Hacker And The Fed: Recent Episodes

NAXO

NAXO co-founder and former FBI Special Agent, Chris Tarbell, and ex-Anonymous/LulzSec blackhat hacker turned network penetration tester, Hector Monsegur (aka Sabu), once faced off as adversaries in cyberspace before becoming close friends and now podcast co-hosts. Whether you are a legal professional, cybersecurity practitioner, or forensic investigator, Chris and Hector will bring you their unique perspectives on the latest developments in cybersecurity. Each month, Chris and Hector will sit down to discuss:

Recent cyber attacks and key takeaways

Regulatory developments that impact how companies and individuals guard their data

New attack vectors and capabilities, including breakdowns of how they can be protected against

Techniques to keep you, your family, and your company safe from cyber attacks

Subscribe to be the first to hear about new Hacker and the Fed episodes. Contact us at hatf@naxo.com if you have a topic you’d like Chris and Hector to discuss on the podcast. Find out more about NAXO: www.naxo.com Follow us on LinkedIn: https://www.linkedin.com/company/81891840 Follow Chris on LinkedIn: https://www.linkedin.com/in/chris-tarbell-20b129278/ Follow Hector on LinkedIn: https://www.linkedin.com/in/hxmonsegur/


By accessing this podcast, you acknowledge that the Hacker and the Fed podcasts and any information, opinions or recommendations contained therein are for general informational purposes only, and are not intended to provide legal, tax, financial, or investment advice. Listeners should consult their own advisors before making these types of decisions. NAXO has no responsibility or liability for any decision made or any other acts or omissions in connection with your use of this material and any reliance upon the information provided in the Hacker and the Fed podcast is done at your own risk. NAXO makes no warranty, guarantee or representation as to the accuracy, sufficiency, completeness, timeliness, suitability or validity of the information in this podcast and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material. Unless specifically stated otherwise, NAXO does not endorse, approve, recommend or certify any information, product, process, service or organization presented or mentioned in this podcast, and information from this podcast should not be referenced in any way to imply such approval or endorsement. The views expressed by guests are their own and their appearance on this podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by NAXO employees are those of the employees and do not necessarily reflect the views of NAXO. The third-party materials or content of any third-party site referenced in this podcast do not necessarily reflect the opinions, standards or policies of NAXO. NAXO assumes no responsibility or liability for the accuracy or completeness of the content contained in third-party materials or on third-party sites referenced in this podcast or the compliance with applicable laws of such materials and/or links referenced herein. Moreover, NAXO makes no warranty that this podcast, or the server that makes it available, is free of viruses, worms or other elements or codes that manifest contaminating or destructive properties. NAXO EXPRESSLY DISCLAIMS ANY AND ALL LIABILITY OR RESPONSIBILITY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR OTHER DAMAGES ARISING OUT OF ANY INDIVIDUAL'S USE OF, REFERENCE TO, RELIANCE ON, OR INABILITY TO USE, THIS PODCAST OR THE INFORMATION PRESENTED IN THIS PODCAST.

View Details

This week on Hacker And The Fed a Danish cloud provider loses all of their customer's data, a hacker in custody continues hacking through a fire stick, there are two great write ups about a zero day vulnerability and HTML smuggling, cyber security entry jobs should be just that, entry into the industry, and we answer listener questions that include an ongoing dialogue with an active hacker about becoming a white hat. Links from the episode: Criminals Go Full Viking on CloudNordic, Wipe All Servers and Customer Data https://www.theregister.com/AMP/2023/08/23/ransomware_wipes_cloudnordic/   GTA 6 Hacker Found to be Teen with Amazon Fire Stick in Small Town Hotel Room https://hackaday.com/2023/08/26/gta-6-hacker-found-to-be-teen-with-amazon-fire-stick-in-small-town-hotel-room/   Traders' Dollars in Danger: Zero-Day Vulnerability in WinRAR Exploited by Cybercriminals to Target Traders https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/   HTML Smuggling Leads to Domain Wide Ransomware https://thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/   Cybersecurity Hiring Gap: Time to Rethink Who Can Contribute https://www.csoonline.com/article/649166/cybersecurity-hiring-gap-time-to-rethink-who-can-contribute.html

https://twitter.com/CyberWarship/status/1692239445188120950   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off   Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed we have Andrew Morris, CEO and founder of GreyNoise on the show. GreyNoise is a cybersecurity company that collects and analyzes mass internet data to remove pointless security alerts, find compromised devices, or identify emerging threats. We talk internet honeypots, how to get into the cyber security industry and much more. Links from the episode: Andrew Morris, CEO & Founder of GreyNoise https://www.greynoise.io/ https://twitter.com/Andrew___Morris https://twitter.com/GreyNoiseIO   Support our sponsor: Go to JoinDeleteMe.com/FED code FED20 for 20% off all consumer plans   Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed Zoom wanted to use your calls to train artificial intelligence, the NSA and DARPA are presenting challenges to the cyber security community, and we answer listener questions from a US military chaplain about justice, a former black hat about a career in cyber security, and even a hacker who used a compromised email account to ask us how to stop hacking. Links from the episode: Zoom walks back controversial privacy policy https://www.thestreet.com/technology/zooms-latest-move-may-make-you-reconsider-using-the-service   Microsoft Exposes Russian Hackers' Sneaky Phishing Tactics via Microsoft Teams Chats https://thehackernews.com/2023/08/microsoft-exposes-russian-hackers.html   Hackers to compete for nearly $20 million in prizes by using A.I. for cybersecurity, Biden administration announces https://www.cnbc.com/2023/08/09/biden-admin-launches-hacking-challenge-to-use-ai-for-cybersecurity.html https://aicyberchallenge.com/rules/   NSA: Codebreaker Challenge Helps Drive Cybersecurity Education https://www.darkreading.com/attacks-breaches/nsa-talks-codebreaker-challenge-success-influence-on-education   Lil Tay Meta Helped Get Account Back from Hacker https://www.tmz.com/2023/08/12/lil-tay-dead-dies-hacker-meta-instagram-hacked-account-hoax/   CISCO Launches a FREE 120-Hour Ethical Hacking Training https://cursin.net/en/cisco-launches-a-free-120-hour-ethical-hacking-training/   Support our sponsor: Go to JoinDeleteMe.com/FED code FED20 for 20% off all consumer plans   Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed the US hunts Chinese malware that could disrupt American Military operations, a year in review of zero-day exploits, a study finds no evidence that ransomware victims with cyber insurance pay up more often, there's fighting words between Tenable CEO and Microsoft, and we answer listener questions from a listener in Greece, Holland, and a new minted NSA hacker. Links from the episode: U.S. Hunts Chinese Malware That Could Disrupt American Military Operations https://dnyuz.com/2023/07/29/u-s-hunts-chinese-malware-that-could-disrupt-american-military-operations/   The Ups and Downs of 0-days: A Year in Review of 0-days Exploited In-the-Wild in 2022 https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html   No evidence ransomware victims with cyber insurance pay up more often https://therecord.media/ransomware-cyber-insurance-payments-uk-report   Tenable CEO accuses Microsoft of negligence in addressing security flaw https://cyberscoop.com/tenable-microsoft-negligence-security-flaw/ https://twitter.com/MalwareJake/status/1686869818912202755 https://www.wired.com/2002/01/bill-gates-trustworthy-computing/   SMS Traffic Pumping Fraud https://support.twilio.com/hc/en-us/articles/8360406023067-SMS-Traffic-Pumping-Fraud   New acoustic attack steals data from keystrokes with 95% accuracy https://www.bleepingcomputer.com/news/security/new-acoustic-attack-steals-data-from-keystrokes-with-95-percent-accuracy/   Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed what authentication attacks might look like in a phishing resistant future, the SEC now requires companies to disclose cyber attacks, there are many more US government domains in the .com world than you might think, and other news stories from this week in cyber security. Links from the episode:  What might authentication attacks look like in a phishing-resistant future? https://blog.talosintelligence.com/what-might-authentication-attacks-look-like-in-a-phishing-resistant-future/

The Messaging Layer Security (MLS) Protocol https://datatracker.ietf.org/doc/html/rfc9420

List of public government managed domains that exist outside of the top-level .gov and .mil domains https://github.com/GSA/govt-urls/blob/main/1_govt_urls_full.csv

Top level domain operator wants out of the business https://domainnamewire.com/2023/07/26/top-level-domain-operator-wants-out-of-the-business/

Network giants unite to fight security risks https://www.networkworld.com/article/3703233/network-giants-unite-to-fight-security-risks.html

Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches https://thehackernews.com/2023/07/cybersecurity-agencies-warn-against.html

Norwegian government IT systems hacked using zero-day flaw https://www.bleepingcomputer.com/news/security/norwegian-government-it-systems-hacked-using-zero-day-flaw/ https://www.dss.dep.no/aktuelle-saker/departementer-utsatt-for-dataangrep/ https://www.wsj.com/articles/critical-infrastructure-companies-warned-to-watch-for-ongoing-cyberattack-76508d83

Satellites Are Rife With Basic Security Flaws https://www.wired.com/story/satellites-basic-security-flaws/   Support our sponsors: Go to hellofresh.com/50hatf code 50hatf for 50% off plus free shipping Get your Hacker and the Fed merchandise at hackerandthefed.com

Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed new cyber security labels proposed by the US government could help us buy our new devices, an employee exposes thousands of intelligence and defense employees, Google may be restricting internet access to some employees to reduce their cyber attack risk, a hacker infects his own computer, and Google says an Apple employee found a zero-day but didn't report it, and we answer listener questions about our phones getting searched and email encryption. Links from the episode:  White House teams with Amazon, Google and Qualcomm on cybersecurity labels for gadgets https://www.cnbc.com/2023/07/18/us-cyber-trust-labels-will-help-consumers-pick-safer-smart-devices.html   Google exposes intelligence and defense employee names in VirusTotal leak https://therecord.media/virustotal-user-email-addresses-leaked-google-military-intelligence   Google restricting internet access to some employees to reduce cyberattack risk https://www.cnbc.com/2023/07/18/google-restricting-internet-access-to-some-employees-for-security.html   Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware https://www.securityweek.com/black-hat-hacker-exposes-real-identity-after-infecting-own-computer-with-malware/   IT Security Analyst Jailed for Impersonating as a Hacker in Own Company https://cybersecuritynews.com/it-security-analyst-jailed/   Google says Apple employee found a zero-day but did not report it https://techcrunch.com/2023/07/20/google-says-apple-employee-found-a-zero-day-but-did-not-report-it/ https://news.ycombinator.com/item?id=36803537   Microsoft Cybersecurity Analyst Professional Certificate https://www.coursera.org/professional-certificates/microsoft-cybersecurity-analyst   Cybersecurity Expert Kevin David Mitnick died https://www.dignitymemorial.com/obituaries/las-vegas-nv/kevin-mitnick-11371668   Listener Questions: https://www.theverge.com/2021/8/18/22630439/apple-csam-neuralhash-collision-vulnerability-flaw-cryptography   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off Go to drata.com/partner/hacker-fed and get 10% off Drata and waived implementation fees   Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed you can't always count on Google for the right telephone number for an airline, an American cloud based directory as a service platform announces that they were hacked by a state sponsored threat actor, millions of US military emails may be ending up in the wrong hands, a new ransomware looks like a windows update, we answer listener questions, and Hector tells a fascinating story about a hacking methodology. Links from the episode: Airline Fake Contact Number on Google Maps https://twitter.com/Shmuli/status/1680669938468499458 https://twitter.com/SwiftOnSecurity/status/1680926780599812098   JumpCloud discloses breach by state-backed APT hacking group https://www.bleepingcomputer.com/news/security/jumpcloud-discloses-breach-by-state-backed-apt-hacking-group/ JumpClouds IOCs - https://jumpcloud.com/support/july-2023-iocs   Domains like army․ml, pentagon․ml, navy․ml and af․ml all have Mail Exchange records pointing to 'handle․catchemail․ml' https://twitter.com/mikko/status/1680947795862200325   Watch out for this new malicious ransomware disguised as Windows updates https://www.foxnews.com/tech/watch-out-new-malicious-ransomware-disguised-windows-updates https://www.trendmicro.com/en_id/research/23/g/tailing-big-head-ransomware-variants-tactics-and-impact.html   Listener Questions https://www.lsu.edu/mediacenter/news/2023/06/13-cyber-clinic.php   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off Go to drata.com/partner/hacker-fed and get 10% off Drata and waived implementation fees

Get your Hacker and the Fed merchandise at hackerandthefed.com

View Details

This week on Hacker And The Fed your lightbulbs may be giving away the location of your house, could Microsoft end ransomware right now? Also, voice authentication may be broken, the latest ransomware attack shows us the important of logistics security, convenience has once again jeopardized Google authenticator security, and a listener shares a wild car theft story.

Links from the episode: Your lightbulbs may be giving out your exact location twitter.com/haxrob/status/1676416949499338752   Microsoft Can Fix Ransomware Tomorrow darkreading.com/vulnerabilities-threats/microsoft-can-fix-ransomware-tomorrow   Cybercriminals can break voice authentication with 99% success rate helpnetsecurity.com/2023/07/06/voice-authentication-insecurity/   INTERPOL Nabs Hacking Crew OPERA1ER's Leader Behind $11 Million Cybercrime thehackernews.com/2023/07/interpol-nabs-hacking-crew-opera1ers.html   Japan's biggest port, Nagoya, hit by suspected cyberattack asia.nikkei.com/Business/Technology/Japan-s-biggest-port-Nagoya-hit-by-suspected-cyberattack   Raising concerns over Google Authenticator’s new features techradar.com/pro/raising-concerns-over-google-authenticators-new-features   Trinidad and Tobago facing outages after cyberattack therecord.media/trinidad-tobago-hit-with-cyberattack   Listener Questions ksltv.com/563455/police-release-images-of-suspect-who-broke-into-familys-car-at-airport-then-their-home/   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off Go to drata.com/partner/hacker-fed and get 10% off Drata and waived implementation fees

View Details

This week on Hacker And The Fed your car may be collecting up to 25 GB per hour of data about you and a new malware payload vector is using DNS, what is “encryptionless ransomware”. We also answer listener questions about a variety of topics, including how to prepare for a cybersecurity career in the US government, banking security, and hack-backs.

Links from the episode: How Your New Car Tracks You https://www.wired.com/story/car-data-privacy-toyota-honda-ford/   DNS TXT Records Can Be Used by Hackers to Execute Malware https://cybersecuritynews.com/dns-txt-records-to-execute-malware/?amp

Encryption-less ransomware: Warning issued over emerging attack method for threat actors https://www.itpro.com/security/ransomware/encryption-less-ransomware-warning-issued-over-emerging-attack-method-for-threat-actors   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off Go to drata.com/partner/hacker-fed and get 10% off Drata and waived implementation fees

View Details

This week on Hacker And The Fed a CEO did a hack back and was sentenced to prison, Reddit hackers demanded a price roll back, repo jacking and fake Github repositories, and we answer listener questions about Hector's old hacks and VPNs.

Links from the episode: I Was Sentenced to 18 Months in Prison for Hacking Back - My Story twitter.com/silascutler/status/1671144482769608705 -> https://hackernoon.com/i-was-sentenced-to-18-months-in-prison-for-hacking-back-my-story   Reddit hackers demand $4.5 million ransom and API pricing changes theverge.com/2023/6/19/23765895/reddit-hack-phishing-leak-api-pricing-steve-huffman   GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking   Attackers Create Synthetic Security Researchers to Steal IP darkreading.com/attacks-breaches/attackers-create-synthetic-security-researchers   Google announces $20 million investment for cyber clinics cyberscoop.com/google-investment-cyber-clinics/   Listener Questions https://fidoalliance.org/   Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off

View Details

This week on Hacker And The Fed a ransomware group hacked a widely used file transfer software and began leaking stolen data, Google claims it caught Chinese government hackers red-handed breaking into hundreds of networks, the Feds arrest a ransomware perpetrator in Arizona, and we nerd out on security researchers taking over various countries domains.

Links from the episode: MOVEit Cyber Attack: Personal Data Of Millions Stolen From Oregon, Louisiana, U.S. Agency forbes.com/sites/maryroeloffs/2023/06/16/moveit-cyber-attack-personal-data-of-millions-stolen-from-oregon-louisiana-us-agency/?sh=3cf2b1b46b05   US govt offers $10 million bounty for info on Clop ransomware bleepingcomputer.com/news/security/us-govt-offers-10-million-bounty-for-info-on-clop-ransomware/amp/

Google claims it caught China government hackers redhanded breaking into hundreds of networks around the world fortune.com/2023/06/15/china-hacking-networks-cybersecurity-google-mandiant/amp/   20-Year-Old Russian LockBit Ransomware Affiliate Arrested in Arizona thehackernews.com/2023/06/20-year-old-russian-lockbit-ransomware.html   Can I speak to your manager? hacking root EPP servers to take control of zones hackcompute.com/hacking-epp-servers/   Darknet Parliament is now a thing cybernews.com/security/darknet-parliament-killnet-hackers/ -- Support our sponsor: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off -- For more information on Chris and his current work visit naxo.com and follow him on LinkedIn. Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss the latest development in the Tik Tok controversy, how to detect and mitigate a new phishing and email takeover campaign, Google's new top-level domain, and some interesting statistics in the new Verizon breach investigation report.

Links from the episode: Former exec at TikTok's parent company says Communist Party members had a 'god credential' that let them access Americans' data businessinsider.com/communist-party-god-credential-data-bytedance-tiktok-former-executive-alleges-2023-6   Detecting and mitigating a multi-stage AiTM phishing and BEC campaign microsoft.com/en-us/security/blog/2023/06/08/detecting-and-mitigating-a-multi-stage-aitm-phishing-and-bec-campaign/   America’s Most Cybersecure Companies forbes.com/lists/most-cybersecure-companies   Hackers claim to have crippled Russia’s banking system cybernews.com/cyber-war/infotel-hack-impacts-russian-banks/   Verizon 2023 Data Breach Investigations Report verizon.com/business/resources/reports/dbir/ -- Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off -- For more information on Chris and his current work visit naxo.com and follow him on LinkedIn. Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss another zero-click exploit attacking iPhones via the iMessage app, millions of PC motherboards may be downloading malware, the FTC slams another company for violations, security researchers find a vulnerability in Gmail's checkmark system that is already being abused. And the Dutch government now mandates an easy way to contact website administrators. Links from the episode: Operation Triangulation: iOS devices targeted with previously unknown malware securelist.com/operati on-triangulation/109842/ thehackernews.com/2023/06/new-zero-click-hack-targets-ios-users.html  Millions of PC motherboards were sold with a firmware backdoor arstechnica.com/security/2023/06/millions-of-pc-motherboards-were-sold-with-a-firmware-backdoor/ FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring thehackernews.com/2023/06/ftc-slams-amazon-with-308m-fine-for.html Bug in Gmail twitter.com/chrisplummer/status/1664075886545575941 twitter.com/ChristopheDary/status/1664907465924681728 linkedin.com/posts/christophe-dary-85330561_spf-dmarc-bimi-activity-7070510499196489728-pPTh?utm_source=share&utm_medium=member_desktop Security.txt now mandatory for Dutch government websites netherlands.postsen.com/trends/198695/Securitytxt-now-mandatory-for-Dutch-government-websites.html securitytxt.org Support our sponsors: Go to HelloFresh.com/hatf16 and use code hatf16 for 16 free meals plus free shipping! Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off

View Details

This week on Hacker And The Fed we dive into the world of ransomware. An insider exploits a ransomware attack for personal gain and a CISO's biggest lessons from quarterbacking a ransomware attack. We discuss AI generated photos and what happened to the stock market. And then we answer listener questions about geopolitics, Hector's hack on the Indonesian government and victims keeping their hacks a secret.  Links from the episode: IT employee impersonates ransomware gang to extort employer bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/ AI Generated Photos twitter.com/jsrailton/status/1660679743266607105 Suspicion stalks Genesis Market’s competitors following FBI takedown therecord.media/genesis-market-russian-market-2easy-shop-cybercrime-fraud FBI releases warning about fake crypto job advertisements ic3.gov/Media/Y2023/PSA230522 Bridgestone CISO: Lessons From Ransomware Attack Include Acting, Not Thinking darkreading.com/ics-ot/bridgestone-ciso-lessons-ransomware-attack-acting-thinking

View Details

This week on Hacker And The Fed we have our first ever guest. Former Black Hat and former member of LulzSec, Cody Kretsinger. Hector and Cody go back nearly 20 years to the earliest days of online hacking when they spent years partnering to infiltrate major computer networks around the world. Despite that long history, they’ve never actually met in the flesh. We cover a lot as they speak together for the first time, from hacking origin stories to life after federal prison.--For more information on Chris and his current work visit naxo.comFollow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss Hector's decision to work with the FBI. To change the course of his life and begin the journey to where he is now. We explore his moral considerations as well as the very practical implications of such a decision. We also hear the story of Hector's first hack and answer a listener question on NSO group and high level hacking.

For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss the recent seizure related to Silk Road, the black market website Chris took down in 2013. Silk Road is back in the news as the IRS just recently caught a man who stole 50,000 bitcoin from the site.

For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss the recent DropBox hack that relied on a phishing attack to steal credentials as well as multi-factor authentication codes. We also discuss other tactics attackers use to work around multi-factor authentication as well as a technology that may replace the applications and codes you use today. And finally, we respond to a few user questions about the FBI.

For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss the NSO Group’s zero-click iPhone exploit, also known as Pegasus, a powerful tool that can be used to take full control of a target’s iPhone without their knowledge. We break down how it all works and how to think about this tool and others like it. We also answer a question from the audience about Hector’s experience using IRC, an old internet chat tool where Hector had “wars” with other hackers. -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we answer audience questions. We discuss the future of cyber security and whether we will ever get ahead of the bad guys. We also detail what it's like to be arrested by the FBI as Hector recounts his experience following the knock on the door. And finally, we respond to a small business owner on how to secure her social media accounts and website from potential threats.

For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

This week on Hacker And The Fed we discuss voice fishing, or "vishing," and the social engineering tactics behind this attack. You know those spam calls you get? Well sometimes those are actually social engineering attacks aimed at convincing you to send money to scammers. It's a relatively new twist on phishing and it employs many of the same basic tactics. We detail what these attacks look like, tell a few stories of our own experience with social engineering, and leave you with some key takeaways for how to keep yourself and loved ones safe and secure. -- Below are several terms Hector and Chris use in the show that some listeners may not be familiar with: Dox – publish private information about an individual online APT – advanced persistent threat, e.g. a nation state with sophisticated cyber capabilities EFNet – an internet chat relay network API – automated programming interface, a way for two or more computer programs to communicate with each other. WHOIS – information about an IP address or domain name (e.g. google.com) -- For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

On this first episode of Hacker And The Fed, Chris and Hector tell their origin story. Hector details the journey from his first time on the internet to becoming a globally infamous black hat hacker. And Chris tells of growing up in Virginia next to the chief of police to ultimately joining the FBI and dedicating his life to fighting cyber crime. The two outline their story from the moment Chris arrested Hector, ultimately leading to a long time collaboration and lifelong friendship. For more information on Chris and his current work visit naxo.com Follow Hector @hxmonsegur

View Details

Former FBI special agent Chris Tarbell and former Anonymous blackhat Hector Monsegur (aka Sabu) first faced-off as adversaries in cyberspace before becoming close friends and podcast co-hosts. Listen to Tarbell, co-founder of an elite cybersecurity firm NAXO, and Monsegur, a top network penetration tester and security engineer, break down the must-know cybersecurity news and topics of the day. You’ll walk away from each episode with unique perspectives on how to keep your family, your company, and your personal cyber footprint safe from attacks.