Loading summary
A
You know, if you're a hacker, you're reading this stuff and you are circumventing this somehow. You thought you're protected through VPNs, you thought you were protected through using busy boxes or whatever, but now you've got this number that's associated with your machine.
B
Sure.
A
Good luck.
B
Hector Monseager was responsible for some of the most notorious hacks ever committed. Special Agent Chris Tarbell and FBI informants
A
participated in some of the world's most infamous hacks.
B
Had caused up to $50 million in damages.
A
A life in the shadows.
B
Cyber attacks on the rise.
A
Welcome to Hacker and the Fed, everybody. I'm Chris Tribel, former FBI special agent, worked my entire career in cyber security. And I'm joined on episode 140 by my buddy, my podcast co host, that beautiful man, Hector Monserghor.
B
Hola.
A
Hector's a former black hat hacker who once faced 125 years in prison for his many years of hacking under the codename Sabu. But then our stories collided in June of 2011 when I arrested him, but then convinced him to work with me at the FBI. Hector's now a Red Teamer, researcher, cybersecurity expert, and co founder of say, Phil.
B
Hey, Heck. Hey, what's going on, brother man? How are you, man?
A
Try to make that different every single time.
B
Yeah, you know, I try to try to make it different and, you know, keep it fresh, you know what I mean?
A
No, I like that. I like your new, fresh feelings.
B
I like to be the fresh.
A
What do you do when you're not fresh down there?
B
Oh, no, man, I can't. I feel so uncomfortable. I have to hop on the shower. It's always a whole process.
A
It is, it's a terrible, terrible process.
B
But man, especially, especially right now with this, this weather, man. It's weather all across the globe, man. It's, you know, I feel like people are showering more, which is great.
A
You know, I mean, this is the greatest time of. To live when we have. We, you know, if you are privileged enough to have warm showers. It wasn't that long ago that people did not have warm showers.
B
This is true.
A
So. But yeah, there is nothing worse than. Well, there's, there's a lot of stuff. World hunger, war. But man, swamp ass is right there with it.
B
Oh, yeah. Swamp ass is one of those things that, you know, you don't even wish in your worst enemies, you know what I mean? It's, it's, it's a terrible plight to deal with, you know? You know, where I Noticed a lot of people get it because you smell it bad when you're traveling on a plane.
A
Oh, yeah.
B
And people are sitting there for six hours straight. And then as soon as they all start getting up to rush out of the plane, you start smelling that, you get that whiff.
A
Well, I mean, if you're on a six hour flight, it's nothing but recycled farts in there because everybody, the pressure change is pushing farts out of people and then the air is just recycling through.
B
Oh, yeah.
A
It's disgusting.
B
Yeah. That's how we're going to start a cyber security podcast today.
A
Yeah, that's right.
B
That's right.
A
We're taught we're humans. This is what we all, we all have these things. If you think you do something weird, guess what? Everybody else does weird things too. So don't be embarrassed about being a person.
B
You know, you should write a children's book on that, honestly, you know what I mean? Like, hey, everybody sharks. No, it happens.
A
I mean, I'd eventually get to the fear boner. Everyone gets a fear boner.
B
Yeah.
A
No, I'll tell you the exact opposite. You know, I think in my experience of when you surprise somebody and you arrest them, it gets the opposite. Things shrink up.
B
Oh, yeah, no, it's. I, I, I could, I could, I could, I could attest to that.
A
That is not your finest moment.
B
No.
A
So we've talked about swamp ass, we've talked about recycled farts and fear boners now, and we're three minutes in.
B
Would be a hell of an episode today.
A
We're shot out of a cannon today, by the way.
B
Shout out to Dingbat. Ding, ding. It's the homie down in the Oz. Always sends us emails, always respond back. This time was late, but I wrote back this morning, I was like, oh, man, I'm sorry for the delay. You know, thinking about you, brother. Keep it safe.
A
Is he doing all right?
B
Yeah, he's good, he's good. He was. You know, there was a story you and I covered a while back about the department of something or another in China where they had a breach of the time service. Remember that?
A
Oh, yeah, yeah. We just changed it to the clock just slightly.
B
Yeah, A little skew enough. Enough of a skew to throw off all the cryptography and all the mathematics involved, right? And so he sent us an email saying, hey, by the way, you know, we had a little back and forth from the Chinese military or government, rather. And guess what? Coincidentally, maybe ironically, somebody hacked into one of our timekeeping services and try to change things around, so. Wow. Well, be careful. You know, Australia's gonna be a big target for sure. So, you know, got to keep up on that.
A
Shout out to Dingbat for keeping up with the stories and updating us with what's going on around the world.
B
Oh, yeah. Big shout out.
A
Big shout out. You got a big week ahead of you. Are you excited about this week?
B
I got a big week of, you know, just going out there and talking to folks and networking, connecting.
A
Is this for Safe Hill or what's this for?
B
Yeah, for Safe Hill. I'm just trying to get safe out there. Big shout out to our listeners. You know, we've had some listeners reach out and they run businesses, they get pen tests. So, you know, we got some conversations going. Big shout out to them for sure.
A
But yeah, you know, we could always use more, right? We could use our listeners telling their friends in the industry, hey, guys, send some business over Safe Hill way. Tell them you're a hacker and fed listener. I bet Mike guys will give you a, give you a little discount for being hacker and fed listener.
B
Oh, yeah, no, we're, we're giving out discounts to our, all of our people. You know, if folks reach out and they have reached out and we, you know, we hook them up, we give them access to our platform, plus all the pen tests and stuff, it's actually pretty cool. You know, we've added a lot of cool things and, and I think whoever's using our platforms be pretty happy, especially now in 2026, where there is going to be a lot of, well, I would say over the next year there's going to be changes with regards to, like, you know, healthcare industry, specifically healthcare industry, where there's some changes in the works that are gonna require certain things like an external and internal penetration test. That's one. Then of course, you know, auditing of cloud and identity services or configurations. So, yeah, we've been doing a lot of that stuff for our healthcare clients and it's been, it's been fun. It's been, you know, just a lot of conversations to be had because there's a lot of confusion whenever you have policy coming into play, you have people like, whoa, what's going to happen now? I'll give you, I'll give you a good one. I'll give you a good one for the audience here. So there are a lot of you that are, you know, you may own a business, you may have a website, but there is legislation out of, out of California, out of New York, out of Illinois that require Some sort of tracking consent. Right. Because if you're doing any sort of search engine optimization, you start adding trackers and pixel trackers. Well, if you're not properly disclosing your privacy and terms policies on your website, if you're not giving a chance for people to opt in and opt out of those cookies or track tracking pixels, they're ending up in lawsuits. Companies are being sued by these law firms that are literally just getting, like, you know, very cursory. Web scanners that are connect to websites all across different industries, identify which of those websites are not compliant to these states, and then sue them from within those states. It's a thing. It's a money grab. Yeah. So we've been helping organizations kind of deal with that, too. That's kind of a big one right now.
A
It's a money grab. By who?
B
By the law firms are taking advantage of the fact that some of these states is. Is not national. Right.
A
Yeah.
B
Like, you're not gonna get sued by a law firm in Georgia, but you might get sued by a law firm arm in California because you forgot to set a cookie preference prompt or something or another.
A
Yeah, that's nuts. So we had a funny conversation on the Patreon today. We talked about China and Russia teaming up to go against Starlink satellites. Talk about AI tokenization. What else? We talk about
B
everything else in between, bro. We just kind of went off on a tangent on other things.
A
Oh, yeah? Like what?
B
Oh, well, say that for the Patreon. Go check it out.
A
Yeah, we got a little risque in the Patreon today, so maybe that's why we opened up with the farts and fear boners and all that.
B
Well, the one thing I'll tell you guys about Chris is that once he's tired of, like, cyber discussions, he goes straight into, like, the boner part of the conversation. You know, it's. It's fun. You could track it in real time. As it happens, you can track. When Chris is just bored of AI and China, he's like, hey, Hector, so would you blow an ancient alien to save the Earth? And, like, whoa. Yeah, why not?
A
I believe if you listen to the conversation, that was you asking the question and me answering it.
B
Yeah.
A
But I will agree with you that once in a while, I will get fed up with talking about the same cyber shit over and over and over. You know, that's why we try to find new stories every week.
B
So.
A
But also, guys, that's why we're talking about the Patreon. Keep the show going. Help us out with the Patreon, help us out with the merch. Hacker in the fed.com get you your fugazi gear. We had a listener reach out to us and they getting a fugazi gator done. I. I don't really know what the connection with the gator is but you know, say love me. It's, it's getting done. So help us out. Hacker in the Fed.com got some new stuff going up there, so take a look at it when you can. You ready to jump in the show, brother?
B
Let's do it then. Let's make it happen.
A
All right. The FBI seizes Net Nut. Net. What the hell is that? Oh, it's a proxy platform and also the, the Popa botnet. So the FBI, the irs, Google Threat Intelligence, Lumen and shadow servers sees hundreds of domains tied to the Netnut residential proxy service on July 2nd. So Netnut operated on publicly traded Israeli firm with the infrastructure overlapping with the Popa botnet that comprise of at least 2 million customer devices which include smart TVs and streaming boxes to serve an unauthorized proxy. Exit nodes, the devices enrolled via the malware SDK without owner consent and the proxies used for mass scraping, advertising fraud, account takeovers and and password spraying by threat actors. No arrest or indictments yet, but a lot of fucking seizures on this one.
B
Yeah. So we covered a story similar to this, not a takedown, but we discussed kind of like a researchers kind of like deep dive into one of these
A
kind of networks where the Samsung devices. The Samsung television devices.
B
Exactly. It was like a TV app that you could download. They had like 2 million similar numbers.
A
I don't think it's. You could download. I think it came preloaded on your. I think you had to actually go in and turn it off when you, when you bought the device.
B
That's right. That's right. Yeah. Well these guys, they want a different route. You know what's crazy about this? These guys were like leveraging like hacks devices. But they're publicly traded on nasdaq. What the hell?
A
Yeah, I don't really understand that. You know, there's some questions going on with that thing. Yeah, yeah, well, they, they've put out a statement saying they're cooperating with an investigation investigators. But I mean they had to know what's going on with 2 million devices. They didn't know what was going on.
B
The only thing I could imagine is that they had some sort of affiliate program where they would allow a third party to bring in devices and then to get paid Per device. And this is where that popup botnet comes into play. But he had a botnet operator saying, hey, I could make some money if I could just, you know, add. Add my bots to, you know, this, this scraper network. And so by the way, just. Just for a content context. Sorry. These residential proxy networks allow an adversary, an operator, whatever, an advertiser to automate the, you know, the. The proxying of traffic from like home IP addresses. The reason why these operators do that is because a lot of like anti bot systems automatically block cloud service provider IP ranges. So this would allow you to kind of circumvent those blocks, giving you an unfair advantage in whatever. Right. Buying sneakers or something. But if you have a botnet involved in this, they could also do the distributed and all of service attacks, which is probably why the FBI really wanted to take this stuff down. I mean, you took down a similar network with networks in your. In your time as an FBI agent. Um, I think the difference though is that when you took those down, they were like obviously very illegal. They weren't connected to a publicly traded company. Like maybe. I don't know.
A
No, no they weren't. And I named mine Operation Backdoor Sinkhole just to see if I could.
B
No way. He did.
A
Yeah. Yeah, that's an FBI case called Operation Backdoor Sinkhole.
B
Oh, I love that. That's great. Thank you.
A
Thank you very much. I was very. I was very proud of that one.
B
Yeah.
A
Y.
B
And nobody gave me any looks like none of the bosses were like.
A
Nope. Approved.
B
Yeah. Well.
A
But I will tell you that I bet if it got to the point of where that would have made the news, probably been an issue, then I would. I've been. I would at least been reamed out.
B
Sure. Yeah. Yeah. But I've been reading before. It's okay.
A
Yeah, yeah. It's like that ending scene of Inglourious Basterds.
B
Exactly. Yeah, that's what I was thinking about. Yeah.
A
I've been reamed out before. I can be okay.
B
Yeah.
A
And I'm really surprised that the name Net Nut was not scooped up by the porn industry.
B
I know. I mean, I would think that's like an old ex hamsters competitor, you know what I mean? Would.
A
I definitely would have thought Net Nut was grabbed in the early in the late 90s.
B
Well, back then you had a. You had a back door. We're talking about a lot of back stuff today. But back then it was a backdoor called Net Bus, you know, to pretty close, but no Net Nut. You're right. I mean that's. They listen, they have some great. I think they're in the wrong industry. Honestly.
A
If you ever get a chance to check out Bang Bus episode number five with Renee, I highly recommend it.
B
Okay.
A
Highly, highly recommend it.
B
Well, I might check out after this.
A
Renee R E N E E. Okay, do you want to pause the show and go check it out?
B
No, no, no. I could multitask, dude.
A
Oh, okay.
B
Miss it.
A
So, yeah, so shout out to Google for disabling a bunch of this stuff and helping out with taking out some of this infrastructure. Guys, be careful when you are plug and play your take home devices, this is what happens. These companies are using your ip, your bandwidth to screw everybody else out.
B
I mean, it is true.
A
Did you find Renee?
B
Yeah, I did. It's the blonde one.
A
Yeah, but she's got this little accent. Oh my goodness.
B
Well, let's get off a net nut and you know, listen, here's what I'll tell you guys. There's a reason why the FBI, the NSA and other agencies have told you guys, hey, you should probably reboot your devices, you should probably reset them or update them, you know, once so and so, you know, periodically because it would help eliminate some of this stuff, some of these intrusions that, you know, that may not, you know, maintain persistence, pass a reboot. Right. And that's what we're seeing here.
A
We need to hold these companies liable. I mean these companies that are doing this shit knowingly, I mean, that's bullshit. They don't know what's going on.
B
Well, think about it like this. You have the FBI, you have, you know, GTIG from Google, you have all these companies involved against a publicly traded company. They've taken down servers, they're taking down domains. I'm surprised the FTC is not involved or the SEC is involved in this as well. I think that's the thing, that's this, that's catching my attention the most. These guys are like, they're a legitimate company. You're cooperating. What does that mean? Does that mean you're going to stop, you know, infecting devices and selling access to bad actors? Like I don't understand what that means.
A
Yeah, but even like all these, a lot of these stuff, these smart TVs and smart boxes, they're coming pre installed. So the company's selling these things.
B
Sure.
A
Like don't have these pre installed apps on your devices or do your due diligence and understand what the. You're bloating on your customers.
B
That's right. That's right.
A
You know, or an under.
B
Stop, stop.
A
All the damn small print about allowing these things to be on the things we're paying thousands of dollars to, and then we're plugging it in. We're trusting these companies and then they're stealing our bandwidth. It's, it's, It's a crock of.
B
Yeah, I think, I think that's. That is so right. It is. It is a thing. Theft of services. I mean, you're not offering a service when, you know, you're connecting a smart device to your home network. Right? But it's theft of something. Step to resources. I mean, you know, if I'm paying, you know, a hundred dollars a month for Internet access and I bought a TV and I paid 1500 for it, why am I allowing in the recordings? I accepted the terms and conditions that, you know, has a fine print that says, hey, we might use your, you know, data for, you know, I don't know, whatever advertisement purposes. Like, why is that even a thing? Like, why can't I just buy my thing? And if I want to opt into something, I could, but not make it defaults. That's the problem. Screw that.
A
I'm going to list a product to you, and if you think this is a viable idea, we'll take it out of the show.
B
Okay.
A
All right. Is there a way of using like, the SafeHill platform or something like that to run your outbound traffic for, let's say, a day, a week and have it analyze and spit out a simple report of what is leaving your home network? Not, not your work network, just your outbound home network. Like, hey, you know, you're having a bunch of communications with Facebook. Hey, you're doing this, like, this thing here is an anomaly. What the fuck is going on with it?
B
Yeah, yeah, no, that's totally doable, right? Because, you know, it depends. Depends on the router that you have, right? If you have a router that comes from your ISP, let's say, you know, I don't know, AT&T or something, they might give you a router that's like really closed. It may not even offer logs. Then you would have to figure out a way to reverse engineer that router. It's not going to be universal.
A
You can't just use some sort of like, wireshark on your. On your router and record the logs.
B
No. Unless you get terminal access to the router itself and you're able to run things. This is why a lot of folks go with like, open wrt that Open router projects because it allows you to do that. You could do TCP dumps, you could do wiresharks with all that. Take the traffic logs and analyze it, just like you said. I think it's a great, great point, but for like consumer in home ISP supply networking. No, that's going to be a, this could be a whole big thing, you know, now for corporations. See, you brought up a really good point because you and I have covered literally hundreds of ransomware attacks against organizations, right? During, during the whole 140 episodes. How many times have you heard me say, dude, you guys probably purchase ndrs. You probably have a Fortinet or Apollo Auto or Cato Networks or Cisco Device. Why were you guys monitoring outbound or egress traffic? Right? It's never the fucking case. We're never hearing that someone says, hey, you know what? We're able to catch a ransomware because it just so happens our network engineering team discovered an ongoing egress, a dump of files over the wire. Never hear that. So imagine consumers at home doing that. It would have to be automated.
A
Yeah, it'd be cumbersome. But I, I don't know, it just, it would, it would be nice to have like an AI generated report that very summarizes what's going on in your home network. But maybe, maybe most people just don't really give a. I would think there's hacker and the Fed listeners listening, but again, it's sort of a niche audience.
B
Yeah. You know, well, here's what I'll say. I'll say that you gave some good ideas and I hope that people are now listening and like now they're thinking of ways to deal with their routers, maybe even replace the routers. Because if you, if you do, it's always an investment. That's the crappy part. If you do invest and replace your, your ISP router with a personal one, then you might have finer control. Might be able to get logs and then analyze it. I'll build a tool for that. You know, I'll build a tool to analyze those logs. I'll bet you catch a lot of stuff and then you can set rules to block that traffic moving forward. Yeah.
A
Or figure out where it's coming from. Like, oh, I have this app that came on my fucking television that's allowing people to run shit through it.
B
Yeah, yeah, yeah.
A
All right. HackerOne's invisible army. How an unauthenticated query exposed over 188 defense program triage. So an unauthorized HackerOne API endpoint leaked complete internal triage roster without authentication or rate timing. Approximately 188 accounts enumerated, including 131 active triage analysts with PII which include real names, usernames, system derived nationalities, home cities, bios, access levels they exposed by non US nationals to sensitive vulnerable data from the US DoD. Lockheed Martin, Northrop Grumman and other programs also revealed bounty payments to Russian researchers including $300 from GSA programs. Summarize what happened in this one.
B
Heck yeah, this is a good one. So you have a researcher on X or Twitter, goes by the name of Y. Soo and you know, by the way, I love the profile because in there he has references to AntiSec and Project Mayhem. You know, yeah, antisec guy. So what he ended up doing was he did some research into HackerOne and I'm actually going scrolling through screen now to see if there's any updates on this story because this should have been a big one to me. I don't think there were many news stories kind of covering it. But what he ended up doing was identifying an API request. He was able to pull a bunch of information from that API request from hacker1. And he found some interesting things. For example, there's a bunch of like Department of Defense, several different military organizations within Hacker One. Now the problem with, with using a third party for something like this, where you're, you know, triaging vulnerabilities for the DoD for example, or lock Lockheed Martin, which is a federal contractor, there's certain guidelines that you probably should be following, meaning that the people looking at these vulnerabilities probably needs to be American. And that's not what he found. He found that there were a lot of the triage managers and triage personnel that were coming from India and Russia. None of them were Chinese that I saw. But there were non US nationals that were kind of taking a look at interacting with and getting information on potential DoD vulnerabilities to Acro1 as a platform. And, and that right there was a major expose. Another thing he found that I found interesting is that there were a lot of dummy accounts. You know, a potential indicator that these accounts may be back doors or front doors to Hacker One accounts that, you know, there was no titles, no names associated with them, but in some cases they had privileged access. Again, this is all from like a API dump over, over like, you know, JSON or JSON dump over API. So there's a lot of assumptions that could be made from this data. Maybe it's relevant, maybe it's not. But I found this story interesting because of the implications. Okay.
A
Yeah, I'll say. It's, you know, outside of Twitter, it's not really out there. You know, the mainstream cyber security news hasn't picked up on it.
B
Sure. Oh, yeah. Well, and, and so let's be honest with it, right? Be honest with what that looks like. You know, what you have is. And by the way, the vector wasn't, was not only over API, it was over GraphQL, which if any of you guys have ever dealt with GraphQL as a developer or as a security researcher, you would know that, you know, a lot of these developers have a terrible, you know, they do a terrible job at kind of securing it or, you know, access controls, dealing with access controls, dealing with authentication authorization, et cetera. And so, you know, the, the real issue here is, aside from Hacker1 having a wide open GraphQL endpoint that allowed for this enumeration, is HackerOne so big and so interconnected in the cybersecurity industry that a story like this is a non story because of the potential implications that there could be integrity issues? We don't know. I'm not going to make the assumption. You're not going to make the assumption, but I found it weird that nobody else really talked about it. This guy provided the data and nobody refused it or refuted either. Right. There was no, hey, this is guy's bs. Hey, this thing is fake. In fact, if you look at the Twitter feed and you look at the threads, there are people in there like, wow, that's pretty crazy. Or hey, you know, screw Hacker one, you know what I mean? It's like. But hackerone didn't release a statement saying, oh no, this is fugazi. Because this guy doesn't know what he's talking about. Yeah, it was an API endpoint. It leaked some stuff. We shouldn't have leaked it. We apologize. We didn't even get that.
A
We will see. We'll see if cybersecurity news kind of picks up on this and where they go with it. But yeah, it's pretty silent so far.
B
Yeah.
A
So a little update on a story we did last week. So new court filings revealed how Microsoft helped the FBI identified Peter Stokes or Bouquet, the Scattered Spiders member that was arrested. So Microsoft assisted the FBI providing data from a Windows Global device Identifier, GD ID GD ui I thought G U D I. I don't know.
B
Yeah, it's G did G D I
A
D. All right, to link the 19 year old dual US Estonian citizen Peter Stokes to scatter spiders cyber activities, including in the May 25th Tiffany Co. Hack involving Ngrok account and creating the data exfiltration. Stoke was arrested in Finland in April and extracted the U.S. the court documents detailed how the persisted Gdid tied his VPN obscured activities to his personal social media accounts and device histories despite using a vpn. So it was sort of a way of having this Microsoft identifier number kind of circumvent VPN logs.
B
Yeah, I mean, here's what it did, right? Generated a, an identifier for the device, the device being the guy's laptop computer, whatever. And then as he kind of moved around the Internet using Bing as a browser, which is crazy or whatever. Right. You know, then, you know, it tied his activity with those g did so gd IDs or not plural. And yeah, I mean, Microsoft was able to kind of leverage that. Since then we've seen evidence that Linux is also doing that with a machine identifier in slash etc slash machine dash id. Probably a Mac OS as well. We got to check that out. But you know, hey, going back to what you said earlier, you brought up a good point. You're buying a device, you're, you're paying the licensing fees. You're, you're, you, you, you know, you're using your money to, to purchase these things. And then you have the manufacturer, you have the developer of the operating system running on that thing tracking your Internet activity. Probably for advertising purposes, but then at least it's something like this. And I'm not so sure I'm keen on that, brother. Man, I'm.
A
Dude, it's everything. It's your phone tracking everywhere you go, everything you say, whatever you do, that, that shit can be used against you. It's your car. Your car tracks everywhere you go, who you connect to. And again, that's all things that can be used against you. Yeah, but how do you get away from it? You're not going to have a phone. You're going to have a car that's only got a carburetor. Guess what? You know, I have a car that's only got a carburetor. You know how hard it is to find somebody to work on a carburetor anymore?
B
Yeah, that's right. That's right. Because these, these, these young guys, young mechanics, don't they have no idea?
A
No, it's all fuel injection and now batteries.
B
Yeah, well, it's, it's a tough spot for privacy. We could both agree this guy was an asshole. Right? Okay, that's one thing, but just because the guy is an asshole doesn't mean that the rest of us have to be tracked on everything that we do. It doesn't mean that we're have anything to hide. There's nothing to hide. But if I'm going to pay for a fifteen hundred dollar laptop, I'm going to pay one hundred dollars a month for Internet service. I'm going to, you know, be making all these investments in software and licensing. It should be mine. It's my thing. If I want to be tracked, let me opt into it. But that's not how things work, obviously.
A
I'm really surprised the way, I mean they must have really wanted this guy to put this information out there. I would have thought the FBI would. Yeah, it's surprising to me that they didn't. I mean I, apparently it looks like they needed to include it in his extradition paperwork. So I guess, I'm going to guess the. Where was he arrested? Finland. I'm going to guess Finland. Courts weren't going to release him unless they told exactly how they found him. So, you know, if you're a hacker, you're reading this stuff and you are circumventing this somehow. You thought you're protected through VPNs, you thought you were protected through using busy boxes or whatever, but now you've got this, this number that's associated with your machine. Good luck. What would your response be as a hacker if you read this and now you are using, you know, a Lennox box or using window boxes like, like what, what's your response? How do you, you douching everything out or how, how you, how are you protecting yourself?
B
So as an adversary, what I would do is I would stay away from Windows. I, I, I've said I haven't used Windows legit, like used it at least in 15, 16 years, maybe even longer. I moved, I moved to Unix or Linux, you know, in the late 90s, early 2000s.
A
So was your reason because of this or just your hatred of Microsoft?
B
Hatred of Microsoft, but also because I, you know, I always heard the jokes from like the older hackers, you know, Microsoft, sorry, Windows is a virus. Windows is a backdoor. It's, this is not new. It's been like this for a long, long time. People have been making those comments, right? So, and plus it was cool to be a hacker running Linux or running Unix back then. I was a NetBSD guy first. You know, I started with NetBSD Unix, I started hacking to Solaris, but then I went to Linux and It was easier, you know, it was able to, you know, be installed on more laptops. Right. But as the adversary, what I'm doing is I'm going to Linux, staying on Linux, but then I'm identifying that Linux has something similar with machine id. So I would rotate that machine ID constantly and then I would probably not use Chrome because Chrome uses the machine ID on Linux just like it does on Windows. And then, you know, we'll probably have to use like a beat down or stripped down version of a browser, maybe like a, like a privacy centric Firefox version, you know, that Tor uses, like a Firefox stripped down Firefox, do something similar. And then that, that would eliminate this threat up to a degree. Then everything else is operational security, you know, how using VPNs, how you connect it to the Internet, you know. But this is, this will be part of like your methodology for Windows users. All of you guys are tracked. This, this, this is what, what Chris was alluding to. He's surprised that the FBI kind of let this out because what this story tells everyone, all of you, is that all of you are being tracked, all of your activities being tracked. And Microsoft could connect you to your Internet activity through these GD IDs. That's what the FBI told him.
A
If this guy didn't have to be extradited, he would have been charged through a grand jury and then it would just have been so and so was indicted by this grand jury on this date for these charges and that's it. None of this stuff would have come out and now made it come out in trial. If he had a decent lawyer and all that, he may have exposed it, but exposing it, what's that going to do? What does that get the guy?
B
That's not going to do nothing. It should become a martyr. They might piss off somebody and you know, the judge gets a phone call, hey, you know, you should, you should max him out. What's the max on this? Well, he got, you know, X amount of charges, it's a two year minimum. But he's got 40 years in max charges. Max amount like we did with Alberto Gonzalez. Give him the 40 years. Yeah, yeah.
A
Interesting, interesting that, you know, scattered spiders. Let's see what comes out from, from this guy, from that. But yeah, I mean, people need to realize that you're being tracked for everything by everything electronic. If it makes your life easier, it tracks you.
B
Yeah, I mean, look, you step outside right now and you hop on a highway, you hop on anywhere, you know, you got these flock Cameras every day, everywhere. Tracking your face, tracking your license plate, tracking your car. You know, you and I talked about the. The Blade Runners not that long ago, maybe last month. Right now there's a massive movement here in the US of people, you know, basically bringing blade running back to the United States. And there's been a lot of attacks, takedowns of Flock cameras all over the country. Because people want to have privacy. They want to be able to drive down the street without being tracked. You know, it's. It's like a little fringe movement. But I tell you man, people are getting tired of this.
A
Another follow up story, Hector the Florida ransomware negotiator convicted for helping ransomware gains exchange US companies. So Angelo Martino is a Florida based ransomware negotiator for a US cyber security firm. Was convicted and sentenced to more than five years in prison for conspiring with hackers to deploy Black Cat, which was part of Alpha ransomware against the US companies in 2023 and facilitate extortion. He worked with co conspirator Kevin Martin and Ryan Goldberg. One incident involved extorting approximately $1.2 million from a victim company which the proceeds laundered and split three ways and then used the funds to purchase access including a food truck and luxury fishing boat. A luxury fishing boat. Can you imagine?
B
This is ridiculous.
A
The US government seized more than $10 million in cryptocurrency and other assets tied to the scheme. The co conspirators of Martin and Goldberg were previously incarcerated for their roles in the same scheme. No additional arrested indictments. So five years this guy worked as the negotiator. So he was on the inside with these guys.
B
He was an insider threat. He's the guy. Get this. I want to give you guys a picture. Let me visualize this for you. So let's say your organ organization is compromised. Unfortunately. You get hit with a ransomware and now you're panicking. Now your business is not producing. You guys are negative. And then you have this random asshole reach out to you and say, hey, I'm going to help you guys negotiate this ransomware. Hire me and my, my buddies. We're going to work with you. We have a legitimate security company we're going to work with to kind of get your files back and save you some money. That's what we're good at. We're good at reducing extortion payments like 80%. I got your back. You hire this guy in his team to whatever company that they had. I forgot what company they had. And what You. What you don't realize is that you're negotiating against yourself. The guy is part of the scheme. He's part of the grift. He's getting paid on whatever you're paying. And he's. He's an absolute traitor of the highest source. Five years. Five years is a lot of time. But for, you know, the damage that he and his ilk have done to the cybersecurity industry in general with stunts like this, I'm surprised he ain't getting maxed out. I'm surprised he's not getting 10 plus because of what he did. And violating the trust of his customers like that is. That is as low as you can get. And not only that, I've talked with you all the time about when we're doing events, and I look at the orders, like each and every one of you, you guys all play a part of the national security of the United States of America. It's true. Every single breach leads to an economic impact that affects, guess what, you and I, Chris and the listeners right now, we have to pay higher insurance premiums. Now we have to, you know, pay for this, that and the other. Cool. Identity monitoring and management, all that nonsense. Cool. No problem. This guy was part of that. These guys were part of that. And, you know, I don't like it. I don't like it at all.
A
Just greed. I mean, they, they, they crossed over from legitimate ransomware negotiation role, which I think is a little bit of to begin with. But then they said, well, we can start deploying our own stuff and then we can play both sides of it. And so.
B
Yeah, and you know what?
A
It just blurs the lines. The. And. And again, like you said, it gave a black eye to cyber security.
B
Yeah, no, for sure, man. And, and one thing I'll tell you is at this point, if you're dealing with a breach like that, an instant like that, just go to the FBI, bro. Go, go to your contacts, you know, execute your ir. You know, your instant response playbook, by the way, which reminds me, another big story. I'm not sure I think I said it to you. There was another big story about SISA having to deal with a conflict recently, sort of breach. They didn't have a incident response playbook. They had to develop one during recovery.
A
Yeah, yeah, you should borrow somebody else's for that one at least.
B
So for all of you here listening, you're hanging out with us today, right? Having a great conversation, learn from these mistakes. That's the whole point of this. This your takeaway. I'll give you. I'll. I'll cheat for you. I'll give you the takeaway. I'm your large language model right now. I'm actually pretty large. I'll be that guy. I'll be your chatgpt right now. Here's what you're gonna do. You hear this story. God forbid you get hit with a ransomware before you get hit with the ransomware. Be left of boom. And make sure that you invest time and effort and resources into resilience. What is resilience? Having offline backups, Having the capability to recover from a ransomware. Who cares if the files elites. Those files already are in the hands of the adversary. It doesn't matter anymore. You know what matters? Getting back online. Getting back to work. Right? That's number one. Number two, God forbid you get hit by something like this, this incident. You get extorted. Go to the FBI, okay? Go to somebody that's going to give you a reality check and tell you, hey, you're fucked anyway, so you don't have to pay the ransom. Screw the ransom. And three, I'll give you another takeaway. Have an incident response playbook today. Start building one today. Go to chat. GPT. Go to Claude. You know what? Shoot me an email. I'll send you a template. And what's your IR playbook going to be? It's going to start off very simple, right? My name is. Here is the policy. 4. Here is the date of the last time we updated this policy in the event of an emergency. Break glass. Who's your glass? You're going to contact your network engineer. You're going to contact your so and so third party provider. You're going to contact the FBI. You don't have an FBI guy's name. Do what Chris says. Chris says, reach out to your local field office, the local office, FBI office in your town, your city, your county. Make a relationship with them. They're going to give you somebody a point of contact. Get his number, get his email. In the event of something like this, hit him up with a phone call. Hey, Special Agent. So. So, I'm sorry to, you know, burn your time right now, interrupt, but I have an incident. We got hacked. There's like $20 million at stake. Can we get some help? These are things that you guys should be doing now prior to an event. There you go.
A
That's excellent. Heck. Hey, can I just bring up if anybody knows. Her name is Peyton. Renee is her real name. If anybody knows her and whether she is part of the hacker in the Fed network. That'd be fantastic. Ask her to reach out to us at Questions at Hacker in the bed.com.
B
yo, you're funny. But you know, you know she's gotta be like in her 50s now, right?
A
Okay, so I'm 48 years old.
B
Okay, I got you. I respect it. I respect.
A
Sometimes she's also credited as Stephanie Renee. So anybody, anybody knows her, please have her reach out to her hacker in the Fed. We're big fans. Big fans.
B
And that's how you know that Chris has reached the, the apex of cyber stories when he immediately shifts away from that and goes into.
A
Yeah, we got three more stories.
B
So come on, let's go.
A
But seriously, guys, Peyton Renee or Stephanie Renee, if you know her, have her reach out.
B
Yeah, she can come on the show.
A
She can pitch anything she wants. Be fantastic.
B
Yeah.
A
All right. So a vengeful researcher, Nightmare Eclipse gets Microsoft's attentions, quote, never justifiable and has real world, real world consequences. So an anonymous researcher calling himself Nightmare Eclipse publicly disclosed multiple working proof of concept exploits for Windows Zero Day vulnerabilities starting in early 2026 and targeting components like Microsoft Defender, BitLocker Cloud Files Driver vulnerabilities enabled local privilege escalation TO system and BitLocker encryption bypass. Some have been actively exploited in the real world intrusions. And Microsoft has publicly responded with a blog post criticizing uncoordinated disclosures as creating unnecessary risk to customers and threatening legal action against actors and enablers. Oh, so Microsoft is now bumping heads because we're revealing their dirty little secrets.
B
That's the worst thing they could have done. You know, listen, you. We could argue all day about the ethics or morality of, of, of this researcher. We could say, hey, this guy's a jerk for dropping zero days. Or you could say he's a hero. Nightmare Eclipse for. Or they're a hero, right? Because you don't know they're anything about them. You know, they're a hero for exposing the potential, quote, unquote, underscore, emboldened potential back door or front door in bitlocker. You know, the fact that you could circumvent encryption on BitLocker with like, you know, a simple repository that this guy, this person dumped is bizarre. It sounds like a back door to me. I'm not saying it, I'm not implying it, I'm not even alleging it, but it feels like it. You know, this is what, you know, back in the days in the 90s and 2000s was referred to as full disclosure. What full disclosure Is is hey, you identify an issue, you either have reached out to the vendor and or you say you know what, screw the vendor. I'm going to expose this issue and I'm going to force that vendor to fix this issue. Now why did full disclosure work back in the days? Chris, you remember why it works?
A
No, why?
B
Because it did exactly what the intended goal was which is to force vendors to do something about these issues. Remember this conflict between Microsoft and, and this researcher started with them providing Microsoft with vulnerability reports and then Microsoft completely just disregarding them. You're saying hey this vulnerability is a won't fix or this vulnerability is low priority fix. The reality is this researcher doesn't have to do that. They don't have to follow the rules. It's not illegal. There's no crime being broken to do security research. It's not a thing. Right. There's no. Now if you use the research to hack it to Microsoft is a different conversation. Right? That's, that's a violation of all sorts of different rules and cross state this and unauthorized access that but security research is not that. It doesn't fall into any of it. So it's legal to security research. What this person was doing was hey, Microsoft doesn't want to fix this. So here you go, you guys figure it out. Now there's a flip side to this which is there are security companies that do binary patching, right? Like zero patch. It's a good example. I think there's a couple others zero patch. And those companies rely on these kind of reports, believe it or not to patch Windows for you before Microsoft gets off their ass to do it. All right, and so what does that mean in the grand scheme of things? It means that Microsoft is walking into Streisand, Streisand effect territory by threatening a researcher. The last time a major corporation threatened a research you saw what happened when they, when they threatened Geo Hot Sony. You remember that?
A
Yeah, I think there's been a few threats since then but yeah, sure that's the, that was a big one.
B
That was the big one. Right. And Sony got hacked 11 times in 30 days. You know shout out to that and, and so you know Microsoft is heading that direction. This researcher is one is the tip of the iceberg. There are dozens of people just like him ready to rebuild or restart that anti sec movement. So throw that out there.
A
Well heck I just, I mean she was also in teen hitchhikers 11 she was young cheerleaders swap and swallow 4. Yeah she was in service animals 2118 and interracial 18. Big, big opportunity in natural knockers 5. Again, anybody knows her, have her reach out to us. It'd just be, it'd be fantastic.
B
Yeah, I mean, National Knockers 5 sounds like I had to love the series, bro.
A
It sounds like the rest of my evening.
B
Yeah, yeah, yeah. It reminds me, there was a, there was a, a film series that I loved as a kid. Best of the best. Remember that movie?
A
No.
B
Oh my God, it was such a great movie. It's about fighting movie, you know, it was like a kung fu series of taekwondo or something or another. Anyways, the first one was great. The second one was decent and then it just kept going. There was like six movies in the, in the entire series and they just got worse and worse. I'm hoping The National Knockers 5, you know, didn't follow suit. I hope it's a good one. It's not a, it didn't degrade, I guess.
A
Do you think I'll have to watch Natural Knockers 1 through 4 to get the gist of it or can I just jump in at five?
B
No, no, I think you're gonna have to watch one to four because that'll prepare you for what you're about to see in.
A
God, I'm gonna be up all night.
B
Yeah, man. I mean, look, it happens, bro. I mean it is a worthy investment.
A
Yeah. Oh, I, I, I should have hydrated better. Oh, there's so many problems. All right, do you want to do the more stories? Are we done with this? Are we done talking about cyber?
B
We could do one more. There's one more.
A
All right, your choice. One and two phones sold in Africa. Exfiltrate telemetry to China.
B
Or.
A
Or the Japanese Police arrested a 15 year old over a ChatGPT assisted cyber attack. Which one do you want to do?
B
Let's do the Japanese one. I think that was.
A
All right. All right, well, don't buy phones in Africa if you don't want the Chinese to know where you're at.
B
Don't buy phones in Africa. Don't even buy a laptop over there. You know what? Just stay away from technology.
A
No, if you were, you know, we used to do, we used to leave shit over there. Good luck going through this. So a 15 year old high school student from Japan was arrested in June 2026 on suspicion. Suspicion of fraudulently obstruction of business. That's not a charge in the U.S. i'll tell you that. For laundering. For launching a cyber security attack against Bandani. Bandani Channel. I don't know what that is in November 25th. The student analyzed network traffic to identify a vulnerability and then use Chat GPT to generate code for a program that automated unauthorized access to member accounts, resulting in the cancellation of over 46,000 subscriptions. The service was offline from November 6 through to December 19, potentially exposed of data for up to 1.4 million members, which include their emails, nicknames, payment methods, but no passwords or for credit call details. So the Japanese got this kid for using Chat ggp Chat GT PT to hacking Hector. Did I mention that she was also in Roadhead and Teen Hitchhikers? I mean, Roadhead was an oral focus scene, but, you know, she was also played a cheerleader in White Cheerleaders, Black Dicks four.
B
Listen, listen, bro. Listen.
A
Yes, we are off the rails at episode 140.
B
No, 140 is out of control. I can't imagine 150 what that's going to look like. Shout out to her. She's wonderful. Shout out to Ms. Renee. She sounds like a wonderful lady. But what you're seeing here with the story out of Japan and by the way, the. The Bandai servers are like anime streaming servers. So what this kid did was analyze his traffic, probably through like a proxy, and then had ChatGPT kind of help him identify a potential API issue. API issues are all the rage, by the way. We covered the HackerOne store, which had an API or GraphQL issue. And so he was able to leverage that to essentially, potentially dump a bunch of user information. Emails, names, addresses, addresses. But he also found the API endpoint to cancel accounts. So he trolled close to 50,000 Japanese anime watchers by canceling their accounts. Automated, you know, in an automated fashion, which. That right there is like. That's an anti. Second of a different way. It's anti entertainment or some shit. You know, he's like, no, you guys. You guys are not gonna watch anime. I'm gonna prove the point. I think the bigger concern is chatgpt. Cat sent the request out for you. He probably sent the requests maybe from his home ip, maybe he used Tor, who knows? But the fact that ChatGPT is referenced here means that the Japanese government were able to track the attack or link the attack because of ChatGPT, which again, is another indicator that those transcripts are not yours. You're paying for ChatGPT, but they're monitoring what you're doing with your sessions. You know, have some understanding that you're using someone else's computer, someone else's service to compute these answers for you. Hence the Story.
A
Well, heck, it looks like she's still alive. Apparently she just retired in 2010 and stopped doing films after that. So she's still out there again, guys.
B
Look at that.
A
Please have Stephanie or Peyton, whatever she goes by, reach out to us@hackerinthefed.com let her know that she can get merchandise@hackerinthefed.Com we'll give her a free Fugazi T shirt. She can support us by joining Hacker in the fen on the patreon. She can get pen tested by Safille at any time she wants. I'm sure safely will pen test whatever she wants. Pen tested. Ask her to give us a five star review wherever she download and subscribes podcasts. Have her share us on social media. Be like Ms. Renee and share us on our social media. Tell your co workers, tell your friends, tell your former porn actresses about Hacker and the Fed. We just need Ms. Stephanie Renee to come on the show.
B
All right, so your Stephanie Renee was my Pinky back in the day.
A
Remember Pinky the singer?
B
No, no, Pinky's not the singer, bro. She was another actress like your friend Ms. Renee. Yeah, Pinky, she was awesome for me.
A
Common spelling.
B
Yeah. P I N K Y. She was built like a. Like a horse. You know what I mean?
A
Was she an actual horse? Is that the sort of film you were into?
B
Yeah, she was a horse.
A
Oh, wow. She wasn't she something?
B
Oh, she's. She's. She's built.
A
She certainly is.
B
Oh, yeah.
A
Oh, all right. Well, that's fantastic. Maybe we'll have Ms. Renee and Pinky on in the same show.
B
Maybe the co host, you know, have a nice, like, co session and, you know, have some great discussions.
A
It'd be fantastic, my friend. An extra thick show. I enjoyed the show. I enjoyed talking with you. I enjoyed. We started off with recycled farts and we ended up on our favorite porn actresses. What? A cybersecurity podcast we're putting together here for the audience.
B
That's right. Thank you, thank you, thank you.
A
Just a little bit more than cyber has some cyber, but we put a little extra into it.
B
That's right.
A
That's why we're so highly rated.
B
Yeah. No, we got some good ratings. Big shout out to the listeners, man. It always shows love. I'm happy with that.
A
Yeah, it's good. All right, friendo. I love you. I'm gonna be busy with Natural Knockers 5, so I will catch you on the flip side.
B
All right. Cheers, my friend.
A
Cheers. Love and respect.
B
More slowly.
Date: July 16, 2026
Hosts: Chris Tarbell (A), Hector Monsegur (B)
This episode covers the evolving landscape of cyber threats, highlighting several headline incidents, including Japan's first known arrest of a hacker using ChatGPT to develop a cyberattack. Chris and Hector break down notable stories in the cybersecurity space, reflecting on trends in digital identification, vulnerabilities in widely-used platforms, and lessons for organizations and individuals. The tone throughout is candid and humorous, balanced with in-depth, practical cybersecurity expertise.
On Corporate Responsibility and Preinstalled Malware:
On Security by Default:
On the Reality of Internet Tracking:
On the Futility of Ransom Negotiators Gone Rogue:
On Vendor Reluctance and Full Disclosure:
On ChatGPT in Hacking:
The hosts maintain a casual, humorous, and at times irreverent style, moving from serious technical insights to playful banter, personal anecdotes, and adult-themed asides. The blend of seasoned law enforcement and former blackhat perspectives delivers hard-won lessons with an unfiltered edge.
The show signs off as it begins: with humor and camaraderie. Chris and Hector remind listeners that cybersecurity is both deadly serious and absurdly human — and that resilience, vigilance, and, yes, laughter, are the best shields against the onslaught of digital threats.
For further discussion, episode Q&A, or to connect with the hosts, visit hackerinthefed.com or join their Patreon.