Loading summary
A
So Canada now is going on the offensive against drug websites.
B
Well, let me ask you about that, if you don't mind.
A
Well, I famously took down a drug website, so let's get into it.
B
Hector Monseager was responsible for some of the most notorious hacks ever committed. Special Agent Chris Tarbell and FBI informants
A
participated in some of the world's most
B
infamous hacks that caused up to $50 million in damages.
A
A life in the shadows.
B
Cyber attacks on the rise.
A
Welcome to Hacker in the Fed. Free episode number 139. Can you imagine? Heck, 139.
B
We're getting old.
A
Sheesh. Very. I'm Chris Tarbo, former FBI special agent working my entire career in cyber security. And I'm joined, as always, by my buddy, my friend, my podcast co host, Hector Muskor. Give it up for Hector, everybody.
B
Yay.
A
Hector's a former black hacker who faced 125 years in prison for his many years of hacking under the code name Sabu. Our stories collide in June 2011 when I arrested him, but then I convinced him to work with me at the FBI. Hector's now a Red Teamer, researcher, cybersecurity expert, one hell of a guy, and co founder of Safe Hill. Hey, buddy.
B
Hey. Listen, I got to say, every time I hit an intro, I get more excited and I feel great. Life is beautiful.
A
Even. You have your cat cage on.
B
Yeah, I do have the cage on. I started no nut. November early. Guys, just a heads up. It's kind of where I'm at in life, you know, I'm pre showing, you know.
A
Well, I have to give the audience a little bit insight. I started drinking. We are celebrating July 5, the day after America's birthday. And so I decided I'm gonna have a beer during the show. So I am drink. I am drinking Bush light limes. Any sort of beer with citrus in it.
B
I'm all about interesting. I had no idea that was like a flavor profile that you appreciate.
A
Yeah, yeah. There's a beer called a Rattler. It comes out of Germany. It's a type of beer. It's a. It's a light beer mixed with grapefruit juice that I find delicious.
B
Well, listen, growing up over there in Les Louis side, baby, Alphabet City, East Village, what they call now, you know, the post gentrification.
A
Sure.
B
There was a place that I loved. It was a German bar and restaurant, but it was mostly a bar. They just made food there called Zum Schneider, RIP Rest in peace. Unfortunately, as a result of COVID they shut down they couldn't afford it. But I used to go there, bro, after work and give myself a nice big mug of Aventinas. It's a nice German. Nice German. Avantine is delicious. And then I would have some, you know, some. Some sausages, you know what I mean? A little. Little sauerkraut. And I would just tear that up, boom, boom, boom, with some mustard, bing and bing, Drink my Martinez and get out of there. Completely blown away.
A
You do love sausage.
B
Yes, I do. I have no shame in my game.
A
Yeah, yeah. Now.
B
Oh, go ahead.
A
No, now go. No, I don't know what's now.
B
Now that I'm getting older, you know what I do is the last time I went was with my brother. But before that I went with you. I would go occasionally to Peter Luger's over there in Brooklyn. You know, I went there before. It was nice. And so I don't go there for the steak or the food. You know what I go there for?
A
The old men. Waiters.
B
No, no, the old man waiters are nice. I like. I like hanging out with. They're cool. They know me, right? When I go there for bro, I sit. As soon as I sit down, if I have my same waiter because he knows I tip well, it would run to my table. It brings you a nice coffee with some schlog. You know what schlog is?
A
Oh, I do know what schlog is.
B
Sometimes.
A
Sometimes I give the old lady some schlog.
B
There you go. Right? So nice coffee with some schlog. Bang. And then before I finish my coffee, because I start the coffee, then I finish the coffee in the middle of that, have a nice bit burger. That's another good German beer, right. Boom, boom. Maybe have a little hot dog on a way out. And I'm done.
A
You go to Peter Luger's for a hot dog or you change back and forth restaurants?
B
Nah, I change back and forth. You know, either a steak or burger, if they have the sausages. I grab a sausage and have my coffee, have my beer, get the fuck out.
A
Did you have a 9th, 4th of July? Did you watch Joey Chestnut win again the hot dog eating contest? Yeah.
B
I got to say, there's one thing more. There's one thing that's really impressed by the gu. And it's the fact that he swallows. The guy, my man was. My man was hogging and schlogging. You know what I mean? He did his thing.
A
Yeah, Shout outs to Joey Chestnut for no record. I mean, he didn't. It was a little warm out Coney island was a little warm this year. Sure.
B
Yeah, well, he's got no competition. The Japanese guy retired, so, like, it's not really a competition anymore.
A
Kobayashi.
B
Remember he was always going back and forth with the Japanese dude? Right. That guy retired.
A
So for a few years, but then, yeah, he wanted more money. He wanted a sponsorship. He want. You know, so he and Nathan didn't get along, so. But I think Joey Chestnut won out in this one.
B
No. Shout out to Joey Chestnut. I mean, I mean, look, I'm not. I'm not going to ask how you got that last name. It is what it is.
A
Probably it was his parents or at least his father's when he was born.
B
I don't know what happened. I don't know what happened there, but.
A
Oh, I don't know either.
B
It's a lot of nuts on chest over here. You got to be careful with this guy.
A
So I feel like you have a big announcement to make about Safil. What's this crazy, radical thing you're doing with S.E. hill?
B
Well, it's one thing you know about me, I'm. I've. I've been radicalized throughout my life. And, you know, in some ways it was bad, but I'm radicalized in good ways, too. So at this point, for people that have been listening to me with you talk, you know, you make. You gotta make. Make it the perception that your boy Heck is a little bit disruptive sometimes.
A
Oh, my God. Are you joining Peter Thiel's group?
B
Hell no. Get out of here with that.
A
All right. You know, I thought maybe you were joining.
B
Well, since. Since pen testing and, you know, assessment services like that, you know, has been, I would say, become commodity commoditized. What I wanted to do was disrupt the space a little bit. So what we're going to do is at some points, either mid to end July or maybe early September, I'm going to open up free assessments on an ASM level attack service management. And then the audience here would be the first ones. Whoever owns businesses that have websites, infrastructure, whatever. Instead of going to pay somebody, just go to our website. You know, I don't know what it's going to be yet. It might be safeful.com something. And then, you know, you sign up, put in your scope, you say your domain and assets, and then we'll do a. Basically a ASM scan, put together a nice report for you. You can give that to your orders, blah, blah, blah. Now, if you want to expand beyond that, we do have a lot of other services, but I think there's a good introduction. Let's make it free. Why not?
A
Nice. I like it. Well, you know, I'm starting a new business, so I'm definitely going to reach out to Safille to go through my site.
B
Well, absolutely, bro. Set it up.
A
Yeah, so.
B
Oh yeah, it'll be.
A
I definitely check it out. So when are you going to make the big announcement about when is it going to go live?
B
Well, it's funny because this is a pre, A pre, pre announcement. And then once we go live, I'll get a little. I'll let the t. I'll let you guys know when it's gonna go live and then at some point we'll probably do a little press release or something so that the whole world knows I want to give, I want to give the listeners here maybe a couple weeks to get in on it before, you know, the floodgates open, as it were.
A
Can I ask you about the logistics of that? This.
B
Sure.
A
How when I go to your website and I sign up for this and it's a free thing and all that, how do you do your due diligence that I am actually giving you my website and not somebody else's website?
B
Sure. Well, you got to remember that what we're talking about here is kind of a cursory assessment. It's not a full pen test.
A
Sure.
B
There's no active campaigns against whatever you're going to be signing up as. Whatever. Christorball.com. the assumption is that Christorball.com is the scope.
A
So it's basically just the email is.
B
Yeah. For ASM type of scan. Absolutely. Now if you were to be like, hey, I want a pen test of kristarbell.com now you have to prove it. You have to prove ownership. And so we have that as well. We have that process.
A
I got you. I just wondered how it worked, how that sort of thing worked.
B
Yeah, yeah, no, it's. It, it works pretty well. It's pretty standard across the industry. If you go for like cyber insurance, for example, they'll just ask for like your domain name for your business. They kind of do like DNS stuff there and blah, blah, blah. But we have a much, it's much more extensive library of tests and runbooks. So you're probably going to get a pretty decent report based off the findings. You either have to fix and then reengage or, you know, hire professionals to help you kind of deal with that. Because we don't do remediation. We'll help you discover those issues.
A
But I Mean you are, do have very good you know, finding thing. Once you have your findings, you, you'll walk them through and of course I mean you might not actually do the hands on remediation but say filled, you know, can, can the, the, the easy stuff, the, the, you guys can help them with the remediation, them what to do, you know, simple patches and things like that.
B
1,000%. I mean look that, that's part of our reporting process and that's you know we offered the multiple deliverables. So you're not, you're not getting like a, you know, a report with a bunk of a bunch of check, check boxes and like hey, you have this thing, figure it out. It's like, hey, you have this thing. Here's what could be done with it. Here's how you're going to prioritize this. Here's how you're going to work on this. Here's how it's going to lower your overall risk and it's going to help you with your cyber insurance premiums. That's one of the goals. You know, when you look at the companies out there that do this and they're specifically the cyber insurance space, I mean they have 105, 106, 120,000 customers that sign up small businesses. They do it as an initial scan and the scans are usually just email security, that's it. And then they just convert that into you know, a nice cyber insurance, like you know a nice little like pre report for cyber insurance. And then that's when the cyber insurance provider will then ask for like a pen test. Okay, thanks for this. Now let's do a pen test. You know, so it's multi, multi step but very useful.
A
Nice. Well, we're going to do a thick show today. So our show sheet for tonight is 30 pages. Normally a show sheet's 10 to 12 pages. This one's 30 pages. Lots of stories to get into. So I think this is a plan. Heck, we didn't do a pre show Patreon episode so we are going to do a post show Patreon episode. So all the stories that we don't get to on the free show, we're going to go over to the Patreon. So thank you to those listeners that signed up for the Patreon. It's only five bucks a month. If you want the full extended episode today, get the fucking Patreon. Just do it. Just help us out. It helps keep the free show free. We are trying our best to keep commercials off here. Hector and I are getting hit up every single day about putting commercials on our show. Our show is, you know, in the top of the charts for cybersecurity. And they want to pay to be on the show, but we want to keep it free. I like staying agnostic, staying that no one controls us.
B
Listen, being agnostic is fantastic. And plus, you know, I don't want to read an ad about like penis lengthening pills or anything like that.
A
You know, pumps, not in a cage. If you're wearing a cage, you definitely don't want to lengthen anything. It'll hurt.
B
Hey, listen, I'm not. I'm not for it, bro, but let's get it. Let's get it done.
A
All right, so Patreon, get on the. Patreon, help us out. Hit us up at the merch. HackerTheFed.com let's get into the free show. Heck. Canada's communication and security establishment, which is Canada's signal Intelligence and Cyber agency, conducted authorized active cyber operations. Offensive cyber attacks hacked against foreign online criminals, brokering the purchase and sale of precursor chemicals for fentanyl and synthetic opioids. The operation involves intelligence collections followed by disruptive hacking that disrupted and dismantled their abilities to operate. The CSE also supported law enforcement efforts. So the scope focused on transnational criminal networks in the fentanyl supply chain. No specific victim counts, data volumes, or exact targets publicly identified. But part of the annual report meant they went on the offensive. So Canada now is going on the offensive against drug websites.
B
Well, let me ask you about that, if you don't mind. So with your time at the FBI,
A
Well, I famously took down a drug website, so let. Let's get into it.
B
That is true. That is true. So, but I know that you guys, back in your days, you guys probably had a lot of restrictions of what you could and could not do. So let's kind of take the scenario that we just read and we're gonna go into a little bit. Would the FBA have been the one attacking the drug market that these guys targeted, or would it be like a third party contractor or the nsa? Like, who do you talk to for something like this?
A
Well, I mean, an exact parallel for this story, I would guess it would be the nsa. Okay, the problem is the NSA would not get involved in anything that was criminal. If it's a criminal investigation, they are not going to because they are not going to burn a tool on anything like that. If they were to get involved, they would say, you cannot do whatever you're thinking about doing. Now on the criminal side, we had the skill set, but we, you know, we. So in the US offensive operations falls under code 50. So criminal code for hacking is US code 18, subsection 1030. 18 is civil, is criminal law enforcement. You know, we did not have Title 50 authority. NSA does that. And you can't do active things against known US entities. So if you know for a fact that it's in the United States, either the, the, the facility, the server, or the person is, is a US Citizen, you can't do it now. You don't know. There's a little more leeway. You can knock a server down if you don't know exactly where it is. You got to get authority. But.
B
Yeah. Wow, interesting. That's, that's really, that's really something, huh?
A
You, it's surprise. The story was surprising that the Canadians, so the, the Dutch have done this for a long time. They would go after CCM sites and knock them offline, DDoS, them, knock them down. But for the Canadians, they, this is a whole new thing. But what are you going to do? I mean, you've got fentanyl and you've got, you know, opioids streaming into your country. You have the ability, you have the technical ability to disrupt the operation. I don't have any problem with it. Do you?
B
No, I don't. We've, we've had a discussion before about like, hackbacks, right? Remember there was a bill that was being proposed, pirateering. Remember that?
A
The pirateering.
B
Yeah, yeah, pirateering. So. May. And this is, this, this is, this is the crazy part, right? So, like, I think, I mean, I'm very anti drug. I don't, I don't like what drugs did to my community growing up, what did to my family. My family were dumb. They got involved in that shit.
A
You have a very personal connection to that world.
B
Absolutely, I have a very personal, deep connection. In fact, it's documented online. You could, you could just search up my last name and, and you'll find my family's court case. You can see my name in the documents, the paperwork. So I, I know this lifestyle. I know, I know that very personally. So I'm, I have a bias against. That's for sure. So when I first read the story, I was like, great, you know what? I'm for that. But then the problem I have,
A
maybe
B
there's a little bit of libertarian inside of me, bro. I'll be honest with you. Because then a part of me is like, do I really want to trust the government in these operations? You know, how, how do I know that the government is targeting like a drug operation and not like a journalist home network, you know, so you, you know, it's like, you know what I'm saying, Right? I'm not sounding crazy right now, but it's like, who makes that decision? Is there a judge involved? Right. I don't know.
A
Let me ask you this. How do you feel about the NSA and what the NSA reportedly does for the US Government by hacking?
B
I don't like what the nsa.
A
You don't like any of it. They're going into, you know, take off like jihadist websites or, or getting intel, like collecting, you know, email accounts for people that are known terrorists, what designate as terrorists.
B
I understand what the NSA does and what they're capable of. We saw some of their capabilities with the Shadow Brokers League. We've seen some of their, some of the capabilities when, you know, there were leaks from Snowden and so on. So I've seen capabilities. Now what we also have documented is wrongdoing where you would have a, an NSA operative or somebody working within that space. The third party federal contractors, unfortunately, are within the space. And so we've seen cases of them snooping on Americans.
A
Yeah, we've. Snowden came out and said that there were guys at the NSA or that were snooping on their girlfriends.
B
Exactly right. And that's what, to me, for me, that's problematic. Now do I have a problem with them targeting like a jihadist network and trying to infiltrate to see if, like the incoming terrorist attack. I don't have a problem with that. I do have a problem when they, when they abuse our civil liberties, when they abuse our privacy, then. So I'm split. I'll be honest with you. I'm split. Right. Because I don't know who's making the decisions, who's making the designations. At the end of the day, I know that I'm human. I know that everybody here is human. Those operators are human. And they could do this. The girlfriend sniffing, right. You know, sleuthing and watching the girlfriend's text messages. I'm not sure I'm for that.
A
No, I'm against that. I'm against the abuse of the system. But you're right, there is not a good way of checks and balances on it.
B
We need, we need to figure that out. And if you could tell me, if you could tell me confidently, you're, heck, you know what? They figured it out, then I'm all for it. Yeah, attack the jihadists, attack these drug markets 1000% I'm for it.
A
When I was young and naive in law enforcement.
B
Yeah.
A
And you would have told me that some guy would, like, beat up a guy. A cop would beat up a guy in handcuffs. I'd be like, that's. That's not realista. No one would ever do that. But the more I see things like that, it opens my eyes that there is abuses of the system. There are some people, and I think there are a vast minority, but they abuse the system. There are cops that hit people while they're in handcuffs. Then that is. That's dust to me. I've never seen it. I've never been a part of it. I wouldn't even, like. It's so foreign to me. I wouldn't even think it's real. But it is. I've seen it. I've seen that on videos, you know. Yeah.
B
I think. You know, I think in many ways,
A
you've been picked up by cops and then dropped off in a different part of town and all that.
B
Absolutely. Yeah. No, I. I got stopped for the audience. You guys might remember. But I'll tell it again really quickly. I was arrested in Atlantic Avenue in Brooklyn, which is huge. Atlantic Avenue is a massive avenue, and had these two cops who jumped out at me and put me in hiccups immediately. And I'm like, hello, is everything okay? Like, what happened here? And they arrested me for murder. And I'm like, guys, I promise you, I didn't murder anybody. And they're like, well, it's not. It's not what it says. And they showed me a picture.
A
I will tell you when I. When I've arrested people for murder. And they. They promised I'd let him go immediately, because they promised.
B
But. No, no, but what I'm trying to try to say here is, like, I knew a murder anybody. I get that a murderer might say that as well. So for me, it was so surreal. I'm like, dude, what? And thank God for the desk sergeant, because the desk sergeant, they were speaking over the radio, and the desk sergeant was like, who do you have. Dude, that's not the guy we're looking for. Let him go. But he dropped me off nine blocks away. They left my car abandoned in the middle of the street with the keys in. So, I don't know. I'm surprised I didn't get robbed. So, yeah, I've been through that. Right. And it's so crazy to see that.
A
A la Avenue. You never get robbed there.
B
That's right.
A
That's right.
B
How dare I? But I understand where you're coming from. Though I do, because I know it's got to be difficult. There's a lot of good cops, a lot of good law enforcement people, and then there's social outliers that just completely it up for everybody else.
A
Yeah, I don't. It was crazy to see the CSC actually took action against 10 other ransomware groups that were impacting Canada in the same time period. Like, so, I mean, I guess, I mean, I guess Canada's just fed up and now they're, they're letting their equivalent NSA guys go, you know, balls to the wall. Let's, let's go, let's do some hackbacks. Let's, let's use some offensive fighter power against these guys.
B
Shout out to the Canucks. You brought up a good point. The Dutch have been doing this. I mean, in fact, during our elections. The Dutch try to help us almost every time when, when there's like a, some sort of conspiracy. During, like during the 2016 and 2020 elections, they literally hacked into like the Russians like GSB or whatever, and they were like watching the Russians like trying to attack our, our elections, and they gave us the release the, the videos online. So Shout out to the Dutch. Shout out to the Canadians. Now I'm, I'm gonna see, I'm gonna pay attention to what other countries are probably gonna follow suit because that's interesting.
A
Damn it is interesting. So, you know, I live in Virginia. I'm not a huge fan of our current governor, but she did do something interesting this, this week. So the Virginia governor, Abigail Spanberger, signed SB338 into law amending the Virginia Consumer Data Protection act to prohibit controllers from selling or offering the sale of precise geolocation data concerning a consumer. So a little bit of data security, a little bit of privacy here. So precise geolocation data is defined under the VCDPA as data that directly identifies a natural person specific location within 1,750 foot radius and narrowly defines the sale as the exchange of personal data for monetary consideration by the controller of a third party.
B
I love to hear that this is
A
a good step forward for consumers in Virginia.
B
Well, it sounds like you have some people in Virginia and you may not like them currently, but, you know, listen, it goes to show you that even, even, you know, someone from a different party or from a different mindset, you know, they could do good, you know, and, and they're thinking about Virginia. They're not thinking about one party, nothing about one group. Big shout out to Abigail.
A
Shout out to abigail.ca Former CA Spook Abigail Spamberger age.
B
Hey, shout out to her. But this follows Maryland and Oregon. Shout out to Oregon. Shout out to Maryland. I'm hoping that, you know, Virginia leads the way. Now Virginia is one of those bigger, more important states. Now the other states around, they can start picking up, you know, just get Connecticut involved. Let's get New Jersey, New York. Right, Philly. And see where it goes from there, bro. Hopefully it spreads. We need more of these. We need more protections for Americans, everyday Americans.
A
What do Americans exactly get from this?
B
Well, the big concern that we have, we just talked about a minute ago, we covered. Well, we've seen historically that NSA operators, you know, they're humans, they make mistakes and they've targeted people. Now imagine a scenario where you have an operative that's stalking or obsessed with somebody, you know, geo fencing an entire region, exposing or leaking the personal details or getting access to personal details of everyone within the region just because they're close to the girlfriend or close to the wife. That's a big problem, right? Because it's not like you're just targeting a girlfriend. You're targeting entire, let's say, you know, a thousand square feet or 10,000 square feet around that person. You're gonna catch a lot of folks, you know what I mean? And so I'm not for that shit. I've never been a fan of geofencing. Geofencing is terrible. It's great for law enforcement, don't get me wrong. Because let's, let's think about law enforcement. You can probably explain it better than I, but here's my take, right? For law enforcement, let's say there's a murder in, you know, somewhere in Brooklyn. Let's say, you know, left First Avenue, whatever, right? There's a murder there on a Saturday at three in the morning, all right, it's next to a train station. And let's say you're able to do a geofence ping. You, you, you may not have footage of the attacker, but you might have their phone pinging at that same time. It doesn't mean that person that pings with the victim is your attacker. It means they were around. That's a potential witness, right? Means their phone was around, the phone was around. That's right. It doesn't mean that the, the owner was around, but the phone was around, which opens the door for potential witness and, or potential murderer, right? I can understand it. For law, for law enforcement, you know, there's a lot of privacy concerns with law enforcement doing that. But then of course, it's abuse because one Thing that we have in this country is we have third party vendors, advertisers and so on, having the same capabilities sometimes as law enforcement.
A
Yeah.
B
If they could geofence, let's say your area of Virginia, not only will they be able to get your information, but the information of all your neighbors. Right. As an advertisement network and then start feeding you guys certain intelligence or propaganda information or using, you guys pull information to use for something else. It's just, it's not cool. So things like this is actually very beneficial.
A
But just so the listeners realize this is not for law enforcement, this is for selling the data to exactly right. You know, locations your phone goes and all that that is selling. So law enforcement will still have the capability of seeing whose phone was in the area when a crime was committed to.
B
Yeah, yeah. So this with third parties. And I'm for that 100%.
A
Yeah, I agree. Privacy against people buying your data and all that, like we just can't get around. I mean you in today's day and age, you have to have a cell phone and for your cell phone company in the fine print to sell your data to somebody else. Bullshit. It's, it's what they call fugazi.
B
You know, somebody hit me up, they sent me a message. They say, they say, yo, heck, once you put that shirt online or the hoodie, yeah, absolutely gonna get it straight fire, straight fire. And they're like, yo, because there was something I said like two weeks ago and I was like, hey, I'm the fool and you're the gazy. And he loved that. He went crazy for that.
A
Yeah, you're talking about him, not me, right? I'm not gazy.
B
No. Yeah, it was a conversation, you and I. You say you loved our conversation.
A
All right, well I'm not gazy. Don't, don't out with gazy LLM. Jackie, now I know you're not doing it, but a lot of people are these days involved stolen AI compute as offensive infrastructure. So researchers published by the Cloud Security Alliance Labs detailed that the evolution of LLM jacking the theft and abuse of cloud hosted or self hosted AI/LLM compute from a single credential resale into fully agencic offensive infrastructures used autonomous vulnerability assessments, exploration and lateral movement. Heck, what the fuck does that mean? What's happening in the world?
B
Well, you know what this is? What this is, my friends, is a pattern. Every time there's something cool, people figure out a way to abuse it. I'll give you a good example. I want to give you Guys. A couple of examples, actually. So when AWS cloud became a thing, right, people started using AWS and they started generating tokens, and then they started leaking those tokens, because us humans tend to make those mistakes over and over and over again. They started opening up S3 buckets, right? All of a sudden you had automated bots finding those keys, using those keys to deploy new EC2s or VMs, right? Virtual machines, and then crypto mining. You remember that? That was a whole big thing back in this. Billions of dollars were lost as a result, right? That's just one example. I'll give you another example. So when OpenClaw was a thing, right, last year, people started deploying OpenCloud bots and agents all over the place. They left them open, right? And it goes directly to the story. Left them open. No authentication, no authorization. If you could find the openclaw agent with some sort of chat window or something, then you could use someone else's infrastructure to kind of do a bunch of computing. This is exactly what this is. This is people deploying technology that they're not familiar with. They have no understanding how it works. They have no concept of security. And you have people taking that infrastructure that's now basically free to steal your credentials, steal your tokens, but to also deploy new agents and do some hacking. That's what this is.
A
So we're going to see this get worse and worse before it gets better, right?
B
Yeah. I mean, look at the numbers. Right now, there's about 175,000. Well, as of the story, 175,000 unauthenticated olama instances around the Internet with model context protocol access, meaning you can run tools off of that, you know, and from there, you can start to build basically a botnet. This is botnet territory. You create a botnet of agents from public, unauthenticated ALAMA instances and just do massive AI processor.
A
I mean, you're not giving people ideas here. What the hell, bud?
B
No, but you know what? I'm about full disclosure. I'd rather tell you what's possible so that, you know what? Whoever's listening can start fixing their instances, because at least one listener here has set up a bot. They set up a llama, they set up open call, they set something up, they said it and forget it. And instead of you waking up to $110,000 bill from AWS, you go fix it as you listen. You know, full disclosure, baby. It works.
A
So we're seeing this in the wild. This isn't just a theoretical thing. We're seeing that people are starting to do the LLM hijacking?
B
Absolutely. Oh, yeah. You know, and big shout out to the cloud security alliance. Love those people, the csa.
A
I think I speak for them once. I think they're good people.
B
I think you did. Yeah, they're good people. I think you did one. Yeah, for sure. They've been talking about this before, AI, they've been talking about this before. Cloud was cool. They've been around since the beginning and it's very smart people out there and they've been telling us, hey, this is going to be a thing. And when it happens, they're like, wait, see, we told you. Here's the thing that's happening. How about you fix your shit? That's what. That's what's going on with csa.
A
How are these instances that are open
B
on the Internet found with automated scanners? Very easy. Just imagine a scenario where you have a really fast computer at home and then you run a, let's say a network scanner, something like an nmap. You could scan the whole Internet very slowly, or you could get like Z scan or Z map, scan the Internet very fast. You're going to blow your broadband, maybe your router is going to explode. But you gotta. You just scan the Internet in a couple hours and what ends up happening is you start finding these instances and voila.
A
But if you set up these instances as a company, is there a way for. Is this part of a standard pen test or is this part of. Can you add that on as a pen test or a vulnerability scan to see if your instances are vulnerable?
B
Absolutely. For example, with Safe Hill, that's what we do. We're looking for your threat exposure, right? So we're scanning every port on every server that you have. We're like trying to identify or enumerate what those services are. If we identify an open Olama instance with no authentication, we could prove it, take some screenshots, generate some evidence, and then voila, you fix it. But if folks are not doing that, you end up with the numbers you're seeing now, you know, under about 200,000 instances open, like today. Right. And that's just the beginning of the iceberg. Olama is not the only service that you could deploy that opens up kind of a chat window. People are opening up Hermes, Hermes agent people are still using openclaw even though openclaw got bought out by Meta and there's other agents out there that people are just deploying and like forgetting about it. You know, it's a problem
A
now if you don't find an instance is open. What if it's just credential? Is, is there a way of protecting against just open credentials on the Internet? Can you, can you two factor this stuff?
B
You can, but you know what's a better idea, my beautiful man?
A
What's that?
B
You put it behind the fucking firewall. That's what the. Oh yeah, you fucking set up a firewall, right? If, if it's, if it's a vm, you set up on Linux, but it's running on Digital Ocean or aws, Google Cloud. You set up a firewall policy that says hey, my IP is the only IP that should be able to access the service with this port. Right, but people are not doing that. They're just, you know, all willy nilly leaving things open. Just like back in the 1990s when every computer had an external Internet IP address.
A
That seems like a pretty simple solution to some of this stuff. I can't believe people aren't employing it.
B
I mean I feel like that's most of what we talk about, right? Adversaries are having the easiest time of their life right now. They're breaking into everything.
A
Yeah, I thought it would all be plug and play. But as just as we knew a new technologies come out, people just put it out there and leave it wide the open. It's crazy to be.
B
Dude, it's assuming nature baby boy, you know.
A
So at the last speech we did down in Florida, got a lot of questions from people saying hey, when are we going to take out some of these groups? What are we going to take some of the groups? I said hold your horses, it's coming soon. We finally got the news this week. So an alleged member of the cyber criminal hacking group Scattered Spiders was arrested in Finland and extradited to the United States. Peter Stokes, a 19 year old dual US Estonian citizen with the known online user name as Boket, was arrested in Finnish authorities by Finnish authorities in April of 2026 pursuant to an Interpol Red notice and extradated extradited to the United States last week. See, that's why I shouldn't drink. I can't say extradited.
B
Yeah. This bouquet by the way.
A
Oh, sorry. Bouquet. Stokes faces federal charges on conspiracy, computer intrusion and fraud in the Northern District of Illinois. He is alleged to be a member of the criminal cyber hacking group Scattered Spiders and which has been linked to over 100 network intrusions resulting in more than 100 million in ransomware payments and millions more in damage, specifically links. Links, ties, strokes include the May 25 breach of a luxury jewel retailer, Computer Systems, where data was exfiltrated and an approximately $8 million in cryptocurrency ransom was demanded. The retailer's security personnel, they stopped the threat actors without payment, but the victim suffered at least $2 million in losses from business disruption. So we finally got a guy on Scattered Spiders, dual US Citizen who was hanging out in Finland.
B
You know, I wish I would have met this kid somehow, LinkedIn, Twitter, whatever, and be like, hey, brother man, listen, you have so much potential, right? You clearly could think like an adversary. Let's put your skills to use it. I'll give you a job, even if it cost me. It burns my pockets because, you know, I'm. I'm a. I'm a second chances guy. I want to give people an opportunity. Obviously, this kid, you know, has his capabilities, right? He's. He's good at something. It's just, it's. It's. It's the worst of cyber security, which is he knew enough to participate in a group setting and then take advantage of people and ransomware people and attack people. I know he's a part of a group. He's probably a small cog on that wheel. But what makes it worse, and you and I talked about this during the. The MGM hack. Remember mgm, Caesars. That one of the first things that came out was, yeah, we're. We're getting social engineered by kids with ink with American accents. Sure. It wasn't like a random Russian, hey, brother, can I please get my password reset? It wasn't nothing like it was Americans. This kid is part of that, right? May not have been part of the MGM act, but he was part of those guys that is American dual citizen. And, you know, it's a shame, it's a tragedy, because it sucks. And now he's going to do mad time in prison and he's going to come out and people are not going to trust him. It's going to take him a long time to get his life in order. There's a shame. I'm sad about it.
A
Yeah. I mean, it looks like he's finally been caught up in all this stuff, but, I mean, if they. He has ties to going back to. Way to the beginning of Scattered Spiders.
B
He.
A
He's looking at. I mean, they. They held him without. They didn't let him out. They. They remanded him in custody. This kid's gonna do some time, lots of time. And being like one of the first people of Scattered Spiders to be arrested. The judge is going to Make a, A, an example out of him.
B
Well, let me tell you something. I've been, you know, I follow the community. I see what people saying, researchers and all that. The big story is not that this kid got caught. There's a big, big, massive story to this. What's that in the indictment paperwork, the documentation that came out. Researchers and, and threaten tell. People are going through those paperwork like crazy, right? The indictment papers, they found something really interesting. It's how he was tracked. Let me tell me break this down for you. It's actually very interesting. You might know this because, you know, you're a former FBI guy. A lot of people didn't know this. So first off, he was a Windows user. His computers were Windows. All right. Apparently. And this is undocumented for Windows users. There's a certain, like, I forgot what's the idiot naming? It's like something. Something GUI did. Sure, right. Is in the Windows computer from installation. It never changes even after like a full reset.
A
Each user gets the same. A different one.
B
Yeah, exactly. Right. So his activity could theoretically be tied even if he's behind VPN or whatever. Microsoft did an investigation. They were able to give the FBA a ton of information of what he was doing based off of that, that that global identifier. And people were aware that was a thing. But folks ain't seen until this, this, this kid's indictment. And so on Twitter, it's a whole massive debate about it. What else is Microsoft tracking aside from that, that identifier?
A
How much detail was. Was put into it, into the indictment? I didn't read the indictment, so I'd be interested outside of timing, that these activities were happening, this GUID was online and active, you know, doing something active. Not just idle, not just whatever, not just on. But actively recording events. Outside of timing, was there specific events that. That was recorded?
B
Yeah. So from what I've seen, and again, it's all on Twitter, folks. So you guys could, you know, just type in the guy's name and you're gonna see people doing like whole reports on the mic, the Microsoft involvement with the indictment. They were able to track, like when he was on a certain forum, when he did a certain thing, when he was traveling behind a vpn, it could still like, identify if he was on, like Telegram. It was pretty extensive. And I was really surprised by that because you would think that something like an undocumented global identifier like that is something that they probably would have not, you know, put in the indictment, but they did. Obviously. You got to prove how they figured this get out. So then somebody else came up and said, wait, if Microsoft could do this, then can any manufacturer of laptops do the same? Because the TPM and the laptops never change a tpm, which is like the little encryption module inside your laptop. Right. For randomness. Right. That thing doesn't change. You can install Linux, Windows, whatever. So can. Can you just. If you're an investigator and you're able to somehow infect an attacker's computer somehow, right? Which we've seen, and you grab like a TPM identifier and then you finally arrest the guy. And the TPM is the same. Same identifier, you know. So anyways, there's a whole bunch of stuff like that online. I would recommend people look into it. It's very interesting stuff.
A
Well, it'd be more interesting to go the other way and try to find them via the tpm. But you'd have to figure out brand. I mean, I guess you could just subpoena all brands. But it would be. It would be, I think it would be fought in court. It would be overly burdensome to go to like Dell and say, give me a user that did all, you know, these 100 things. So I don't know, I could see where it'd be fought in court. Unless you get a very friendly laptop.
B
Think about it and see, now you're taking me down a rabbit hole.
A
Sure.
B
Because what if, let's say, Dell, all Dell computers, they provide you a TPM for randomness, but what if that randomness is not necessarily fully random?
A
Well, you know computer science, there's no such thing as random. It's all pseudo random.
B
It's pseudo random. Right? That's exactly right.
A
There's no such thing as random in computer.
B
So what if your computer is a certain pseudo randomness and my computer is a pseudo certain pseudo randomness? And you know what? We're going to burn an hour on this. But now it's making the little hamsters in my head kind of. For any mathematicians and crypto experts, please feel free to email us on this because I think it's very interesting.
A
And I'll tell you for a fact this. Listen, audience, the hamsters aren't in his head. They're someplace else.
B
Well, they're not in my ass either. They're here. They're talking to me.
A
You know, Richard Gear 2 over here.
B
Oh, Jesus Christ.
A
Oh, boy. Oh, boy.
B
Let's get into that.
A
So the US now is offering $10 million for hackers targeting WhatsApp and Signal users the US State Department rewards for justice program announced a reward for up to $10 million for information leading to the identification and location of members of the Russian linked hacker group UNC 5792. It's associated with the Russian Federal Security Service, the FSB Border Guards, and was conducting widespread phishing campaigns targeting signal and WhatsApp accounts of US government officials, military leaders and allied personnel. Journalists, nos and researchers focused on Russia and Ukraine, which operate on behalf of the Russian military service as part of the broader cyber security attacks against U.S. infrastructure. So now the U.S. department of State's $10 million hector to target Russian FSB actors.
B
Yeah, well, you know what? I'm not surprised by this. There's a lot of people in this space, right, that have been doing like, you know, CTI or threat Intel. They've been in the space, you know, they've been doxing, these adversary groups. I've showed you, we've talked about some of them. They've been doing it for free because they don't like bad. They don't like bad actors right now. They have the potential to get paid, and they're really good at tracking these down. I've seen some amazing reports, you know, so I'm curious to see, like, what this looks like. How many of those guys are gonna get paid? How many they're gonna actually dox and, and infiltrate and connect the dots. And, you know, I wonder how this is going to work. Is it going to be like a bug bounty program type of thing, you know? Like, do they just email the tips at FBI? Like, hey, I got you this guy who did 14 ransomwares last year. Here's the name, here's his picture, here's evidence. And then FBI finds the guy, extradites him, and then what does the, does the discoverer get paid? I don't know.
A
I mean, if I know the Russians like I think I do, they don't let these people travel. If you are on the offensive side for the fsb, you do not leave Russia. You don't go on vacations anywhere.
B
That's true. That's true. Well, that's not necessarily true. We've seen them get extradited from Spain, right? But we, we pissed Spain off since then, so I'm not sure that's gonna be a thing anymore.
A
I think they're gonna lock that down.
B
Yeah, yeah, yeah.
A
So we'll see what happens with it. But 10 million bucks out there, guys, if you can name some FSB actors that are going after WhatsApp and Signal. And apparently they're targeting the, the sink, the signal backup recovery keys. So specifically they want to clone signal accounts for high end government officials.
B
Well, signal right now is all the rage. A lot of, a lot of these rushes are attacking signal like crazy, you know, and this is why I got. Listen, remember, remember back last year when we had signal gate with hexath and noise? You know, guys, you know, last year when I went on my little rant on the topic, you know, I think we pissed off at least one listener. Right. You know, I was a little, little, you know, aggressive with it. But part of what we're hearing with these stories is, was my concern. If we have these folks from our government using signal, building out signal groups, they have no idea what the they're doing. You know, sometimes these guys are posting their password on Twitter because they're, they're thinking, they're typing into a password prompts, right for them to be building signal groups. And these Russian actors are able to like hijack signal accounts, sit there and kind of listen for information. It's a problem. And so it makes sense, I think. I'm willing to wager that a signal account got hijacked that belonged to somebody political. And this is why the government is like, you know what, let's start putting some bounces on these motherfuckers, you know.
A
But 10 million must be somebody pretty good.
B
Yeah, you know, Ted Cruz, you know, one of them idiots those guys, Those guys are as, they're dull, you know what I mean?
A
I don't think Trump's putting out 10 million for Ted Cruz's signal account.
B
Yeah, yeah, you're right, you're right. You know what? I stand correct. You don't give a Ted Cruz.
A
So for the free market lie why Switzerland has 25 gigabit Internet and America doesn't. So the ongoing structural disparity in high speed broadband development where Switzerland has achieved widespread network, dedicated symmetrical fiber connections up to 25 gigabits per second throughput, enforced open access point to point infrastructure, while the United States largely remains territorial monopolies while shared point to multi point connections, limited provider choice and slower effective speeds. So key actors include the Swiss regulators, the incumbent Swiftcom, which is 51% state owned and competing ISPs versus US incumbents which operate differently under the regulatory framework with limited open access. So the scope involves national infrastructure affecting residential and business connectivity. So the Swiss have high speed Internet throughout their whole thing and the US
B
has well big shout out to Stefan Schlerer, the guy that put this together. He did A great report, guys. Check out his website. And what's fantastic about his write up is that he didn't mince any words, he didn't add any extra fillers. He kept it very honest and very real with what the problem looks like and what the problem may be. What we have in the United States, as much as I love my country, it's a Beautiful time, happy 250, right? Beautiful time. But we have a lot of micro monopolies, in some cases nationwide monopolies of these ISPs, these Internet service providers who are full of shit. They're full of shit. You know, I live in the cities. I either go from New York City or I go to, you know, Puerto Rico or wherever I'm going. And so I'm a city guy, but that doesn't mean I'm ignorant of the perils that my fellow Americans who live in the rural states and cities, towns, the fact that some of these people are still on dial up in 2026 and then they have to go with an expensive service like Starlink just to get Internet access. You know, Starlink works, but having Internet access should be at least a basic right. Here in the United States, we don't have that because we have monopolies controlling whether that happens or not. It's bullshit. And so Stefan Schooler, I'm probably mispronouncing his name, did a really good job explaining that. Hey, yes, the United States is much bigger than Switzerland. Yes, there's obvious differences in how both governments are run. But at the very least, the Swiss have figured out that Internet access should be at the very least a basic right. And in order for them to do that, they have to. They had to upgrade infrastructure nationwide to make that happen. That needs to happen here in the United States. And guess what? It does cost money. And we're one of the richest countries on the fucking planet. Please tell me why we're not doing this.
A
Yeah, but 25 gigabit, I mean, it's not needed that fast.
B
You don't need it that fast. But you know what? Can we at least get our brothers and sisters in the rural fucking states, in the cities, in small towns, can we at least get them a gigabit? Can we? We can. We choose not to.
A
You don't like old Internet dial up access?
B
Well, the problem with it, bro, I love it. If I go back to dial up, I would. And I'd be fine. Right? Here's the problem though. We have a lot of people, millions. We don't have like 20,000 people, we're talking about millions of people of America that cannot get access to the Internet. They cannot, they're not, they're not able to do what for example, I'm able to do. And that's a disadvantage. It's a shame, you know. So this article was fantastic. I think more people need to read it and I think there needs to be some sort of any something. Right. I know you're not a big garment guy, you're a small garment guy. Right? I get to get all that shit. But what are your thoughts here? Do you think the government should be able to do something and, and fuck you do. I think the monopolies, gotta keep the monopolies but at least can you offer these rural people some sort of Internet access by upgrading infrastructure? What are your thoughts on this?
A
I mean I don't think it's the government's place to offer Internet access. I think to take your foot off of the regulators. The regulators take the foot off of these industries to get it out there whether people want them and want the fiber connections. I mean to run fiber way out into the rural area. So three homes gets it. You're gonna drop. You know I, I just don't think it's gonna stay up in a capital market. I do like the idea what SpaceX has done. They said let's take the physical connection away. Let's offer you know, a connection via satellite.
B
Sure.
A
I mean what would you, Are you against that?
B
No, I'm not against that.
A
I mean it's right now it's sort of a monopoly. I know Amazon has plans of putting up a constellation for Internet, you know, space based Internet connections but I just don't think, I mean the United States in relative land size compared to Switzerland.
B
Sure.
A
Out of control. And so the amount of space we need to cover to ride fiber, I don't think it's feasible. I think we can only go to the Constellation based Internet access.
B
I, I'm cool with that. But then you look at the starlings price, there's, there is a monopoly. You're right, that's another monopoly. Yeah, the price, you know the people,
A
you know the people is a monopoly. There's a monopoly because they're the only motherfuckers that had the balls to do it. Which is sort of what capitalism is.
B
Well, no, no, calm the down, slow down. I know you like Elon Musk, slow down. But you know Elon Musk had the capital to build the system out but this system is not new. It's been around regulation held this back,
A
Jeff Bezos had the money to build a constellation. He didn't do it until Elon Musk was successful at it.
B
I understand all that, bro, but that's not the fucking point. The point here is that when you have someone like Elon Musk and Starlink able to just completely ignore regulations and, or get a green light from everybody involved because they're best buddies with the fucking President. Yeah, it makes sense why Elon Musk and Starlink has the capability to offer. But that's not the fucking problem. I don't even care about that.
A
Bezos could have done it while Biden was in office.
B
So what does the Biden have to do with this? What I'm saying is for the people down in the rural cities, the towns, you know. Yeah. It might be three or 30 houses. Those people are out in the fucking sticks. They cannot afford 300. Fucking an initial 300 investment plus 150 or 125amonth. That's fucking crazy.
A
You think the government should subsidize that?
B
Why not? We subsidize everything else. I got to subsidize the fucking President. Go play golf. You could subsidize a whole fucking family down in fucking Appalachia somewhere or down south in a fucking woods somewhere. Yeah, you could give them some Internet access.
A
So why are we subsidizing them and not people in New York City that have the access? Why can't, why don't we subsidize everybody then for Internet access?
B
Why not? Yeah.
A
Where are we getting the money from? We're $37 trillion in debt.
B
I, I get that, brother, but you know, that's, that's self inflicted cheap.
A
Dropping bombs on schools. We got to pay for those bombs. Whoa, you can't give another country $300 million after you bombed them out. That money's got to come from somewhere. Well, 300 billion, I thought.
B
Yeah, 300 billion. Yeah. Plus the hundreds of billion we've given out to other countries in the Middle east, you know, and the hundreds of
A
billions that we spent on bombs. Schools don't blow themselves up.
B
Well, that's the point. I mean, I mean, I'm glad you're bringing that up because it is, it is a solid point. We should be able to help our people. It's time to help our people. And it doesn't make you a socialist nation to help your people either. You know, I'm thinking about Larry out in the sticks. I want him to have some Internet access. He's. You don't got Larry Larry, Joe, you know what I'm talking about. Some redneck names, because that's who the we're talking about. See, at least I think about the rednecks. Those classes, elitist, techno, oligarchist or whatever the fuck they're called. They're not thinking about the. The rednecks. I'm thinking about the rednecks. I want the Rennex. That's me tonight.
A
All right, brother, we've gotten to a thick show. Thick, thick show. Let me preview what we're going to go over on Patreon do. So we're going to talk about Palantir's thoughts on the importance of AI sovereignty. You apparently enjoy this one, so we'll see where that goes.
B
Not enjoy, but we got some talking points. Go ahead.
A
AI has been. It's been decided that AI can't be listed as the inventor on patent applications. Good. We'll jump into that a little bit. Meta paid hundreds of contractors to pretend to be teenagers. Well, I don't know why they need to do that. They could just paid real teenagers.
B
No.
A
And then Palantir is getting kicked out of a shitload of European countries. So we'll dive into that a little bit. Yeah, yeah, so we'll dive into that. So we'll do the. The. The. A bunch of Palantir stuff, some AI stuff, and we'll have fun over there. Well, maybe we'll even talk about your cage or something a little bit.
B
Yeah, it's about something talk some.
A
So. All right, we'll jump over there and do that one now. So, guys, support Hacker in the Fed on Patreon. We're trying to push you guys over there. It's five bucks a month again. It's keeping commercials off here. Hector every day calls me and says, take the commercial money. I don't care. We'll read about dickheads in the middle of fucking Hacker in the Fed. I say, no, we're not doing it. We're not taking the Ed.
B
We're not selling our souls.
A
So he's begging me. So merch is up at Hacker in the Fed dot com. I am going to reach out to the merch lady and make her put up this week a Fugazi shirt. We are getting. We got to get it going. It got Fugazi is going to happen before this episode comes out, I promise.
B
Oh, yeah. I still got my. My original Hacker in the Fed hoodie from the original store that we did in the beginning. Like. Like straight up in the beginning. Yeah, the quality is so good.
A
I. Fantastic.
B
Yeah, it's not no cheapy choppy cheap shit. In fact, I remember the one that we had was right here. Made in America. Beautiful like quality like dude, I loved it.
A
100% made in America. Even if I, in fact I ship them out so you, they, they come out and I, I bring them to the post office.
B
So you got, you get, you got Chris's DNA with each box. Look at that.
A
Five star reviews. Wherever you download, subscribe. Hacker in the Fed. Subscribe. Bump our numbers up. Share us on social media. We put up a write up every week on LinkedIn and I think, I think Alanis is putting us up someplace else. She's putting up little short videos. Yeah, I've seen her doing it. So tell your co workers, tell your friends, tell your lovers, tell the person that puts your cage on for you. Download. Hacker in the Fed.
B
Do it.
A
All right, brother. Love and respect. I had a good time.
B
Cheers. Cheers, brother. Sam.
Hacker And The Fed – Ep. 139: "Canada Just Hacked the Drug Cartels"
Release Date: July 9, 2026
Hosts: Chris Tarbell & Hector Monsegur
In this information-packed episode, Chris Tarbell (former FBI cyber agent) and Hector "Sabu" Monsegur (ex-LulzSec/Anonymous hacker turned security professional) provide their sharp, often funny insights on a major shift in cyber enforcement: Canada’s intelligence services going on the offensive against drug cartel websites. The duo unpacks what "active defense" means, reflects on parallels to U.S. electronic operations, debates hackback policy and oversight, and dives into additional cybersecurity news — from LLM jacking to privacy laws and global differences in internet infrastructure.
“In the US, offensive operations fall under Title 50, criminal code for hacking is Title 18, subsection 1030… NSA does Title 50, but they will not get involved in anything criminal. They’re not going to burn a tool on that.” (13:04)
“The Dutch have been going offensive for years, but this is new for Canada… If you’ve got fentanyl pouring in, and you can disrupt it technically, I don’t have a problem with it.” — Chris Tarbell [14:24]
“There's a little bit of libertarian inside of me, bro... How do I know the government is targeting drug ops, and not a journalist's home network? Who makes that decision?” [15:49]
“Do I have a problem when they abuse civil liberties? Yeah. We need to figure that out.” — Hector [17:44]
“Shout out to the Dutch. Shout out to the Canadians. Now, I’m gonna pay attention to what other countries are gonna follow suit.” — Hector [20:43]
“His activity could be tied even behind a VPN... people were aware it was a thing, but hadn’t seen it until this indictment.” — Hector [37:52]
“As much as I love my country, we have micro-monopolies... millions of Americans still on dial-up in 2026. Starlink works, but basic internet access should be a right.” — Hector [47:25]
“Let’s make it free. Why not?...It’ll be just a cursory assessment, not a full pen test. You enter your domain, we scan and send you a report.” [06:02–06:58]
| Time | Topic | |-------------|----------------------------------------| | 11:30–18:00 | Canada’s CSE offensive against cartel drug websites | | 21:15–25:49 | Virginia geolocation privacy law | | 26:35–32:54 | AI “LLM Jacking”/cloud exploit risks | | 33:17–41:19 | Scattered Spiders arrest & tech attribution | | 41:35–45:32 | $10M bounty on FSB hackers targeting Signal/WhatsApp | | 45:38–54:00 | Switzerland vs. U.S. internet infrastructure | | 05:32–10:17 | Safe Hill free service announcement |
This summary covers the critical news, expert commentary, and listener-relevant takeaways from one of Hacker and the Fed’s densest, most wide-ranging episodes.