Loading summary
Chris Tarbell
So Madison Square Garden, msg, or also MSG Sports Entertainment has operated a facial recognition and biometric profiling system since 2018.
Hector Monsegur
Hector Monseager was responsible for some of
Chris Tarbell
the most notorious hacks ever committed.
Hector Monsegur
Special Agent Chris Tarbell and FBI informants
Chris Tarbell
participated in some of the world's most
Hector Monsegur
infamous hacks that caused up to $50 million in damages.
Chris Tarbell
A life in the shadows.
Hector Monsegur
Cyber attacks on the rise.
Chris Tarbell
As always, everybody, welcome to Hacker in the Fed. I'm Chris Tarbell, former FBI special agent working my entire career in cyber security. And I'm joined, as always, by my buddy, the squeezable, the huggable Hector Monsegur. Hey, Heck.
Hector Monsegur
Hey.
Chris Tarbell
Hecker is a former black hat hacker for those that don't know who once faced 125 years for all his years of hacking under the code name Sabu. Our stories collided in June two. I love the. In June 2011, when I arrested Heck, but then convinced him to work with me at the FBI. Hector is now a Red Teamer, researcher, cybersecurity expert. One hell of a guy. Oh, yeah, and he co founded Safe Hill.
Hector Monsegur
Hey, what's going on, bud?
Chris Tarbell
141 episodes in Buddy. I'm trying to make it different every time he's.
Hector Monsegur
141 episodes. Look, I got all the gray hairs to prove it. Like we're. We're getting up there, bro.
Chris Tarbell
141 free episodes. That doesn't even count the Patreon episodes.
Hector Monsegur
That's true. Have you ever counted how many Patreon episodes we've done?
Chris Tarbell
No, no, I don't like to count. You know, they say you're not an expert until you do 10,000 hours, and I don't know if we're there yet. So this may be an amateur podcast still.
Hector Monsegur
Yeah, we're still neophytes, basically. That's fine with me. I'm okay with that.
Chris Tarbell
You think? Are we script kiddies of. Of podcast world?
Hector Monsegur
Yeah, we're the script kitties of podcasts for sure. You know, because I've seen some of the infrastructure, at least from the outside of what other podcasters are doing, and they have like automation with the website to RSS feed to like post into this on Twitter, on blog spot. It's a whole thing.
Chris Tarbell
You want to take it to that level? Are we gonna. Are we gonna start doing that?
Hector Monsegur
Come on. Come on. That's. That's a bit much. It's just two buddies talking about cyber. It's not a. You know, we're not going mainstream.
Chris Tarbell
A niche podcast about Cyber security and tanning balls and former porn stars. And that's it?
Hector Monsegur
Yeah, that's it. That's all it is. And that's fine. That's actually pretty cool. I mean, when you, when you start listening to the other podcasts in cyber, they're kind of forky and cringy, you know, just like, hey, change your passwords. You know, it's, it's. Change your passes Wednesdays. You know, it's like, okay, I get that we could do that too. But come on, man, let's talk about some technical stuff.
Chris Tarbell
Sometimes do they get online and change their passwords together?
Hector Monsegur
Yeah, they do a whole thing. They're changing passwords, they're doing, you know, kumbayas.
Chris Tarbell
Wait, wait, are they using capital letters, numbers, and special characters?
Hector Monsegur
Yeah, bro, you know what they're doing is like, man, listen, you know, they got like a little printed out sheet, just like the Germans used to have, the OTP sheets and do some one time padding and all this nonsense, and they still get popped anyway, you know how it is.
Chris Tarbell
Interesting. Interesting. Heck. Yeah, I got some bad news for you, brother.
Hector Monsegur
What's the bad news?
Chris Tarbell
I got a call this week from our arch nemesis, Alanis.
Hector Monsegur
Oh, no, not her.
Chris Tarbell
I know, I know it's her. It's always Alanis's fault. So we used to blame other people. We used to blame Will. We used to blame Phineas. No, now it's Alanis's fault. You know what she told me? She told me that we do not talk about Safe Hill. We don't explain Safe Hill enough and how great Safe Hill is for helping us out with the show and helping us bring the show and keep the show commercial free. So you know what she said? I got to make a commercial about Safill in the show.
Hector Monsegur
Oh, come on, Alanis. What are you doing, girl?
Chris Tarbell
All right, well, for those that don't know that Safe Hill is a cyber security startup that Heck co founded, and it was built by ethical hackers. Heck. Do you guys have a platform called Security iq?
Hector Monsegur
What's called Secure iq?
Chris Tarbell
Secure iq. I should probably get the name right.
Hector Monsegur
Yeah.
Chris Tarbell
Alanis is gonna have my nuts now. My tanned nuts right in her hand. She's gonna grab them and twist them.
Hector Monsegur
Yeah, I do like the Wu Tang. Do you remember the first Wu Tang Clan album where it was like this whole scene where like. Yeah, put his nuts on the dresser, beat him with a hammer. Remember that?
Chris Tarbell
No, but I've told. I've told you the story that Beth to me was in front of me At Costco, right?
Hector Monsegur
Really?
Chris Tarbell
Yeah.
Hector Monsegur
You did actually.
Chris Tarbell
Yeah, yeah, yeah. He was scoping out my cart, seeing what white people buy.
Hector Monsegur
Yeah, he's doing recon.
Chris Tarbell
He kept turning around looking at what was in my cart and I just look at him like what? Leave me alone.
Hector Monsegur
Method man, this guy, he got that, what was that? Fair something Milk, you know, fair life.
Chris Tarbell
Yeah, not back then, it wasn't around, but anyways. Secure iq, AI driven threat exposure management solution that finds the attacks path into your environment and proves which one actually works before someone else does. Heck yeah. How are things at Sefill? What have you guys been working on lately?
Hector Monsegur
Well, listen brother, I'm tell you something, it's been, and it's something we've talked about on Patreon where there's been a lot of research going on over the last, you know, two and a half plus years, non stop research into cool things. And so we have our hands in a lot of different areas. One of the, one of the areas that I think would be fascinating for the audience here and I kind of touch on it real quick, is always intelligence, right. Open source intelligence is actually pretty badass. You did a lot of that stuff when you was an FBI agent, you know, collect you leveraging all sorts of different data sets to kind of build out a story. Right. And so if you, if you, I don't think you ever got to see one of our reports. Our reports are pretty badass.
Chris Tarbell
I have, I have seen one before and I was very impressed.
Hector Monsegur
Yeah, well, so we, what we've done here is for years we've done it manually, but you know, it's 2026 now. We've got to automate some of that stuff. So we've done, we've been doing is building out like the automated processes to kind of gather information, kind of profile of assets or targets and then kind of tell a story like that. And then of course you have the humans coming in and validating that. Right. So that, that alone has been fascinating. We got a guy named Anthony. Anthony's been doing really good with it and we have a big physical pen test job we're doing soon. Like we're actually breaking into stores soon. And that's part of it.
Chris Tarbell
Right.
Hector Monsegur
But like always, intelligent report on locations. Who's the sanitation company, you know, like who's the, the owner of the building, the property and kind of put all that together, look at lawsuits, tie it together. There you go. It's pretty nice.
Chris Tarbell
Oh, that's interesting. I love it.
Hector Monsegur
Oh yeah.
Chris Tarbell
So if, if the hacker and the Fed listeners want, you know, more about information about, like, threat exposure management or the penetration testing services. How do they get a hold of you?
Hector Monsegur
Yeah, well, listen, you know, I'm. I'm accessible. Feel free to send me a message on LinkedIn. Go to, you know, safo.com directly, or you can just email us@info safehold.com and, you know, ask us your questions, whatever you're interested in, and go from there.
Chris Tarbell
If our listeners really, really hate this, can they reach out to Alanis directly?
Hector Monsegur
Yeah, they could curse Alanas at all questions@hackertheed.com.
Chris Tarbell
no,
Hector Monsegur
I'll forward it to her.
Chris Tarbell
Don't worry. Okay, thank you. Thank you.
Hector Monsegur
Yeah, I'll. A curator.
Chris Tarbell
You traveling all this week? Are you staying up in that smoky New York City?
Hector Monsegur
You know, the smoky New York City? I'm kind of over with. I'm trying to go back, you know, go back to the island. Oh, yeah, I'm trying. I think. I think soon, the next, you know, a few weeks.
Chris Tarbell
All right. Is it. Is it bad? Is the smoke bad up there?
Hector Monsegur
No, I got better. It was yellow as hell, bro. It was like legit yellow out here.
Chris Tarbell
Yeah, man, I don't think you can say that anymore, brother. I think it's. That's racist.
Hector Monsegur
It might be, but I'll tell you, dumb Canucks, man, they. They try to whack us, you know? And. And for their troubles, for my trouble, they sent me a bottle of maple syrup here.
Chris Tarbell
Oh, that's nice.
Hector Monsegur
Yeah, they're like, hey, I'm sorry. Here's some maple syrup.
Chris Tarbell
And do you just take hits off that or do you pour it on pancakes?
Hector Monsegur
Hey, listen, brother, you take some hits off of that. This is. This is liquid gold right here, brother. It's not like that fake fugazi syrup that we have here, you know?
Chris Tarbell
Are you talking about Aunt Jemima?
Hector Monsegur
Hey, listen, leave Aunt Jemima out of this. She's not the issue. The issue is the high fructose corn syrup and this nasty ass. That would be.
Chris Tarbell
Oh, that is true. That's true. My. My family, I was. Was long standing. From Vermont, so we're. We're. We're Vermont maple syrup people.
Hector Monsegur
Oh, is it liquidy too, like the Canadian stuff?
Chris Tarbell
I like a nice grade B. You want the darker one? Grade P, you think grade A is better, but it's not. Grade B is better.
Hector Monsegur
Well, I gotta send you a bottle, bro. What's wrong with you?
Chris Tarbell
I don't want you to get diabetes. That's why I don't want to send you A bottle?
Hector Monsegur
Nah, it comes from the trees. What the says, when does diabetes freaking give you trees, give you diabetes? Come on, bro.
Chris Tarbell
Yeah, that's true. It's essentially like you'd be a vegetarian. It's a. It's essentially a vegetable if it comes from a tree.
Hector Monsegur
Well, this is we're talking about. I'm gonna take a shot of this maple syrup real quick. This right here. We gotta put some hair in your chest.
Chris Tarbell
I don't know if you. You need that. I think you got plenty.
Hector Monsegur
Well, I mean, you know, I got the hair, but, you know, listen, I wanna. I want the old school 1970s Greek chest, you know what I mean, with the air everywhere.
Chris Tarbell
Pour some of that on your chest so. So it really sticks into your hair.
Hector Monsegur
See, that's what they adore. Like that sticky. I don't like that.
Chris Tarbell
That was my dad's worth. Nightmare. He hated sticky. He never wanted to be sticky. Yeah, that was his thing.
Hector Monsegur
Yeah, I can't deal with that, so.
Chris Tarbell
All right, well, guys, Heck and I had a fantastic Patreon episode prior to this show. So download, join the Patreon, Help support the show. Maybe if you support us better, we can kick Alanis off here. I don't know. Who knows exactly. Help us out on the merch Hacker in the Fed dot com. You ready to get into it?
Hector Monsegur
Heck yeah. Let's have some fun.
Chris Tarbell
Big freaking story this week. How two WordPress core bugs chained into a pre auth rce. First of all, explain that title to the people. What is. What is chained into pre auth rce?
Hector Monsegur
Bean. All right, this is fantastic. So imagine a scenario where you go to a website and you go to the website and it's just there. It's the like, let's say Facebook or Twitter, whatever, and you see content and then you can log in and create an account. Once you create an account and you log in, that's post authentication. When we're talking about pre authentication, we're talking about. All we need is just access to the website, not an account, no credentials, nothing needed. Then you have WordPress. WordPress is a blog, and it's a blog platform, has been used by people all around the world for, you know, I don't know, 18 years or more, maybe. I forgot what year they were created.
Chris Tarbell
I think he's probably longer than that, right?
Hector Monsegur
Longer than that, yeah. And so word. WordPress itself, you know, it's pretty. It's pretty mundane, man. It's just a. It's just a. A way for you to log into your. Your website and just upload some content, post a picture or two and then write a press release and move on with your life. What companies do is instead of building out like entire website and creating a CMS, a content management system, they'll use WordPress for that, which is fine. You have WordPress deployed by these companies, you have a pre authentication and then you have the chains component. And what that means is that it takes several steps. You combine several different steps to create an attack path.
Chris Tarbell
And these steps are the vulnerabilities. You're essentially using two vulnerabilities to get past normal security procedures.
Hector Monsegur
Well, let's talk about, you know, what the attack actually looks like. Right. So when the CVEs came out, there was a reference to a SQL injection pre authenticated so it doesn't require an account, for example. Then you're able to send a payload which then would allow you to, you know, execute a query on the backend database for that website. Now the idea there for the next step, according to the proof of concept from this weekend, the next step was to create a rogue administrator account and then modify a plugin and then be able to execute commands. That opens up the doors to RC. Okay, so that's what that looks like. WordPress unfortunately has a history of terrible security when it comes to plugins. All sorts of SQL injections, all sorts of back doors, front doors, developer accounts being hijacked and malicious plugins being uploaded. But that's not, that's not the case here. The adversaries in this case, the researchers just use plugins to kind of backdoor. Once you get a rogue admin account to then run commands.
Chris Tarbell
And are any of these malicious plugins, can they be used against people visiting the website?
Hector Monsegur
Well, yeah, someone could upload a malicious plugin to their website after they've compromised. Sure they can.
Chris Tarbell
That would affect users, just regular users that come to the WordPress site.
Hector Monsegur
Yeah, it could, it could be used to target users for sure. I mean that, that's not the basis for this, but that's, it's totally a possibility. There are several possibilities from something like this. If you have an old WordPress site and it's compromised by means of this attack chain. Yeah, you're going to have stolen credentials, stolen, you know, user information, emails, password hashes. They, the attacker could upload malicious stuff. We've seen in the past where there's been like mass targeting of WordPress blogs and then they will inject like a credit card stealer. We've seen that a lot. Right. That's a big one.
Chris Tarbell
Sure.
Hector Monsegur
In fact with like we, we covered the Caspitel's website at some point last month or two months ago, right?
Chris Tarbell
Yeah.
Hector Monsegur
Where he had some sort of CMS and it was breached in some capacity and, and then someone uploaded a malicious skimmer to steal credentials of his fans who were buying like, you know, whiskey or whatever. Right. So it's, it's definitely a real concern and, and a real possibility.
Chris Tarbell
So the vulnerability is now impacting millions of sites and WordPress has released a security patch to fix it. But the problem historically is most people that are using WordPress are low level websites. I mean, right. That's not, that's not understating it, right? That's not, I'm not putting anyone down, but it's not, it's not like someone running a WordPress site most likely doesn't have a security team checking for updates. And is WordPress historically had automatic updates or is the site administrator by default have to go in and apply these patches?
Hector Monsegur
That's a great question. So right now most modern installations of Web WordPress do have automatic updates by default. That should be a thing.
Chris Tarbell
All right.
Hector Monsegur
But you cannot, you cannot rely on that. Right? You have to. Any error, any network error is going to break the update. So if anyone's listening here and you have a WordPress site that you deploy for your website for your company or something that you know, some hobbyist project or whatever, family project, go check it out, log in as admin, make sure it's updated and might want to check your server logs as well because there's a potential that there's been a breach. You could probably start by looking at your, your, your admin group to see if any new admins have been added or if any accounts have had their passwords changed recently. And you know for a fact that's not a possibility. Right. But yeah, if automatic updates are up, up to date, they're running on the server, you have version 7.0.2 running, then you're much in a much better state. If you're running an old ass WordPress from 12 years ago, more than likely you might be running into problems from other vulnerabilities. Not even this one, because this one I think is very limited to 6x to 7, maybe 5x, but who knows.
Chris Tarbell
So interesting side story that came out of this one is that Adam Cues of Searchlight Security. Searchlight, sorry, Searchlight Cyber. I'll give him his proper flowers. He discovered the remote executable vulnerability. Historically, brokers have paid up to half a Million dollars for comparable WordPress RCE0 days. He's, he's reportedly found this one and it cost him $25 in AI tokens. Interesting, right? 25 bucks and a little bit of knowledge can make you half a million potentially.
Hector Monsegur
Well, here's what's fascinating about the way he did it though, right? Big shout out. Again, shout out to, to Searchlight Cyber. I believe they own Asset Note. I could be wrong. They do have Acid Note and Acid Note is like a, an asm, an attack service management platform. Now what's fascinating about what he did in terms of discovery is that he follows the news just like, just like we do. And one of the stories that he caught during his day to day is a story that was published by mathematicians online and OpenAI where a famous mathematical conjecture called the cyber the cycle double cover conjecture was solved using a very specific set of prompts. And so what he did was since OpenAI published the prompts, he copied it, he modified it and then he ran it against the Source code for WordPress and Bada Bing, it identified this attack chain, which is fantastic.
Chris Tarbell
That is, that really is fantastic. Like it's, it's not, you know, it's not rocket science to just watch the news when, when a math thing like this is solved. But to think about it is, hey, well if this is solved, what programs out there are using this? And because now that becomes a vulnerability. That, that is ingenious.
Hector Monsegur
Yeah, yeah, I mean it's the, it's the, the prompt engineering side of it is what's cool. You know, the fact that he spent 25 bucks is amazing.
Chris Tarbell
Yeah. And shout out to Adam. You and I are just reviewing old episodes of Bang Bus and Adam's actually applying what he sees on the Internet to things.
Hector Monsegur
Yeah, yeah, yeah, yeah, exactly.
Chris Tarbell
Right?
Hector Monsegur
That's true.
Chris Tarbell
Interesting stuff. So Uber Eats exposed somebody. So really Zyria. Zaire.
Hector Monsegur
Oh, this guy has a crazy name.
Chris Tarbell
Yeah, I'm just going Zaire Wilkins.
Hector Monsegur
No, no, no, we gotta do the whole thing, bro.
Chris Tarbell
We do the whole thing. I am not even trying it.
Hector Monsegur
All right, so here guys, you gotta hear this one. This is awesome. Right? So I'm gonna go with Zaire. Dante. Dante. Okay. Zaire. Dantavius. Zamarion Wilkins. I got it.
Chris Tarbell
All right, maybe.
Hector Monsegur
No, that is, that's it, bro. That is it.
Chris Tarbell
He's a 21 year old student at the University of West Florida and he has an online name, Sibyleth. I don't know.
Hector Monsegur
Cybo.
Chris Tarbell
Yeah, I don't know. Was arrested by the FBI. And charged with conspiracy to obtain information from computers for private financial gain. He allegedly financed, procured and helped market eight malware laden video games distributions primarily via Steam. Between May of 24 and February 26th. The malware infected approximately 8,000 devices and was used to steal credentials and drain at least $220,000 from roughly 80 cryptocurrency wallets. He was arrested following the FBI raid on his north of Lauderdale in Florida home. The case is being prosecuted out of Seattle. Faces up to 10 years in prison if convicted. You want to get into the attack vector. You want to explain sort of how that worked?
Hector Monsegur
Well first off we covered this story before. This was the story where there was backdoors, team games. We've covered this at least twice and you know, we were concerned that there were going to be kids out there using their home personal computers that are being shared with corporate employees in the real world. And he proved it right. He proved it because by developing and distributing backdoor games on the Steam platform, it allowed him to compromise a ton of ton of people. You know, you got 200 plus thousand in crypto alone. One of those victims was actually covered by VX Underground, you know, pretty popular Twitter group, you know, the team out there on X X Twitter. One of the victims was a cash, a cancer patient literally dying and they needed the money. It was like 25 grand, 24 grand. This guy stole from that one person, person and that person unfortunately has passed away from his cancer, you know, situation. So yeah, this guy Zier Dontavius is a complete scumbag for what he did. Now as for the technical bits, here's the technical bits, right? They were able to, you know, use you know, whatever platform to kind of create these games. They you know, insert into these games these back doors maybe on the second publication or update rather than the initial, you know, update because those get, you know, I'm sure this was sort of review of these games when they're first posted. At some point they backdoored those games, infected a bunch of computers with malware and based off of what the FBI is saying, more than likely it was like a info stealer family. They used, it seems like they bought a rat, a remote access trojan for about 10 grand. So boom, right? They didn't deploy that on a whole bunch of computers. They stole credentials, they stole wallets. Now this is where crypto becomes crazy. You see how all these guys are getting involved in hacking into exchanges. There's a big story out of the uk they arrested the two guys that were involved in The MGM and Caesar hack saw that, right?
Chris Tarbell
I did, yeah.
Hector Monsegur
These guys are, how we say in Spanish, Novapo. They're neophytes. They're, they're complete, they're not criminals.
Chris Tarbell
How we say it on, we say it here, we say Fugazi.
Hector Monsegur
Yeah, they're fugazi for sure. Because this guy Dontavius, whatever the fuck, he got caught because he had no way to, you know, convert that, those crypto into like actual money or funds that he could use. So instead he would just use the crypto and use crypto sites to convert those into gift cards. And so he was basically stealing from cancer patients to buy Uber Eats. That's.
Chris Tarbell
Yeah, he, he used bit refill gift cards to purchase his Uber Eats and then he used those gift cards to send food to his real address with his real phone number.
Hector Monsegur
Come on, come on. What the hell is going on here?
Chris Tarbell
Yeah, even in the back in the days of Craigslist, you always had the package sent to your neighbor's house and then the neighbor that was at work all day.
Hector Monsegur
Facts, facts.
Chris Tarbell
And you just leave the instructions. Just leave on porch.
Hector Monsegur
Yeah, this is, this is the reality folks. When Chris and I are talking about these kind of adversaries. And you'll hear that, you hear it on Twitter, you hear it, you'll see it in the FBI report. This sophisticated actor did this. X, Y and Z. No, it's not sophisticated sophisticated. You know what this guy did? This guy used, he abused a system of trust to upload a game that attracted your child into downloading, was able to get your crypto and then buy himself Uber eats while he went to school. You know, it's, it's such a, it's such a tragedy because you know, especially now what I know, right? Knowing what I know now today, rather than, you know, what I was doing, I wasn't doing this dumb shit, but I was definitely hacking. Back in the days you start to realize there are actual victims at the end of this, you know, especially when it would involve stealing their money. Like, come on, bro, what are you guys doing?
Chris Tarbell
So this one's kind of fun. So an alleged Russian cyber spy in Boston case previously worked for Kaspersky, sources say and documents show so Dennis Oberosco. Man, these names are killing me. Today a Russian national faces US federal hacking charges in Boston for allegedly involvement in the state sponsored Void Blizzard, also referred to as Laundry Bear. Cyber Cyber esp. We covered that. So many on this plate that stupid names Cyber astronaut campaign targeting NATO aligned European government agencies and at least 11 US companies involving mass theft of emails and communications on behalf of the Russian government. Dennis previously worked for a senior specialist at Kaspersky lab in Moscow from 2017, 2019, and for the Russia's FSB intelligence service for approximately five years prior to. He later served as deputy director of an FFB licensed company. He pled not guilty to computer crimes during his July 9 hearing in Boston. No new arrests and additional charges, but looks like a guy that was tied to Kaspersky may have done some state sponsoring hacking for. For Russia. I have heard a lot of crazy things about Kaspersky and how much Kaspersky allegedly is aligned with the fsb.
Hector Monsegur
Well, I've heard that, plus I've heard the, the response from the Kapersky people. Yeah, they've made a lot of effort in saying, no, no, no, we may be of Russian origin or we may still be located in Russia, but we assure you we are, you know, we're, we're adhering to ethical standards and we're, we're, you know, we're not aligned with any specific government. We're just trying to offer cybersecurity services. You know, at some point, I felt bad for them because there was a point in like 2018 or something where, like, I think it was Obama or somebody. No, 2018, no, that's way beyond Obama. Somebody, somewhere. I forgot who it was or what year. They, they put like an embargo against Kapersky. You remember that? That was a whole big thing.
Chris Tarbell
Yes, I, I definitely remember that.
Hector Monsegur
Oh, yeah. And so I had researchers from Kopperski talk to me at the time, and they're like, bro, this is not fair, you know, I said, well, so fucking leave Moscow. What the fuck? If you want to do. If you want to do business in North America. But then that's like, that's like a Russian telling me, hey, if you don't like what's happening in the U.S. just leave the U.S. like, it's, it's, it's not realistic, so you just gotta just be right. But it sounds like this guy worked for Kopersky for about two years. He's aligned with the fsb. It's just another black eye for Kapersky. I'll be honest with you. I. I don't know how they could continue to survive, you know, within North America. I don't think they came to do business here. I don't know.
Chris Tarbell
Do you know anybody that uses them?
Hector Monsegur
Not anymore. They used to, back in the days. First was everywhere back in the days.
Chris Tarbell
I always said they. The Chris Percy was the best because they're the ones putting the viruses out.
Hector Monsegur
Oh, my boy. You subscribe to. To, you know, one of the old theories, and I'm with it. Right. Which is that the. The virus scene of the 80s and the 90s is really what blew up that industry. A part of the industry, if you were a fan of viruses, malware back in those days, which I was, even though I wasn't really big into deploying it. But I was fascinated by the community, Chris, I really was. Because they had all these massive programmers working together to figure out how. How to circumvent this thing or another. It's just like hacking, right?
Chris Tarbell
Yeah.
Hector Monsegur
And so what I remember is one day there's. It's like malware research for, you know, hobbyists. And then all of a sudden you have McAfee, you have Dr. Whatever the hell. Right? You have Koppersky, you have AVG, you have like 10,000 security companies selling antivirus software. And all of a sudden every other day is a brand new scary virus that destroys your shit. And it just kept happening until it just disappears one day. And now we have EDRs to deal with anomalous execution.
Chris Tarbell
Yep. Anyways, it was the same way in the DDoS mitigation world in the early 2000s.
Hector Monsegur
Oh, yeah, of course I remember.
Chris Tarbell
100% it was the same companies. Because I knew of one company that. So you're getting DDoS, your whole website's down. You sell commerce. You can't do anything. They wouldn't even pick up the phone. Phone for less than $40,000.
Hector Monsegur
Sure.
Chris Tarbell
To take your phone call if you're being under attack. It's 40 grand.
Hector Monsegur
Listen, I remember those days clearly, man. Cause I remember I was at war. One of those companies on fnet, you know? And you think you're like, back in those days, you had the FBI rated. FoodNet, that's one of the companies, right? That was in New Jersey. You had a big data center over there. Then you had, like, cogents, you had prolexic, whatever the fuck you had. All these different companies doing, like, bulletproofing, DDoS protection. And then it's like, wait, but where's all the DDoS is coming from, though? You know? You know, I don't know, man.
Chris Tarbell
I don't think it was real hard to figure it out.
Hector Monsegur
Oh, yeah.
Chris Tarbell
So, heck, this may. This may put a little black eye on your world champion New York Knicks. No, no, no, no.
Hector Monsegur
Let me. Let. Let's separate the New York Knicks from msg. That's how you're going to do it. That's how you start off.
Chris Tarbell
I don't know. I mean, I. It's either that or the wedding venue of Ms. Taylor. Kelsey.
Hector Monsegur
Wow, that's her new name, huh?
Chris Tarbell
I get. I. I don't know. Taylor Kelce, maybe Travis Swift. I don't know. I don't.
Hector Monsegur
Travis Swift does sound cool.
Chris Tarbell
If he, if he came out the first game. If he. Is he still playing for Kansas City?
Hector Monsegur
I don't think so, bro.
Chris Tarbell
I, I think if he is. I don't know if retired or not. If he is, if he came out in game one with Swift across his back on a new Jersey. Oh my God.
Hector Monsegur
Yeah. Oh yeah. That'll be scandalous. And they'll make a few more million dollars off the scandal.
Chris Tarbell
So Madison Square Garden, msg or also MSG Sports Entertainment has operated a facial recognition and biometric profile system since 2018, secretly creating risk and threat scores and dossiers on attendees, celebrities, athletes, fans without consent or notification. Examples have included labeling individuals as low risk or high risk. You know, I've been in Madison Square Garden probably a dozen times since 2000.
Hector Monsegur
Same year, man.
Chris Tarbell
Yeah, I'm gonna guess I'm low risk. And your brown house is high risk.
Hector Monsegur
My brown ass is high risk. Yeah, no. Oh yeah, I, I agree with you on that one for sure.
Chris Tarbell
So honor around June 5, the night of the Knicks NBA Finals wins, shiny Hunters compromised the organization via vishing which is a voice phishing of a low level employee, gained access to their Microsoft Entra ID and exfiltrated data. Approximately one month later, Shiny Hunters published about approximately 45 gigabytes of data containing approximately 26 million records, including biometric surveillance logs, internal threat assessments, VIP dossiers, celebrity personnel details and customer complaint emails, all about the facial recognition system. So Shiny Hunters we and moan but now they've done a little bit exposing of what these major corporations are doing.
Hector Monsegur
Yeah, and I feel like it's a tip of the iceberg, you know, msv, MSG can't be the only one doing this. There's been stories and exposes of, you know, kind of like what they've been doing with regards to tracking potential bad actors going to msg. A good example is, you know, Oakley, Charles Oakley was banned from MSG for having a conflict with security guard. And then, you know, every time he tried to show up, it was a whole big thing. They always kicked him out, they blocked him at the doors. So this has been, you know, something that folks in New York have been talking about like, hey, what's going on with msg? You know, what are these guys doing? And yeah, now we're actually seeing the data. The data has been published, at least some of it has. And I'm sure there's some journalists here in New York combing to that data as we speak.
Chris Tarbell
Do you are. You're not surprised by this, right?
Hector Monsegur
I'm not surprised by it. I'm not happy with it either. You know, there's. It's one thing to have surveillance, right? Because you know, you're running msgs. There's a potential vector there for terrorists, right? Mass casualty event will be massive from msg. I get all that, right? There's a reason why they have a lot of security there. I get all that. But then the problem is when you start using AI, you start centralizing that stuff, start keeping our pictures and databases, and then you start profiling us. That's what I have a problem with. As somebody from New York City that grew up with racial profiling, if you guys don't know what that is, Google it. Type in NYPD racial profiling 2000s. Your boy Hector was profiled just because of the way I look. And I was stopped an average of two times a day. I went to work, I got stopped, I came back from work, I got stopped. In fact, Chris, when he arrested me, said, dude, you got stopped so many fucking times. They even arrested me for murder during that time when I did not commit a murder.
Chris Tarbell
Allegedly.
Hector Monsegur
Allegedly. No, I did it. I didn't do no murder, dude. I'm too much of a humanist for that. I would feel so bad.
Chris Tarbell
I mean, the only reason I arrested you is because you're brown.
Hector Monsegur
Yeah, there you go, you see, finally, it's out. It's out. But, but all jokes aside, I'm not keen on that profiling, you know, especially if it's stored long term and it's then going to be used against people. Right.
Chris Tarbell
You know what? I can tell you again, I can't say it as a fact. It's all allegedly. You know who's got this data?
Hector Monsegur
Who?
Chris Tarbell
Nypd, of course. Every big security job in New York City is a former NYPD guy, Of course. And they got their hooks right back into it. So any of the data that MSG is collecting goes right to them.
Hector Monsegur
Oh, yeah. Oh, yeah.
Chris Tarbell
Well, every freaking doorman in New York City is on New York City's play role. New York City police play role because they, they need info. They need what packages are going in place. And again, it's to get the job done. But you think your information's private. It is not.
Hector Monsegur
Not. Well, that's the problem. Right. You know, it's. As a society in the United States, we're very quick to, to put judgment on China. China does this. They have a credit system. Well, we have a credit system too. Well, they have surveillance. Well, we have surveillance everywhere too. Or they have centralized this. Yeah, well we have that too. You know, it's very easy. You know, George Carter, I don't bring him a up a lot, but he had some really good philosophy on this where he said here in the United States we do something with language and it's very Orwellian, which is like, you know, instead of propaganda is, you know, it's messaging and instead of censorship is moderation. And so what you see here is no, it's not surveillance, it's just security. It's so.
Chris Tarbell
Yeah, I mean, so. I mean one thing we're not to overpass on this thing is, is these guys got in because they impersonated an IT support to a low level person who then provided their credentials. Now whether that involve, you know, multi factor authentication also, who knows?
Hector Monsegur
Obviously not.
Chris Tarbell
It may have. No, they, they got to trick the person into giving them that. Hey, there's about. We're. We're about to send a code to your phone. What's the phone? What's the code? So you know, if you, if you're doing a voicemail, a voice call, you know, that's easy to get, get past the, the mfa, but you know, they've also. It's interesting. So MSG has not issued a public statement on it, but multiple class action lawsuits have already been filed in the southern district of New York about this. And it's not about MSG collecting it. It's their failure to protect it. They're su. They're suing because they. Yes, you have my biometric information. I guess I agreed to it by purchasing a ticket and entering your facility. Sure. And you should have protected it better. Is with the lawsuit, not that you're actually storing this.
Hector Monsegur
You know what? I'd rather that than nothing at all. Right. I'd rather there be some accountability because yeah, if you're going to store that kind of information and you're getting ops with a low level attack, the same thing that happened in Vegas a couple years ago and you have not learned since then, then there's clearly some gaps in your security you have to kind of sort out.
Chris Tarbell
I mean where are you at a privately owned facility saying putting up a big sciences. We're going to take your picture, we're going to build a profile on you. We're going to track every, every movement. Don't come in and watch the Knicks if you don't want. You're all right.
Hector Monsegur
If, if that sign is up, then I, then I'll make the decision.
Chris Tarbell
What if it's in really tiny letters right before you hit, you click buy.
Hector Monsegur
Well, that's, that's the shitty part, right? Because that's how they do it. That's how a lot of these guys get through to violating our civil liberties, you know, and this is, this is a basic, fundamental privacy. But the problem here that we have in the United States, if you guys have been paying attention, is that you have people that are literalists. You know, they'll read, they'll read the, constitute the Constitution literally. They'll read the Bible literally. And then they'll tell you, well, if the word privacy is not in the Constitution, then you're not entitled to privacy.
Chris Tarbell
Right.
Hector Monsegur
They'll tell you that to your face. And it usually comes from one party, you know, and it's the Democrats. No, this is the Republicans, the liberal libertarians. Well, I don't even think they're Libertarian. I don't even know. I don't even think they know what they are at this point. I don't even think they know whether they're Republicans or not. But that's besides the point. The, the real point is that there's no respect for our privacy here. Whether you're a paying customer or not. Look at all the drama that Americans had to go through to lobby Congress to deal with, you know, the Deere company, you know that, you know, you have equipment. I have a John Deere, you have a John Deere. And up to recently, if you decided to work on that John Deere, then you voided all warranty and you're screwed. You can't even get replacement parts. I think things have changed more recently, but it's taken 25 years of fighting in court to get to this point, which is absurd to me.
Chris Tarbell
Yeah, the next one is the three second theft. I thought this was how you lost your virginity, but apparently not. It's why AI Voice fraud outruns every defense. So AI Voice cloning enables rapid social engineering fraud, for example, a grandparenting or family emergency scams where attackers use just three seconds of publicly available audio to generate convincing synthetic voices that demand money or information under emotional distress. So we've covered this before, but you know, some concrete examples came out, like in the summer of 2025 in Dover, Florida. A woman named Sharon lost $15,000 after scammers cloned her daughter April's voice from the social media clipping and then simulated a car accident involving a pregnant woman and demanded cash bail by a fake attorney. And it's getting worse and worse. You know, heck, I think we're putting ourselves in danger by putting this podcast out.
Hector Monsegur
Well, it's. It's too late for that, brother.
Chris Tarbell
We got.
Hector Monsegur
We. It's too late.
Chris Tarbell
Well, it also saves us, though.
Hector Monsegur
Sure, we can always say deniability.
Chris Tarbell
We didn't say that. That's AI.
Hector Monsegur
Yeah. You know, Chris was talking about tanning his balls out in the field. That's. That's. That's for g. His AI Stuff.
Chris Tarbell
Heck wasn't in the Epstein's list. That's all fugazi.
Hector Monsegur
No, no, listen. I was not on that list. That's right. That is right. Let's make sure we correct that. Well, yeah, you know, it's sad. It's very sad because this is part of a much bigger story with, like, the whole 764 nonsense of cults. There are cults of people online on Discord working together in tandem, using technology and AI to extort children, extort little girls, extort little boys. They extort. Gr. Extorting grandmas. I read a story on Reddit. Whether it's true or not, because there was. There's obviously no source to it. It's no news article. But, you know, I read a. I read a report. Not even a report. It was a guy doing, like, a confession. And, you know, he. He had finished. He. He had detox from Kratom. Kratom, whatever you call that.
Chris Tarbell
That. Was that at the girl at the gas.
Hector Monsegur
Gas stations. Yeah. Apparently it's a massive drug. It's like heroin, bro.
Chris Tarbell
Yeah. And it's not regulated at all yet.
Hector Monsegur
Yeah, it was like K2 when K2 was public, right?
Chris Tarbell
Bath salts, people eating each other's faces.
Hector Monsegur
Oh, yeah. So this guy said, hey, I finally detox. But, man, it was a battle because I had my. My little niece. She was 15. They found a Roblox, they made her take pictures of herself, and then they forced her to kill herself on live camera. Whether that was true or not is. Whatever. Here's the reality we know from court cases, you know, and. And, you know, convictions, arrests, especially recently, of these 764. And these. All these different cults, these subsidiaries that have been targeting people, just like this grandma story here. And they're relentless, brother. They have no ethics. They have no humanity, no empathy, no sympathy is all for a quick buck and a couple of laughs, bro. It's very much anti human. Okay?
Chris Tarbell
If we're shoving all these guardrails on AI, why can't AI determine that this shit is beyond what it should be intended to be used for?
Hector Monsegur
Well, here's the double edged sword. I myself, I'm an open model guy, right. We have our own servers, we're using local models, right. And we're able to do so much to help people. Just me, just with seifill, right. And there's a lot of other people like me doing the same exact thing online. Now when you're running a local model, Chris, you control the guardrails, okay? Especially if you're using an uncensored, you know, large language model. Okay, now what does that mean? That means that a lot of these bad actors will do the same thing, but they'll use their uncensored models and their local deployments to do what you were talking about in this article here without having to deal with anthropic and OpenAI's guardrails whatsoever. So it's a double edged sword, unfortunately.
Chris Tarbell
Where do you, where do you fall on you still even all the bad things that can come along with it. You're still, you know, open source guy, like just. I'm still use it the way you want to use it.
Hector Monsegur
I'm sort of open model guy because I feel that we could do a lot more good than bad. Just like, you know, the second amendment with guns. There's a lot of people arguing on both sides saying that hey, having guns in a big city is bad, but having no guns is worse. And there's a whole bunch of reasons on either side with stats from both sides, you know, and so, you know, it's one of those situations like well, here's why status, here's what I'm willing to do to do good. You know, there's always going to be a bad actor in all these different scenarios. And that this is one of those.
Chris Tarbell
It's crazy that all you need is three seconds from a, like an online social media post and you can get the voice.
Hector Monsegur
Sure.
Chris Tarbell
A voice that even gets a mother.
Hector Monsegur
Well, this is why if you look, if you, if you guys look at the Ferrari story from several years ago where you know, the CEO of Ferrari gets a phone call and they're asking him information. I think it was his co founder or partner investor and they were asking information about like hey, so what's the latest Ferrari model is coming out? He Realized that already is off. That's. That doesn't sound right. So he asked the guy, hey, so yeah, before I get to that, remember that book we were talking about? And the person hung up the phone because it went off script. They didn't have the copy first that. To deal with that. Okay, so when you guys get a phone call and it's like, hey, we just kidnapped your daughter and you know, we need $20,000 in Ethereum or whatever. Right. Well, what can you do at that point?
Chris Tarbell
Well, I mean, it's their calling and they're actually describing a crime. It's a kidnapping. I think some of these more are more like, you know, oh, there's been an accident, they're in jail or something. So, yeah, that, you know, you're. You're less. You're less likely, I guess, to freak out about it. You think this is the way it happens? You think that the police call you and set the bail over. Over the phone and tell. Tell a loved one that that's how it works.
Hector Monsegur
Yeah. We don't do that.
Chris Tarbell
Right.
Hector Monsegur
That's the way we got to. That's why the law enforcement got to do. We don't do that. You know, you see, when you go to USPS website, we're going to tell you, hey, if you received an email, phone call, text message from us asking for X, Y and Z, that's not us.
Chris Tarbell
Yeah.
Hector Monsegur
You know, you might have to have the FBI do like a nationwide thing like, hey, we would never call you, or ambulance is not going to call you, or the lawyer's not going to call you to ask for money over the phone. That's not how things work.
Chris Tarbell
You know, you say that I recently I was telling my daughter a story. I don't. I don't know how it came up, but Emma Stone came up in conversation and I had to. I had to call Emma Stone one day. Did I tell you the story?
Hector Monsegur
No. Remind me.
Chris Tarbell
No, I had to call Emma Stone and it was such a. Trying to get a hold of her. Like, I got her manager's number and I tried. I got her cell phone number and all that, and she didn't answer. And like, trying to call a major celebrity in the first place is difficult. And then trying to convince them that you are an FBI agent, what I'm telling you is legit is even harder. So sometimes the FBI does call you.
Hector Monsegur
Yeah, well, it's one thing to call. There's nothing to ask for money. Right.
Chris Tarbell
That's true. That's that the FBI will never ask for money.
Hector Monsegur
Yeah. So we gotta. We gotta. We gotta pay attention to the cues, right?
Chris Tarbell
Yeah.
Hector Monsegur
What. What is an FBI agent going to do when they call you an ambulance or a lawyer versus what an adversary might do, Right?
Chris Tarbell
I mean, retired FBI may ask you for some nudes.
Hector Monsegur
Hey, this is Chris Tarbo. Do you have any nudes laying around? You got to send them to me now.
Chris Tarbell
That's AI. AI said that, not me.
Hector Monsegur
Not me.
Chris Tarbell
But. But if you do, send them at questions@hackerthe.com.
Hector Monsegur
yeah, listen, we don't need more news. You already see enough balls on the freaking email.
Chris Tarbell
I'm not for that anymore. What? Send them directly to Chris at Hacker in the. Fantastic.
Hector Monsegur
There you go. That works.
Chris Tarbell
So hackers revealed the Sono AI music generator scraped YouTube and Genesis. So a hacker breached Sono, which is an AI music generation company, and accessed internal source code and trading data sets. Details revealing that Sono had scraped millions of songs, lyrics and Audio files from YouTube Music Deezer, Genesis, Pond 5, Freesound, and many more places. The breach also exposed customer data, including emails, phone numbers, and stripe payment information for hundreds and thousands of users. So hackers are revealing these companies doing some dumb.
Hector Monsegur
Yeah, well, they're doing dumb stuff. Illegal stuff. And I. I feel like we covered this already. We talk about it at least. At least a bit. What's crazy about this story, though, regardless, is how this company allegedly, you know, they stated that. No, we were not. We're not copying, like, YouTube. We're not copying, you know, a copyrighted music. We're cop. We're copying music that's. That's publicly accessible, like, public domain music. Right. These adversaries sold the world. No, that's not the case. These guys are lying to you. Now, what's probably going to happen is they're going to get sued into the, you know, into The Abyss by YouTube, by Spotify, by all these massive, you know, production companies and music companies. Yeah, I mean, it's a tough one. Try not to be shady and have, you know, crap security.
Chris Tarbell
Right. I gotcha. But, yeah, I don't know. All right, brother, I think. I think we've reached the end. I don't. I don't. I've sort of out. No, no, no, no. Wait, wait. We do the last story. We will do the last story. I know you love this. So White House teleprompter operator made more than $100,000 betting on Trump's speeches. So Gabriel Perez, a longtime White House technical assistant and President Trump's Teleprompter operator since 2016 allegedly used non public knowledge to prepare presidential remarks and last minute edits to place bets on mentioned predictions markets.
Hector Monsegur
So.
Chris Tarbell
Oh, cow mentions predictions markets. He profited over $100,000 across more than a dozen speeches and events including the February State of the Union, a December prime time address and January World Economics Forum remarks. The bets were placed on whether specific words, phrases or topics would be uttered. Perez reportedly exited some positions mid speech when Trump deviated from the script. How the fuck did he not think he was going to get caught?
Hector Monsegur
Well one, yes, that's a great question to Gabriel Perez in the White House. Come on, what is that? What's going on here?
Chris Tarbell
What do you mean? I don't know what you're saying.
Hector Monsegur
Hey man, I don't know, it sounds like a brown person name to me, brother.
Chris Tarbell
You think they hung about to dry? You think they dangled him out there for, for this one?
Hector Monsegur
Well here's, here's the reality. These prediction markets have really exposed the, I would say that that part of us, of the humanity where it's greedy as hell, where you're willing to give up your job for a quick buck. A hundred thousand dollars. I'm sure he was making more than that as a teleprompter operator. And even then, even if he was making less than a hundred thousand, he was working at the White house for like 20 something years. Like this guy was a senior member of staff at that point for that space.
Chris Tarbell
I don't think he's senior member of staff. If you're, if you're preparing remarks on a teleprompter, you're not advising the President.
Hector Monsegur
I'm not. That's not what I was saying at all. Okay, that's not what I was saying at all. What I was saying was he's been around so long within that job and he's senior level. Right. There's no way that the homeboy was advising the President, but there's also no way that this dude was, you know, powerless like an intern. Yeah, dude obviously had access. And so to give all that up for a quick bet on Kalshi or Poly Market, it's crazy. But we've covered, we've covered several insider traders so far. Double entendre on the trader part. And so, you know, they seem to be catching the low level guys. They never seem to catch the people doing the insider trading on oil during a war. That's the one they won't catch.
Chris Tarbell
Well, you keep saying that they're there. You think they would have caught him by now.
Hector Monsegur
I mean, you know, I don't know, I don't know what's going on with that, bro. You know, but, but yeah, we're gonna see probably more of this.
Chris Tarbell
And you know, it's strange that people with the inside access, you know, it's, you know, I, I've heard stories of, you know, the FBI jumping on like fights, UFC stuff, you know, when the bets get too big. Like all these betting places, either whether it's, you know, the DraftKings, the MGM's, or even the prediction markets, when a crazy amount of money comes in on one side, it automatically sends up a red flag. You know, it's, it's sort of like, I know they do this for a fact in the markets. If you're making more than like a certain percentage, they look at your shit and see where you getting this access from. Yeah, maybe you might be lucky once or twice, but you're not lucky every single time.
Hector Monsegur
Sure, sure.
Chris Tarbell
So it's, it's, it's. I, I don't understand how these guys keep getting caught. Like you said to, to lose a six figure job just because you want to make a few extra bucks. Because it was easy. It's crazy to me.
Hector Monsegur
Yeah, it's tough, man. And I, I get it. I mean, times are hard right now, you know, but you know, for any of you guys, any of you people, wonderful, wonderful listeners listening, if you see an opportunity to do an inside threat of inside threat, don't do that either. On an inside. Yeah, definitely don't do that. But if you have an opportunity for an inside trade scenario, walk away. It's not worth it. I promise you. It's not. You might make a quick 50 grand, but that 50 grand is going to cost you X amount of years of prison. You're going to lose your job and you're always going to have that dark mark over you, man. It's not cool.
Chris Tarbell
Not cool at all, sir. Guys, support Hacker in the Fed on the Patreon. Support Safil. If you guys want to know more about or learn about their threat exposure management plan platform or their penetration tested services, reach out to hect on LinkedIn or visit safe hill.com email them at info safehill.com tell them you heard about a hacker in the Fed. Let them know that their support of Hacker in the Fed is paying off. Just go over and visit them. Come on, help us all out.
Hector Monsegur
It is a nice website.
Chris Tarbell
Come on. Merch is up at hacker in the fed.com 5 star reviews. Wherever you download, subscribe to podcast Share us on social media. Tell your worker, co workers, tell your friends, tell your people that's got the diarrhea diseases going around the United States.
Hector Monsegur
Hey, what's up with that?
Chris Tarbell
What's going on while you're sitting on the can download hacker in the Fed? You got the. You got the diarrhea.
Hector Monsegur
Anyways, you got the time.
Chris Tarbell
Yeah, you got plenty of time. You got two weeks of the shits. The squirts are going to happen.
Hector Monsegur
Is that the new Ozempic, though?
Chris Tarbell
Oh, maybe, maybe.
Hector Monsegur
You know what I mean?
Chris Tarbell
Taco Bell, the new Ozempic.
Hector Monsegur
Listen, I. I read. I read a guy on Twitter. He said he lost like £12 at one week with that, bro.
Chris Tarbell
So I don't know literally why it's on top of mind. While I was sitting here during the podcast, one of the mean girls just texted me and said her mom's got it.
Hector Monsegur
Oh, no.
Chris Tarbell
Two weeks on the bowl.
Hector Monsegur
Oh, man. Two weeks.
Chris Tarbell
Her mom's not got a lot of room to spare. This girl. Woman's in very good shape. She's got. She's not got weight. Yeah. So. Poor husband.
Hector Monsegur
Poor husband. Jeez. Listen, man.
Chris Tarbell
Again, not one of the mean girls, but mean girl mom.
Hector Monsegur
Well, you know what? It's close enough. The mean girl. You better be careful. You know what I mean?
Chris Tarbell
We all better be careful.
Hector Monsegur
You too, because now it's time. Now you're like. It's. It's like a. It's two degrees of separation, bro.
Chris Tarbell
Have you seen the brown map? Have you got on the Internet and looked at the brown map with the diarrhea spreading?
Hector Monsegur
No, I haven't seen it yet.
Chris Tarbell
I just expanded it to my area. I now am part of the. The brown map.
Hector Monsegur
I'm sure I'm all part of the brown map, too, brother. And you know what?
Chris Tarbell
Different brown map.
Hector Monsegur
Different.
Chris Tarbell
And what you're on. You're on Illinois PD's brown map for. They. They got your data from MSG.
Hector Monsegur
It's a special. It's a special map. That's crazy. I went to MSG game and they got me. Freaking profile. Come on, man.
Chris Tarbell
That's brown guy entering. Brown guy entering.
Hector Monsegur
Oh, man.
Chris Tarbell
All right, brother. Fun show.
Hector Monsegur
It's beautiful as always.
Chris Tarbell
All right. Love and respect. I'll talk to you next week. Cheers.
Hector Monsegur
Much love, brother. Cheer, Sam.
Episode: The Steam Malware That Stole Crypto From Thousands
Hosts: Chris Tarbell & Hector Monsegur
Date: July 23, 2026
This episode delves into several hot topics in cybersecurity, featuring a deep dive on the Steam malware ring that stole cryptocurrency, a major WordPress vulnerability chain, data breaches connected to biometric surveillance at Madison Square Garden, headline AI voice fraud schemes, further revelations on insider trading at the White House, and more. The co-hosts mix serious technical breakdowns with irreverent banter, personal anecdotes, and their usual skeptical take on "sophisticated" cybercriminals.
True to form, Chris and Hector keep the conversation accessible, technical, and laced with insider sarcasm and NYC humor. Listeners get actionable takeaways (patch WordPress, beware voice scams, don’t do insider trades) amidst candid admissions and personal war stories—cultivating both respect for cyber defenders and wariness of tech’s misuse.
Summary prepared for those seeking the full tech, legal, and cultural context of the episode—without the need to decode the banter or sit through off-topic asides.