Former FBI Special Agent Chris Tarbell and ex-Anonymous/LulzSec blackhat hacker Hector Monsegur (aka Sabu) faced off as adversaries in cyberspace before becomin... More
Former FBI Special Agent Chris Tarbell and ex-Anonymous/LulzSec blackhat hacker Hector Monsegur (aka Sabu) faced off as adversaries in cyberspace before becomin... More
Available Episodes
5 of 36
Zero-click Exploits Attacking iPhones, PC Motherboards Downloading Malware, and a New Dutch Mandate
This week on Hacker And The Fed we discuss another zero-click exploit attacking iPhones via the iMessage app, millions of PC motherboards may be downloading malware, the FTC slams another company for violations, security researchers find a vulnerability in Gmail's checkmark system that is already being abused. And the Dutch government now mandates an easy way to contact website administrators.
Links from the episode:
Operation Triangulation: iOS devices targeted with previously unknown malware
securelist.com/operation-triangulation/109842/
thehackernews.com/2023/06/new-zero-click-hack-targets-ios-users.html
Millions of PC motherboards were sold with a firmware backdoor
arstechnica.com/security/2023/06/millions-of-pc-motherboards-were-sold-with-a-firmware-backdoor/
FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring
thehackernews.com/2023/06/ftc-slams-amazon-with-308m-fine-for.html
Bug in Gmail
twitter.com/chrisplummer/status/1664075886545575941
twitter.com/ChristopheDary/status/1664907465924681728
linkedin.com/posts/christophe-dary-85330561_spf-dmarc-bimi-activity-7070510499196489728-pPTh?utm_source=share&utm_medium=member_desktop
Security.txt now mandatory for Dutch government websites
netherlands.postsen.com/trends/198695/Securitytxt-now-mandatory-for-Dutch-government-websites.html
securitytxt.org
--
Support our sponsors:
Go to HelloFresh.com/hatf16 and use code hatf16 for 16 free meals plus free shipping!
Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off
--
For more information on Chris and his current work visit naxo.com and follow him on LinkedIn.
Follow Hector @hxmonsegur
2023-06-08
1:05:46
An Insider Exploits A Ransomware Attack, AI Photos, And Hector's Indonesian Hack
This week on Hacker And The Fed we dive into the world of ransomware. An insider exploits a ransomware attack for personal gain and a CISO's biggest lessons from quarterbacking a ransomware attack. We discuss AI generated photos and what happened to the stock market. And then we answer listener questions about geopolitics, Hector's hack on the Indonesian government and victims keeping their hacks a secret.
Links from the episode:
IT employee impersonates ransomware gang to extort employer
bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/
AI Generated Photos
twitter.com/jsrailton/status/1660679743266607105
Suspicion stalks Genesis Market’s competitors following FBI takedown
therecord.media/genesis-market-russian-market-2easy-shop-cybercrime-fraud
FBI releases warning about fake crypto job advertisements
ic3.gov/Media/Y2023/PSA230522
Bridgestone CISO: Lessons From Ransomware Attack Include Acting, Not Thinking
darkreading.com/ics-ot/bridgestone-ciso-lessons-ransomware-attack-acting-thinking
2023-06-01
57:08
Pig Butchering And Crypto Crime-fighting With Erin West
This week on Hacker And The Fed we speak with Erin West, a Santa Clara County Deputy District Attorney, Founder of the “Crypto Coalition”, an over 800-member group of active law enforcement partners sharing cryptocurrency crime-fighting techniques, and the very tip of the spear for Pig Butchering – the latest online romance scam. We learn about the incredible work Erin is doing via Operation Shamrock and how we can protect ourselves and our loved ones from being victimized.
Links from the episode:
SCARS: Society of Citizens Against Relationship Scams
againstscams.org
Advocating Against Romance Scammers
advocatingforu.com
This podcast is sponsored by BetterHelp. Visit BetterHelp.com/HATF today to get 10% off your first month.
--
For more information on Chris and his current work visit naxo.com and follow him on LinkedIn at inkedin.com/in/chris-tarbell-20b129278/.
Follow Hector @hxmonsegur
2023-05-25
47:33
Vehicle Location Data Leaked For Over 2 million Drivers, Another US Government Breach, And D.B. Cooper
This week on Hacker And The Fed, up to 10 years of your location data may have been exposed if you’ve driven vehicles from a certain manufacturer, stolen private keys may lead to insecure boot ups of your computer, Congress gets another notification of a US government breach, and we answer more listener questions about failed hacks and intentional exploits. And we talk about D. B. Cooper!
Links from the episode:
Toyota: Car location data of 2 million customers exposed for ten years
bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/
Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security
securityonline.info/intel-oem-private-key-leak-a-blow-to-uefi-secure-boot-security/
Data of 237,000 US government employees breached
reuters.com/world/us/data-237000-us-government-employees-breached-2023-05-12/
Mastermind Behind Twitter 2020 Hack Pleads Guilty and Faces up to 70 Years in Prison
ustice.gov/opa/pr/uk-citizen-extradited-and-pleads-guilty-cyber-crime-offenses
T-Mobile Worker Joked About Adding Extra Phone Lines and Tablet to a Customer’s Account Without Them Knowing
twistedsifter.com/2023/05/a-t-mobile-worker-joked-about-adding-2-extra-phone-lines-and-a-tablet-to-a-customers-account-without-them-knowing/
Google Cybersecurity Certificate
grow.google/certificates/cybersecurity/#?modal_active=none
--
For more information on Chris and his current work visit naxo.com and follow him on LinkedIn.
Follow Hector @hxmonsegur
2023-05-18
1:00:05
Chinese State Hackers, Ransom Negotiation, And Listener Questions
This week on Hacker And The Fed we discuss private data leaking due to a misconfiguration, and no one is listening to the researchers. We are shown the mindset of hackers during a ransom negotiation, a cell phone provider is hacked for the 9th time in 6 years, there are 50 Chinese state hackers for every FBI cyber agent, and using AI to help hack. And finally, we answer listener questions about .xyz, pen testing tools, and possible Hacker And The Fed swag.
Links from the episode:
Many Public Salesforce Sites are Leaking Private Data
krebsonsecurity.com/2023/04/many-public-salesforce-sites-are-leaking-private-data/
Hackers Claim Vast Access to Western Digital Systems
techcrunch.com/2023/04/13/hackers-claim-vast-access-to-western-digital-systems/
T-Mobile Discloses 2nd Data Breach of 2023, This One Leaking Account PINs and More
arstechnica.com/information-technology/2023/05/t-mobile-discloses-2nd-data-breach-of-2023-this-one-leaking-account-pins-and-more/
Chinese Hackers Outnumber FBI Cyber Personnel 'By At Least 50 to 1,' Wray Testifies
foxnews.com/politics/chinese-hackers-outnumber-fbi-cyber-personnel-wray-testifies
Capturing the Flag with GPT-4
micahflee.com/2023/04/capturing-the-flag-with-gpt-4/
The Cyber Police Exposed an Attacker in the Sale of Databases with Personal Data of Citizens of Ukraine and the EU
cyberpolice.gov.ua/news/kiberpolicziya-vykryla-zlovmysnyka-u-zbuti-baz-iz-personalnymy-danymy-gromadyan-ukrayiny-ta-yes-6598/
--
For more information on Chris and his current work visit naxo.com
Follow Hector @hxmonsegur
Former FBI Special Agent Chris Tarbell and ex-Anonymous/LulzSec blackhat hacker Hector Monsegur (aka Sabu) faced off as adversaries in cyberspace before becoming close friends and podcast co-hosts.
Listen to Tarbell, co-founder of the elite cybersecurity firm NAXO, and Monsegur, a top network penetration tester and security engineer, break down the must-know cybersecurity news and topics of the week. You’ll walk away from each episode with unique perspectives on keeping your family, your company, and yourself safe from cyber attacks.
Listen to Hacker And The Fed, Pursuit of the Paranormal and Many Other Stations from Around the World with the radio.net App
Hacker And The Fed
Download now for free and listen to the radio easily.