeleteMe.com/FED and use promo code: FED20 Links from the episode: twitter.com/doctorow/status/1628948906657878016 thehackernews.com/2023/03/cybercriminals-targeting-law-firms-with.html?m=1 twitter.com/dcuthbert/status/1631302488996364288/photo/1 whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/ whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf nbcnews.com/politics/politics-news/major-us-marshals-service-hack-compromises-sensitive-info-rcna72581 twitter.com/nol_tech/status/1629910222746578945 abc7news.com/atm-scam-tap-card-chase-bank-function/12905397/ -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

A Leaked Ransomware Negotiation, Twitter Security, And NSA Best Practices For Securing Your Home Network

March 02, 2023 0:46:16 0.0 MB Downloads: 0

This week on Hacker And Fed we discuss a leaked ransomware negotiation, how Twitter's new verification system may improve security, and the NSA releases its best practices for securing your home network. Support this episode's sponsor, Drata. For 10% off and waived implementation fees visit drata.com/partner/hacker-fed. Links from the episode: pwndefend.com/2023/02/15/lockbit-3-0-and-royal-mail-chats-published/ dice.com/career-advice/cybercriminals-increase-recruiting-tech-and-it-pros-across-the-darknet gizmodo.com/facebook-instagram-verified-elon-musk-was-right-twitter-1850139933 media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Insider Threat Attacks, Malware Used To Steal Crypto, And Hector’s Embarrassing Story

February 23, 2023 1:08:29 0.0 MB Downloads: 0

This week on Hacker And Fed we update a story from a few episodes ago about a woman driving with a suspicious eavesdropping device near the embassies in Paris, Credit Suisse suffers a insider threat attack, an old attack methodology is updated to steal cryptocurrency, a hacker utilizes screen-capturing malware to cherry-pick their victims, regulators propose a rule to have cyber educated board members, Hector receives a phishing email that turns out to be a much larger issue, and finally Hector pays off his losing Super Bowl bet. Links from the episode: francetvinfo.fr/faits-divers/escroquerie-aux-sms-de-l-assurance-maladie-les-suspects-volaient-les-numeros-de-telephone-depuis-leur-voiture_5665943.html efinancialcareers.com/news/2023/02/credit-suisse-employee-data-leak blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack thehackernews.com/2023/02/hackers-targeting-us-and-german-firms.html cfr.org/blog/walk-and-chew-gum-cisos-communicating-boards-have-speak-their-language venturebeat.com/security/4-misconceptions-about-data-exfiltration/amp/ bleepingcomputer.com/news/security/namecheaps-email-hacked-to-send-metamask-dhl-phishing-emails/ -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Insider Threat Attacks, Malware Used To Steal Crypto, And Hector’s Embarrassing Story

February 23, 2023 1:08:20 0.0 MB Downloads: 0

This week on Hacker And Fed we update a story from a few episodes ago about a woman driving with a suspicious eavesdropping device near the embassies in Paris, Credit Suisse suffers a insider threat attack, an old attack methodology is updated to steal cryptocurrency, a hacker utilizes screen-capturing malware to cherry-pick their victims, regulators propose a rule to have cyber educated board members, Hector receives a phishing email that turns out to be a much larger issue, and finally Hector pays off his losing Super Bowl bet. Links from the episode: francetvinfo.fr/faits-divers/escroquerie-aux-sms-de-l-assurance-maladie-les-suspects-volaient-les-numeros-de-telephone-depuis-leur-voiture_5665943.html efinancialcareers.com/news/2023/02/credit-suisse-employee-data-leak blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack thehackernews.com/2023/02/hackers-targeting-us-and-german-firms.html cfr.org/blog/walk-and-chew-gum-cisos-communicating-boards-have-speak-their-language venturebeat.com/security/4-misconceptions-about-data-exfiltration/amp/ bleepingcomputer.com/news/security/namecheaps-email-hacked-to-send-metamask-dhl-phishing-emails/ -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

A Major Phishing Attack, TikTok In Texas, And FBI Customer Service

February 16, 2023 0:44:16 0.0 MB Downloads: 0

This week on Hacker And Fed Reddit suffers a phishing attack, the FBI offers "Ritz Carlton" level customer service, Texas bans TikTok on state owned devices, and a researcher documents the methodology of finding a major network flaw. Links from the episode: reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/ govconwire.com/2022/10/bryan-vorndran-outlines-tenets-of-fbi-role-in-cyber-ecosystem/ beckershospitalreview.com/legal-regulatory-issues/fbi-aiming-to-protect-give-ritz-carlton-level-customer-service-to-companies-that-report-cyberattacks.html gov.texas.gov/news/post/governor-abbott-announces-statewide-plan-banning-use-of-tiktok eaton-works.com/2023/02/06/toyota-gspims-hack/ -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

"Malvertising" and Stolen Background Check Data

February 09, 2023 0:47:30 0.0 MB Downloads: 0

This week on Hacker And The Fed we discuss how Search Engine Ads are being used to spread malware through "malvertising". We also cover the impact of a breach involving data for over 20,000 individuals stolen from a firm that aggregates public records and sells background checks online. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

The FBI Take Down Of Hive Ransomware Network & Questions About The FBI

February 02, 2023 0:54:20 0.0 MB Downloads: 0

This week on Hacker And Fed we discuss the FBI's takedown of Hive, the Ransomware group with over 100 million in ransom payments. We also talk about the FBI's insider threat brochure, giving companies indicators on what to look for internally. And finally, Hector asks Chris some questions about the FBI. Links from the episode: justice.gov/opa/pr/us-department-justice-disrupts-hive-ransomware-variant fbi.gov/file-repository/insider_threat_brochure.pdf cisa.gov/insider-threat-cyber -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

2023 Hacking Predictions, Bug Bounty Hunters, And The Super Bowl Sunday Hack

January 25, 2023 0:49:48 0.0 MB Downloads: 0

This week on Hacker And Fed Hector makes some predictions of the hacks we will see in 2023. We also discuss bug bounty hunters, how they're not getting paid what they deserve and why they may take their exploits to the dark web. We touch on another big API data leak and Hector tells a story of a hack he did on Super Bowl Sunday. And finally we help a listener with spoofed calls and text messages. T-Mobile Filed Form 8-K with the US SEC -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

Cyber In The News: Important Stories Slipping Under The Radar

January 19, 2023 0:51:09 0.0 MB Downloads: 0

This week on Hacker and the Fed we discuss a variety of recent news stories, including a report of a messaging service selling access to user data, bootleg network devices being sold through certified vendors, Gmail offering end-to-end encryption, lessons learned from a not so secure encrypted messaging application, cell phone software that was stolen and made public, and a password problem at a major US executive department. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

This episode has failed processing Original Audio