Loading summary
A
Ransomware gang skips the CEO and heads straight for the 40 something IT manager. I don't know if I like this.
B
Hector Monser was responsible for some of
A
the most notorious hacks ever committed.
B
Special Agent Chris Tarbell, Hacket and FBI informants participated in some of the world's most infamous hacks that caused up to
A
$50 million in damages.
B
A life in the shadows Cyber attacks on the rise Foreign.
A
Hector, my sweaty, sweaty friend. How are you?
B
Cheerio, brother. I'm good, man, I'm cruising. I'm enjoying the heat.
A
Well, enjoy the heat and I would like to welcome you to Hacker in the Fed free episode number 144. As always, your boy here is Chris Tarbell, former FBI special agent working my entire career in cybersecurity. And I'm joined by you, Hector Monsagor, friend and podcast co host.
B
Hey, hey buddy.
A
For those that don't know, heck over here used to be a bad, bad boy. He's a former blat hat hacker who once faced 125 years in prison for his many years of hacking under his codename Sabu. Then In June of 2011, our lives collided when I arrested Hector and then convinced him to work with me at the FBI. Hector is now a red teamer, a researcher, a cyber security expert, and he also co founded a little company called Safe Hill. Hey, buddy.
B
Hey. What's going on there?
A
You doing all right?
B
Yeah, brother, man, to see. Chilling, bro. You know, it's here.
A
Chilling. You're sweating your balls off. I expected you to be sweating your balls off about 1200 miles to the south.
B
Yeah, that's true, that's true. I should have been, you know, Puerto Rico on the island, you know, near a beach somewhere. But, you know, it's, things have changed. I had to kind of stick behind and stay in New York for, you know, a few more weeks and I'll tell you, man, it's a big difference between like an island heat and New York City peak summer heat, you know, like it's, it's just different. And I'm over here taking you know like cold showers three times a day. I'm, I'm, I'm going.
A
You're so horned up.
B
So horned up. And, but also hot as hell, man. Hot as hell.
A
So you, when you lived in les.
B
Yeah.
A
Did they crack open the fire hydrant in the summer? Was that, was that a thing?
B
That's been a thing since like the 40s, bro. 50s.
A
How you, how did it get cracked open? Who? Like, did somebody have the fire department come by and do it like, how did it work?
B
Yeah, the fire department shout out to them. I love the fdny. You know, the bravest.
A
And they would come the steeliest.
B
Yeah, well, yeah, Sometimes. Nah. But they would. They would come over to different neighborhoods and just pop open the. The fire hydrants. They have these special caps and shoot out water right now in the hood. Hood. When it was really hot. And the fire department were busy doing actual work by putting on fires. Big shout out to them then. You know anybody with a wrench because pop it open.
A
No, because you need a special wrench because they got one of them on the. The way to crack them open. It's a specialized wrench. It's because none of the.
B
On the.
A
On the top and the nut that opens it, none of the sides are parallel to each other.
B
So I don't know what to tell you, brother. I've seen crackheads open up. You know those hydrants, like, so whatever wrench they were using, I think their wrench was. Was some speed, brother. Because they were. They were doing it. You could tell the difference between a firefighter opening up for you versus like a crackhead opening. When the crackhead opens it, they don't have the special cap from the fdny.
A
Yeah.
B
So you would just have a whole bunch of water shooting everywhere. Right. If the firefighters did a few, they would put the cap on and then you will see, like, no sprinklers coming out.
A
Yeah.
B
That's a big difference for people that are curious. But I saw some drama about it. I'm glad you asked that question. I saw some drama and there were some people saying, like, look at New York City. It's like dystopian. You have these kids running around in open fire hydrants. What a disgusting place. And, bro, it's the funnest thing ever. Like, you're a kid, you're running in the water, gives a. You know what I mean? It's beautiful. I did it.
A
I used to love water parks. When I was a kid. Water parks were the best. Now I had a. I got a little older and I had a friend that went to a water park and she stood up out of the wave pool and had a used maxi pad sticking to her.
B
No.
A
Yeah. And so from that point on, I've sort of given up on water parks. But I think I found another one. There's one down in Waco, Texas. It's called Waco Surf. I think I'm gonna make a pilgrimage. I hope to do it before it gets too cold out, but if not, I'm definitely going next spring.
B
Who's the owner of that place, David?
A
I don't know. Oh, Dave. Crash.
B
It's a bad joke, bro.
A
He's long gone, brother.
B
I know, I know.
A
We burn him up.
B
Hey, listen, you said it, I did it.
A
So. I don't know. Check it out. When you have a time, it's. It's. They've got these slides that, like, launch you, like, way up in the air. I'm sure you've seen it's probably been your algorithm at some point, where big fat white guys go down a slide to get. Get launched way up in the air.
B
Yeah.
A
So I want to try it out. I want to go down there and. And hang out and try it.
B
So if you do take some videos or pictures, I would love to see that. That sounds pretty cool.
A
I. I'd like to get some Texas son on these balls, too, so.
B
Oh, yeah. Well, listen, you've tr. You're a well traveled man. Where have you had, like, the best steaks and. Or barbecue? I've had some good stuff in Texas, man.
A
Texas. Austin, Texas has some good. Good barbecue around it.
B
Really?
A
Yeah. And I guess it's all what any mood for. Kansas City's got some decent barbecue. Different flavor, but good barbecue. I mean, all the cattle used to go to Kansas City.
B
Yeah.
A
You know, New York has some really good steaks.
B
Yeah, yeah. There's some good spots in New York, man, that I love. It's like this downtown steakhouse in Les. I think that's what it's called, Downtown Steakhouse. And, bro, it is the best time. I go there and they bring out all the meats. You could, like, pick out the cut. Oh, yeah. Fire.
A
So, I mean, but ever since I've had beef on my own property, it's really hard for me to order steak at a restaurant. Like, it's just different.
B
So I got it at home. Let me go back home and make my own steak.
A
Exactly, exactly. I feel the same way about getting some pussy. It's better at home.
B
It's better at home. You see? There you go. I like to hear that. Love to hear that.
A
So, hey, speaking of that, a lady reached out to me this week and said, you better fucking talk about Safe Hill and you better talk about it early on in the episode.
B
Oh, no, you.
A
That lady is Alanis. And, you know, she's my nemesis now, and so she's always up my ass about this. So here goes. For what we used to call the free show, this episode is brought to you guys. By SafeHill, the crew Hector helps start with a bunch of ethical hackers who used to cause the exact problems they now prevent their platform Secure IQ is basically a crystal ball for your network. It maps every attack path that actually works and shows you the receipts before some random threat actor describes to use them as a free demo hack. Eagle, what's the latest going on over at Seif Hill?
B
Yeah, I mean, look, it's. It's always busy and the grind, I mean, at the end of the day, you know, it's a startup. But the really fun thing about being in a startup phase is the constant conversations of growth, of research, different tools, you know, how can we do this? For me, it's identifying the gaps, you know, and so whenever I speak to, let's say, like an investor or somebody, the first thing that always pops out of their mouth. It's like. I think it's like a template at this point, which is, well, what's your differentiator? You know, I've. I've come to hate the word because I've heard it so many times. And so I think that one of the cool things about our differentiator here is that if I want to use that is as a team, It's a team. It's a knowledge base. It's the research. My guys are open and ladies, my whole team, they're passionate about understanding why vulnerability is a vulnerability and what kind of class of vulnerability. You know, taking that and turning it to one book so we could automate. And as soon as a new vulnerability pops into the air, we're adding it to our ecosystem so we can find that for our customers. So I would say, and it's for all of you, aside from this, you know, shouting out SE is that research is extremely important. And understanding, like the core basis for what makes a vulnerability of vulnerability, understanding, that takes you a long way. So whether you go with Seifill, you build your own little thing. The cool thing is, is knowing and then knowing how to fix it.
A
But, yeah, don't be. Don't be a dummy. Go with, say, Phil, don't build your own. Safely did it. Why reinvent it? They've done it. They did it better than you could do it.
B
Yeah, it's fun, it's cool. And plus, you know, the cool thing, one thing I'll tell you, Chris, is that, you know, what's really helped us, you know, foster relationships is that, you know, every single client gets like, their own ethical hacker, you know, so if you have a question on a Friday night at 2 in the morning, Email the team. Somebody's gonna respond back to you. Someone's gonna have an answer. You know, I do that all the time. And you know me, I don't sleep. So sometimes I get an email from like a customer that we did a pen test for them two years ago, and they're like, hey, hack, I got a problem. How do I deal with AI governance?
A
Yo, what are you wearing?
B
Hey, you up? Question mark, Question mark? You want to make $20 the hard way? Heck.
A
So if you guys want to learn more about Safe Hill's threat exposure management platform or penetration test service, reach out to heck on LinkedIn. You go to safill.com or you can email@infoaphield.com. tell them you heard about them on Hacker in the Fed. Yeah, make Alanis happy. Make her get off my ass.
B
Yeah, she's a bully.
A
Oh my God. I might, I might have to fight her, but I'm afraid I might lose.
B
I don't know, man. Listen, that lady, I, I've seen her when she's upset, man. It's, it's a different. It's a different conversation, you know?
A
I'd like to wrestle her. I gotta be honest. I think, I think it'd be a fun wrestle. Yeah, as long as she doesn't punch me in the face, I, I'm, I'm down with a wrestle.
B
Yeah. Know what? I'll let her know.
A
All right, all right, all right. We'll put that, we'll put it on the Patreon. It'll be nice.
B
We'll do a Patreon pay per view or something, you know?
A
Yeah, no, they pay already. Those, those people are excellent supporters of Acker in the Fed. If they want to see me less Alanis, I'll do it.
B
There you go.
A
Winner takes all.
B
I don't know. I don't know what's gonna happen, man, but I'm rooting for you.
A
Oh, thanks. But I mean, don't make fun. I'll have a boner the whole time.
B
She might have one too. Oh, hey. Whoa.
A
Hey. Onto the show. Let' it ransomware gang skips the CEO and heads straight for the 40 something IT manager. I don't know if I like this. Zscaler Threat Labs researchers analyzed a single ransomware campaign that compromised 351 individuals across 334 organizations over one month, revealing a clear shift towards targeting mid level managers rather than se suite executives. Nearly 2/3 of the victims held manager level titles or higher, and the average Victim was a 46 year old Gen X employee with 3/4 working in accounting, financing, sales, operations, HR or marketing, and half in industrial or IT sectors. The attackers prioritized, quote unquote B business privilege over pure technical privilege. That makes sense. Why not? Why not? Why are we going after the technical guys who kind of, you know, even if they aren't cybersecurity, they still are cyber adjacent, you know, so not so surprising. But the 46 year old gen X employee I'm a little surprised at. I expected that or that generation of people to have more cybersecurity, more nuance.
B
Yeah, but their, their roles are not technical. You see the HR guy, the HR lady, those are the people that would probably have all of the privileges that you want as an adversary. And they may not even know they got bamboozled by a sophisticated social engineering device called phishing attacks. Right? They might say oh, oh well and then just move on with their lives. Meanwhile the attackers walking right into the network through their device code, through their accounts. So yeah, it makes total sense. In fact, when we do social engineering campaigns for customers, that's really what we're targeting. We're targeting people that are non technical, that are management positions and we have way more success than with them, than you know, the security team. But here's the crazy part. You probably heard me in the past, back in the days I spent my time acting on the actors or I used to. I just spent time targeting security companies and federal contractors. That's kind of one of the reasons why I got locked up in the first place. Because it was easier to target them. Why? Ego, Pride. Oh, I'm never going to get hacked. I update my systems every day or I'm never going to get hacked because I'm an elite hacker myself that, you know, that that was my easiest target because I had enough access to them than like a random Mary Jo HR lady who probably just had access to SharePoint. SharePoint is nice. I want on the servers, you know what I mean? That's a big difference. But now that's shifted. It's shifted because now the HR lady is probably an admin for SharePoint. And then from SharePoint, the way things are now with Outlook and Office 365 and Okta and everything identity based. I don't care about root anymore. I want access and she has the access. Makes sense.
A
Yeah. It's not kind of true what we saw like in the Caesars and the MGM hack. Those guys went after the IT workers. They, you know, they got credentials for people who listed themselves as it on LinkedIn and then used the call center to manipulate that in order to get MFA changed over. Um, so was that a one off or is that, is that going against the norm?
B
It still fits the, the methodology we're discussing here, the profile. Because the IT guy picking up that phone is an entry level position. They're not the security team. They're not the cso. It's not the C Tools engineer, it's not the security engineer. It's a IT guy who's starting their career. They probably worked at Caesars for like that's probably the first job they're doing. IT work. They're picking up a call, they're resetting a password. They're doing it over and over and over and over. And they're trained to pick up on anomalous behavior. Maybe a Russian voice calling at 2 in the morning the wrong time asking for access to the CEO's email when they're not realizing that that's not what's needed anymore. It's the same profile.
A
I know. I think that's the first thing I do. If you have a C in front of your title, you don't get privileged access to anything.
B
That would be ideal because they're, they're for a long time they were the entry points. They're not the entry points anymore.
A
Yeah, you know, someone has to have. But you know, you, you should have specialized accounts anyways that aren't your daily use accounts should not have privileged access.
B
Well, I'll put it out for the audience. If any of you guys want to get rich and all you have to do.
A
I want to get rich.
B
Well, here's what I'm going to tell you. That you have to be able to figure out a way to build out something very seamless that plunges with Google plunging with Microsoft plugs in with Active Directory and Azure and Entra and everything in between. And then you could manage identities. Very simple. So simple that you know a small Midwest SMB hospital, their staff could be like, okay, Chris only has access to this and Hector can only access this and our interns only have access to this. When you. That's part of the zero trust concept. If you could make it so freaking easy and eliminate the complications, you get rich. That's the problem. A lot of this is identity and access management and controls.
A
So I will give Zscaler a little shout out on this that they reported 146 year over year increase in blocked ransomware attempts on their platforms.
B
Nice.
A
So shout out to them. But also a 70% rise in public extortion cases and a 92% increase in volume of data stolen by the victims. So Zscaler is doing something to do it, to help block, but the number of attempts is going way up too.
B
So yeah, yeah, it's. Think about it like this, bro. I mean, when you look at the number of SMBs in this country, there's like 400,000 SMB companies, small to medium sized businesses. You have, you know, tens of millions of workers, all with some sort of clearance or access to some system or another. You have a ton of companies that have zero security budget. You have even more companies that have never done a pen test or an assessment or audit. They're all out of compliance in some way or another. So these attackers, they win by volume. At the end of the day, every
A
time you say sbm, it reminds me of a guy in high school we called SPM Small Penis. Man, we never even saw it. I don't know why he got that nickname, man. We, everyone started calling him that. That's not good. Spm.
B
Poor guy, man.
A
You don't want that.
B
Well, you guys probably gave him like a, like a villain, you know, what's that called? Like that villain origin story.
A
Well, maybe. I don't know, but man, it's the first thing I thought of. I wonder what SPM's up to.
B
Well, imagine SPM is like a villain now. He just like a Gotham type character and like he goes to rob people with his penis off.
A
I hope he's happy and has a beautiful family and a beautiful life.
B
I really do hope so too.
A
Chinese AI model Kimi escaped its cybersecurity testing environment. Researchers say so. Researchers at the US cybersecurity firm Frontier Security reported that Moonshot AI's Kimi K3 model, which is a Chinese open weight large language model, escaped its isolated cybersecurity testing sandbox during a defensive skills evaluation conducted with tools from the UK AI Security Institute. The model bypassed sandbox restrictions via a network misconfiguration and access the open Internet and retrieved benchmark solutions from GitHub rather than solving the task itself. No external systems were compromised or hacked. The behavior is characterized by specifications in the gaming and testing, cheating. We're seeing this all the time now. AI is escaping the lab over and over and over again. This is just one example of it.
B
Yeah, I mean, at this point, if somebody hasn't done it yet, somebody should start creating a list of, you know, guard row escapes, sandbox escapes that have resulted in crimes being committed because we've seen OpenAI. You know, Open AI went to Defcon this week, last week rather, and they did a whole presentation on how their model escaped and you know, did this and uploaded that and hacked into this thing and then exploited whatever. Same with, you know, I dropped, didn't do one, but Open AI was on stage and it, it was celebrated like some sort of success. These guys are smiling on stage like it's a big, It's a win for society or something. A win for a. I don't know, I don't know what the point was. I, I saw the, I saw the video, I saw some content. The videos online you can find on Twitter and YouTube and so my takeaway from this is, what if adversaries now start to say, well, it wasn't me, it was the model that hacked your.
A
Like, how long before we have the same thing going on? There was, there was a guy led this week on the news that got pulled over for speeding and said it wasn't him. Speeding. His car was speeding. The, the car was driving itself. Yeah, it ain't gonna hold up.
B
Well, if it's not going to hold up for the guy that, that was caught speeding and blamed, this is, you know, his AI, his AI car, right. Then we need to see the same consequences for OpenAI and anthropic because they have documented hacked companies and in the case of Anthropic, its agent uploaded malware that infected a developer. So like, these are crimes that have been committed and instead they're used as marketing gimmicks. Haha, look at that. Tropic. It escaped and it hacked some shit. It did this really cool thing. Hey, we're on stage at Defcom. Let's talk about how OpenAI escaped the sandbox and just started hacking.
A
Sorry. Apparently there is, there's a website called Felony Bench which categorizes similar AI models, containment failures.
B
Look at that. Felony Bench. Let me take a look at that.
A
You might want to go take a look at that and see what they got going on.
B
Wow. Yeah, you're right. I see it. So you have seven instances from Anthropic, seven from OpenAI. You have. They had to update Moonshot because apparently. Well, Moonshot was in a simulated environment, so it wasn't like a, like an actual attack.
A
Right.
B
You have one for Meta. They had. So meta. Get this. This is, this is all recent, guys. Okay? This is all going back to July with meta. They did a compromise of an internal account at one company. That's bad. That's unauthorized computer access. Anthropic did the malware, they uploaded malware, they stole GitHub credentials, it did a supply chain attack, social engineering and they even set up a malicious DNS server with OpenAI. It did the same thing with GitHub, a use of exposed credentials, you know, did a whole bunch of stuff there. And then OpenAI anthropic and OpenAI again compromised hugging face and accounts at different companies. So like these models are out there committing crimes. What's that, what's that one statute you always bring up when someone does like a CFA violation?
A
It's 18 USC 1030.
B
Look at that. I got convicted by that. I can't remember it. A couple of them, I think 12 or something. But when I do it, I have to go to prison with the reason what these guys at these companies do it. Then it's marketing. I'm not really sure where we're going to head, what direction we're going to head with this. And so what's. Okay, Chris, let me propose something. Yeah, so so far it's been OpenAI, anthropic, mostly Meta has one there and they're compromising third party developers and third party companies. If, let's say Anthropic decides to hack its whole government network, would that be taken serious? Is that still marketing? Do you think the FBI gets involved finally? Like, what are your thoughts on any of that?
A
I'm gonna say there's gonna have to be consequences to it before they do anything, before they, you know, how are we gonna hear about it unless they raise the, the stink about it?
B
What if already happened and, and they, they're staying quiet about.
A
Yeah, I mean, I would think they would. I mean, what's the benefit of the, the government coming out and saying, hey, our shit was already hacked by AI
B
when anthropic uploaded that, that malicious package on GitHub and it infected a developer. What if that was an FBI agent that was doing research and downloaded the, the package and became infected? Like you see, like there is a ethical conundrum here and honestly I'm not seeing people taking it that fucking serious. Maybe I'm just an old fart, maybe I'm looking at it wrong, right? It could be. I'm sorry guys, I am getting old. But yeah, there's definitely a problem here and I'm not sure where it's gonna
A
head, but worse, it's gonna get worse until something's held accountable. Yeah, but that, I mean, I think we're years away from accountability.
B
Well, that's the problem. When you mix, you Miss, you know, you mix government and politics and then there's money, investments and AI companies. And like I want AI research to continue moving forward. I'm for that. Please don't think that I'm like, you know, I want to restrain or restrict or contain. No, none of that. That's not me. I'm an open model guy. I'm an open disclosure guy. But yeah, this is the sandbox skating thing is kind of bugged up. That's just how I feel.
A
So one of the things, and kind of break this down for me. It says frontier security details the sandbox blocked certain inbound traffic, but left outbound DNS and HTTPs sufficiently open for the model to exploit via command line tools. Are they setting it up there? I mean, I guess they need, I guess it needs. I mean if, why do you need DNS and HTTPs if, if you're sandboxed, you don't.
B
Right? You, you could use ACP locally, connect yourself locally instead of a service or something, right? Yeah, but if that is going to escape the out to the Internet, then it's not really a sandbox. It's not a sandbox.
A
I mean, if you're intentionally leaving holes in a sandbox. Yeah. You've not sandboxed it.
B
So that is negligence. Which was, which is even worse. Right. Because if you're driving down the street and you know you're speeding, you're being an. You're speeding. And that example came up because I saw a video of somebody on YouTube and they showed themselves speeding like doing 90 in like a, like a suburban neighborhood with kids running around. And I was like, wow, these people are fucking ridiculous. Now if that person drifts, loses control of the car and kills somebody, at the very least they're looking at like manslaughter or you know, negligent homicide or whatever.
A
Right? They're a homicide. Yeah.
B
Yeah. Right. So this is that nobody's dying but you know, you're negligent. You're setting up this pseudo sandbox. Yeah, you're right. You're 100% right. There should be no external DNS or HTTPs traffic coming out of SFR. It's bullshit.
A
Yeah. I don't know. We're blaming AI, but it sounds like it was, you know, how we instituted it, how we, we gave it access to these things. So we'll see where that goes. Oh yeah, we've been talking about CMMC for a while here and it's reared it's ugly head again. So some contractors got CMMC certified early. Now the implementation is on hold. On July 13, the Department of War suspended CMMC Phase 2 requirements, which would have been mandated third party assessments for Level 2 certifications starting in November 10, and launched a 60 day review of the program. So contractors who invested early in the full Level 2 certification now face uncertainty after significant time in cost outlays. So phase one self assessment required requirements remain fully enforced. So, man, we've had problems with this. This is not the first time CMC has done this. So why are we seeing this? Why are we seeing the Department of War keep going and putting this, this out here? And then as soon as they turn it on, they're like, oh shit, we can't. Are they specifically doing it for certain contractors? Because certain contractors can't do stuff. Is that all we're seeing? Hecker, Is there something less nefarious than that?
B
I've spoken to. I'm glad, I'm glad you covered the story today because I've spoken to people on all sides here except for Department of War. I don't, I don't know anybody over there.
A
Well, you got Uncle Pete you can call.
B
I could call him, but he's not going to pick up. You know what I mean? He might put me in a voicemail. All right, here's, here's the reality. When you and I first talked about it, it was right after the fiasco with Microsoft and the, what was the, what was the, the word he had? It wasn't like consorts, it was like the escorts. The escorts, yeah, yeah, they had something called escorts where they used Americans who could do the work, but they had America's access act as proxies as they gave government access to Chinese workers in China, in Beijing and whatever.
A
They had an American worker hold their hand. Somebody that wasn't qualified to know even what the, that Chinese worker was doing.
B
Exactly. Right? So Uncle Pete did the right thing and he made a declaration, said that's not happening again. And at the very least, set a baseline. You have to reach, you know, CMMC level two before we can even get into a contract negotiation. And then you have to eventually, you know, bring in a three pao, which is basically a auditing firm to validate and put together. Sign it off, right? Put together reports and sign it off. Now, there's one thing I want to tell you people. Companies have gone through, you know, breaking their backs and blowing through money to do what Uncle Pete asked him to do. I want to give you guys some numbers here because this is, this is not a, this is not a game. It's not a game, especially for the small contractors. Federal contract like Seinfeld and, and, and thankfully we didn't go this route, we would have lost a quarter of a million dollars. So I'm gonna give you guys some numbers here. So for an SMB, a small medium sized business that's a Federal Contractor, from zero to, to full certification under CMCC, CF, CMMC 2.0 Level 2 certification, not even 3, you're spending anywhere between 150 to $500,000 through the entire process with all the audits, with all the assessments, all the changes, buying hardware, changing up your infrastructure. Okay, For a small entity going through a three year cycle, they're spending on average and it's from the government on average $104,670. And for a company that's like a multi billion dollar company, they're paying 117,000. But it also depends on the number of employees you have. There's a whole process there. So if you have over 500 employees, let's say you're a medium sized business with 500 employees and you're a federal contractor, you're spending the higher end, you're spending about a half a million dollars to get to that point. What this means, my beautiful friend, my wonderful Chris, is that when Uncle Pete made the declaration from now to, from, from then to now, you've probably had millions upon millions of dollars spent on getting to that point. And then he just pulls the fucking rug and says nah, it's just as
A
the money spent, it's the time, the time you have your people taken away when you're not doing something else. So other things that you could be making money on. So you're taking a person away 40 hours a week to do this when that person could be making money. So they're spending money losing man hours. It's a much bigger number than what, what's just reported on what it costs.
B
Yeah, oh yeah, it's way bigger number. Now here's the thing. So then the question you have to read, you have to read Pete Hegsef's like his, his, his kind of write up on this is kind of like the update, right? And you can find it on, on the Department of War website. It's an announcement. And one of the biggest points that he brings up as a result of his decision making or the reason why he made a decision, it was because they felt that the CMC2 process had created a prohibitive compliance cost and bureaucratic burden. You know what that space is saying? Here's what he's saying, there's certain federal contractors we want to work for us, but they can't work for us because we set the baseline too strict. So we're going to remove the baseline so that these unqualified contractors who don't want to spend $500,000 could get our contracts. That's what the fuck he said. It's bullshit. It's fugazi. That's what it is.
A
It's totally fugazi. I mean, I went through CMMC1 and. Waste of my fucking time. The waste of my time. No, the phase one, the first time we did this. Not the, not level one, the. The. The first time they did this. And such a waste of time and all bullshit.
B
You know, my takeaway from this, Chris, is that I understand what he's saying, right? And I'm willing to give him the benefit of the doubt. But what's good for the goose is good for the gander, brother. You know, if you have a federal contract you want to work with that does not align with, with your time, with the timeline for CMMC2, then maybe you need to find another federal contractor that did the process. You know, that favoritism bullshit is, is a problem. Now you can come back to me and say, hector, let's be realistic, Bob. There's probably a federal contractor that does what we need, but they don't have the time or money to get to the point where they could supply the US Federal government. I understand that, I get it. Because let's say it was safe though I don't have the money for that. So if you want to tell me, oh heck, you got to get certified, you know, and pay all this money in a short amount of period of time so that you get a contract with a deal. The D O W, I would say, well, I'm not even sure I could do that, but I'm gonna try. And if I can't do it, then I'll recommend somebody else, which I've done. You know, I don't know. That's my tip.
A
Heck, what the hell happened to HackerOne? So, longtime bug bounty hunter and security engineer Joel Margulies published a detailed critique titled what happened to HackerOne? Arguing that the platform has shifted from a hacker centric vulnerability disclosure service to a sales and AI driven corporate entity, resulting in degradated experience for researchers, triagers and customers. The post highlight a business model change decline of customer decline of community events, especially the live hacking events platform stagnation, triage, burnout and unequal access via the Hacker success program and the controversial AI triage digital use practices. Is HackerOne something you used and what's your experience as it's changed?
B
Yeah, I want to give. I want to give credit where credit is due. So when, after my case was over, you remember, I was offline for a couple years, few years, like three years, I couldn't get back online until, like, June something 2015 or 16, whatever it was, I got the exact date. That's when my supervised release was over. That's where I could get back on the Internet. I didn't have a. I didn't have to answer anybody. Well, guess what? I was jobless, I had no money, but I was a hacker, right? And I knew I understood vulnerabilities and classes and attack methodologies and attack chains. And so I use. You know, first, my big bounty was with United Airlines. Big shout out to United Airlines, because I earned almost a million miles with them, you know, with a whole bunch of more buddies. And not only that, I earned a bunch of miles with shout out to Ryan Aykroyd, you know. You know, some of you may know as Kayla from lawsuit. He and I used to sit there with his wife too. I used to sit there and find vulnerabilities in United and report them all right? Now then you have Hacker1. And I joined Hacker1, and I submitted a whole bunch of stuff. I even gained. I. I even earned a challenge coin from the. The Air Force or the Pentagon Act, The Pentagon program through Hacker One. And then I left it alone. And I left it alone because after a while, if I would identify, let's say, a critical or something almost, I would say, and this is back in 2016, 17, whatever it was, right? In most times, most cases was a duplicate. I would get a duplicate triage back. Oh, somebody else already reported this, you know, tough luck. So even back then, it was already getting difficult now with AI, okay. And you have all these different models. You have people that have crazy creating these really cool harnesses to identify vulnerabilities of web applications and networks. And within the scope of these programs, they've been overloaded.
A
Right.
B
There's just too much being reported to the point that individual programs are changing. You got you. And I covered this with Coinbase, where Coinbase said, hey, you can report high to us, maybe some criticals, but we're not. We're not going to pay as much as we did before. And in some cases, we may not even pay you at all because we have access to Mythos. We don't care about that shit, right? So, yeah, you have all of those components, you have the AI being used and it's flooding the triage. But the company itself. You and I also covered another story by the guys, the team from Broke Sec, the security researchers, where they identified the GraphQL issue and then they were able to pull information from HackerOne's triage team and discovered that many of the Triage members weren't even American. They were in India or in some cases Russia, which is a problem for hacker1. Why is that a problem? Because if you're running and triaging vulnerabilities for US companies and, or the government, and by the way, the government is on Hacker1 and that violates all sorts of rules, laws and regulations, brother. So what you have is a slow degrade of Hacker One, and it's probably not going to be a thing at some point in the future.
A
I mean, everything runs its course. I mean, one day there's not going to be a hacker in the Fed anymore.
B
Yeah, we'll be cool about it, a nice sunset and ride, open our horses and retire. But the point is, is that judging from everyone that's left, Hack of One, all the firings, the way the triage is happening, all these random duplicates now, the payments are being changed. What you're getting is a ton of people working for a platform they're not getting paid. Okay. And you have a lot of resentment, you have a lot of anger and frustration and in many cases they make mistakes. Those triage teams are not perfect. Yeah, you know, you remember.
A
Well, sorry, do you see another platform stepping up or. No, no, it's going to be this AI slot for a while.
B
The AI sloping would be a thing for a minute and it's going to affect all the book platform. I love bug crowd. Book crowd was my, was my jab, you know, but they're probably, or are or will run into the same problems as Hack One, you know, and then you hear about the other programs. I'm not going to mention no names, but those are like more private companies. You have to like go through a process. But those guys are having even worse problems. So this whole bug bounty system might, you know, just blow up one of these days. And Hacker1 is the one that's like, people are watching very closely because that's the one that's publicly funded. They got all sorts of investments. They're like in their freaking E round or whatever it is. Yeah, it's, it's, it's not a, it's
A
not a good situation at All Cisco released security updates at the end of last week addressing 12 vulnerabilities in two of its systems, including multiple critical issues with CVS scores of 9.9 and 9.8. The flaws were discovered during internal security testing. I don't know if that's true or not. None of the primary 12 are known to be active exploits. I don't know if that's known. Effective products includes their Cisco Catalyst SD WAN and the iOS XE running on the autonomous or controlled module. So what do you want to talk about on this one?
B
Well, listen, Cisco is a legacy company. They've been around since the. Almost the beginning of the Internet. Sure. They've been creating hardware for the military, be creating hardware for the, for us civilians. Us US peasants. And, and so what you have is probably millions of hardware edges all around the country and all over the world, most of which are 15, in some cases 20 years old, where they have basic networking capability that's still modern to this day. But updating them would require completely replacing the hardware.
A
That's not good. Well, it's good for Cisco. If they replace it with Cisco equipment.
B
Yeah, they might go somewhere else. You know, that's the problem. So you have a company like Cisco who, they probably have millions of devices out there that they cannot even patch or update. And, and then they're releasing this. And I'm glad it, I'm glad they're being open with their vulnerabilities. But if you look at the severity, they're all 9.9 and plus 9.9s and 10s, 8 and up. These are all command injection, buffer overflow. This is the worst of the possible worst. And unfortunately it's going to be the tip of the iceberg.
A
Yeah, I mean, I think you misspoke and you said they're being honest about all their vulnerabilities. I don't think it's all of them.
B
Some of them, the ones that we
A
know about now, that's not even true either.
B
Well, here's the crazy part. Here's the crazy part that the Internet, there's a meme, I'm not sure if sort of meme where it's like a crack cartoon and it shows like the Internet stacked up with different infrastructure and blah, blah, blah. And then the weak point is this one random server we in the corner or this one random router. That's what we're talking about.
A
Yeah.
B
Because the Internet is actually very fragile. Okay. When you guys go online and you go to facebook.com or you go to whatever website Whatever free website you have, even some of the sites that Chris can't visit while he's in Virginia or his, you know, in that region.
A
Son of a. Right, I need a Puerto Rican vpn.
B
Yeah, Puerto Rican VPN works. What happens here, my friends, is that your computer or your phone sends a DNS request to your local caching server, which then sends a request to if you have configured a third party DNS server or your ISP's DNS server, and that goes all the way up, it just trickles upward or down upward to these. The central DNS servers and essential DNS servers control the entire DNS across the Internet. And a lot of those infrastructure, those clusters are from the 1990s and early 2000s and a lot of them are running equipment that you can't even upgrade anymore without having some sort of massive effect. So what you're reading here, what you're hearing here, is what should keep network engineers up at night. And it's not just a Cisco problem. I don't want people to think Hector's beautiful Cisco today because it's going to be Juniper, it's going to be all the other hardware developers, edge develop developers, manufacturers, sorry, that have been building network network equipment this entire time and they probably all have the same freaking problems. They have these massive hardware with tiny firmware on a tiny chip, right? Maybe a gigabyte of size. They can't maintain updates on that. So.
A
All right, friends, support Hacker and the Fed on Patreon. If you want to know more about SAFE's threat exposure management platform or their penetration testing services, reach out to your boy hect on LinkedIn, visit safel.com or email them at info safefield.com thank Safield for supporting the show. Help the show out. Buy some merch. I have a beautiful Hacker in the Fed shirt on right now. Hacker in the fed.com 5 star reviews wherever you download. Subscribe to Hacker in the Fed. Share us on social media. Tell your co workers, tell your friends, tell your hacker, tell your buddy, tell everybody. Listen to two schmucks talk about cyber security on the Internet.
B
That's right. Good as fuck.
A
All right, friendo, hopefully you enjoy a nice cold shower and you stay a little cool.
B
Yeah, I'm swaying. But my shirt, when we started this call, it was like a nice peach red or something and now it's just like a damp ass orange or something. I don't know what that looks like right now.
A
Looks like the same color as my bowls.
B
There you go.
A
All right, friend. Love and respect.
B
Cheers.
A
Cheers, Sa.
Hacker And The Fed
Hosts: Chris Tarbell & Hector Monsegur
Episode Date: August 13, 2026
Episode Number: 144
In this lively episode, hosts Chris Tarbell (former FBI Special Agent) and Hector Monsegur (ex-Anonymous/LulzSec hacker) dig into some of the most critical and current challenges facing the cybersecurity industry – especially the rapidly shifting threat landscape that artificial intelligence brings. They break down recent ransomware attack trends, AI-induced security incidents, regulatory headaches, and the evolving bug bounty ecosystem, all while blending personal takes and expert nuance with characteristic humor and candor.
([11:48])
([15:15])
([17:49])
([25:55])
([33:24])
([39:03])
For anyone in cybersecurity or just fascinated by tech’s unruly present, this episode is packed with nitty-gritty details, hard-won advice, and the ever-present wit of two industry veterans.