You're off Google you're done with Google you're done. I'm watching Google but but just also added this also affected Groc as well. Yeah, it's probably gonna affect any other similar platform. Yeah, you know what? I'm gonna I'm gonna get off the internet. That's what we do. Hector Montseger was responsible for some of the most notorious hacks ever committed. Beyond a special agent Chris Tarbell. Hackets and FBI informants participated in some of the world's most infamous hacks that caught up to $50 million in damages in life in the shadows cyber attacks on the rise. Welcome to hacker in the fed. I'm Chris Tarbell former FBI Special Agent working my entire career in cyber security. Join as always by my friend and podcast co-host Hector Montseger. Hi Hector. Hey, how you? I don't I'm okay. Hector's a former black hat hacker who once faced 125 years in prison for as many years as hacking under the code name Sabu. Yeah, our stories collided in June 2011 when I arrested Hector but that I convinced him to work with me at the FBI. Hector's now a red teamer researcher cyber security expert and co-founder of Safeville. Yeah. Hi everybody. Hi Chris. How you doing today brother? Hey, give me your best white man impression. I love I love when people sound like white people. I can't do it brother. I'm not a good impressionist, you know. Where I do? Hey, hey, don't buddy listen. I need a little big cream cheese. That's in New Yorkers. I don't know. You want me to hear me do a Puerto Rican? Yeah, no, no, no, no, no, no, fucking way. Go ahead, buddy. Got this. The problem Puerto Rico. I'm gonna tear right now. The Puerto Rican accent is stick. If it's like a tone from the island, right? And then it was like someone from here that was born and raised here and they grew up with their grandparents and their mother's talking, you know, with the accent. Their accent is so ridiculous. That's when they speak English or Spanish, you don't know what the hell they're talking about because it's like a mix of Spanish. And so yeah, if you would, if I would ask you that question, hey, you know, give me or rather, I would add that request 20 years ago. Hey, give me like a Puerto Rican accent. You can probably do like a John Leku, Zamo, I remember when he should do the, remember John Leku, Zamo, the comedian. He did a one man show. I loved the years ago. Yeah. Yeah. Well, in that one man show, he does a lot of that, like, Puerto Rican accent stuff, right? That doesn't really exist like that no more, bro. Like talk to like the new generation of Puerto Ricans, Puerto Rican Americans or whatever, or descendants of, you don't have that shit. Oh, that's bad. How many do you say so quickly? You know, it's a kind ofization 2000 years of this and another 45 years of that, you know, how that goes, bro. No, I don't. No, spread, yeah, you don't. That's right. I'm an American white guy. We got nothing like that. Come on, bro. You know, from the old country, man, you know, no country, I'm sure you know what we talked about. You've had a good week. What's going on in a safe, I think, fun. It's been a good week. It's been a busy week. I would say the last week, a lot of a lot of the conversations were around like, you know, what's going on in the world, you know, specifically to like, you know, specifically to like cyber security obviously. And what are we saying? We're seeing things like supply chain attacks, specific to libraries, specific to like extensions or even specific to like, you know, cold editors and third party cold extensions are cold, you know, apps. People like to call vibe code these days. That's fine. But then, you know, we're seeing a lot of attackers, aviservies getting really use success against those kind of users. So that's, that's one. Now, where where we come in for that is, you know, with our really badass like threat intel feed, specific to like info dealers, way more to cast that. We're able to see when, you know, if your employees are getting hit by info stealer by means of a supply chain attack and then, you know, we can alert you. So that's, that's one component. But, but then you have the other, the other issue Chris, which is during the last week and change, we can some time. You had some next JS reacts for the abilities that came up. They even call that they, you know, you know, people give names at exploit or vulnerability class, right? Or vulnerability. Just to get these people. Yeah, just to make it marketable and accessible to the layman. But they're, they're calling it reactive shell. And so reactive shell. What's, what's dangerous about it is that how prominence and extensive in terms of findings. There were literally like in the beginning of when the vulnerability was disclosed, there were like tens to 100,000 servers online with the vulnerability. And then it just kept growing and growing and growing. Nothing has slowed that down by the way over the last, you know, we can have. So for us, what are we, what are we doing to deal with that? We're looking at, okay. We've been, we've been really invested in like finger print capability. So when we're engaging a client's network and we're documenting their assets, we're fingerprinting those assets. In the event something like this pops up way would to like, you know, do a super quick select query search and then identify all our customers that may be vulnerable. So yeah, so I'm obviously constantly watching the news, looking at patterns, looking for vulnerabilities, infectious being exported. And then trying to like improve, you know, what we're doing and add that capability to the platform. A lot of cyber's that's, that's for sure, a lot of hacking going on too. It's pretty well. Very different from my week. I had a very strange week this week. And it was very close to the holidays as always gets weird. So my Monday started off with a film day commercial for a regional grocery store food lion for those on the East Coast. Is there from like North Carolina, through like New Jersey and all that. There's food lines. So I did commercial for them a Monday. And then on Wednesday and Thursday. I hosted a concert. So it's a concert benefit series for for the pantry and we had an artist. He's a he comes every year. He's a he's a in the country music hall of fame. So he does like like more. You know, country and gospel and that sort of thing. So Christmas music too. So it was nice. It's very very beneficial to the pantry and helps the community. And then Friday I went to a concert that was inside a cave. Get what the hell. It's like EDM. No, it was a flute. There was a flute a tire flute band and they played Christmas songs. No way. That sounds amazing. It was like a 20 minute walk back into this cave and you sit down and put on like a 30 minute concert back there. Did you have like Yani Papa with his flute? No, Yani didn't make it. But it was all ladies. All ladies in the world. Wow. Look at that. I love it. And then Saturday morning we had a we hosted a Christmas breakfast with Santa. So at the community center. We had all the kids and their families come and have pancakes and get to have a picnic. It sounds so beautiful. And then we put up big air slides and all that. So it's really good for the whole community. And then I went for my normal Saturday hike up in the Shenandoah of the Shenandoah National Park. So I've had a hell of a week. Wow. That does sound like a hell of a week. It's a beautiful week. It's really cool things this week. Yeah. It's a good week. So I'm hoping this next week is the same. Yeah. Same but different. Same, same but different. That's right. That's right. So that's my boy Suge. You know, he's on YouTube. Yeah. That's his famous phrase, by the way, same, same but different. Yeah. You ever watch those videos? I do. Yeah. Yeah. I love those guys. Those guys are the best. That's it. You know what? Man, let me tell you something. That's such a blessing. You know, to be able to be involved in the community and to be able to do those cool things. You know, I, I was a big believer in community. You know, a big, big room. Local community and all that. It's fantastic. Yeah. Oh, yeah. And so, you know, I'm hopeful that to be involved in that, you know, at some point in my life. Because he in New York City, let me tell you guys something. I didn't even know my neighbors when I lived in New York City. Yeah. New York City is very lonely. It is. Unless you like to go out to the clubs and bars every weekend. And then yeah, you get to meet that community. But what really got phased out of New York was like the block parties. I, I terms you guys watch any old movies with New York in the 60s, 70s and 80s. There's always like a block party in my old neighborhood. The low east side. We still have it. The amusey, you know, amuse party that happens like every year. And people love it. They go there. They hang out. The kids are there. It's, you know, it's kind of like a like a St. Generals kind of thing. Right. But they do it a little Italy. But where where I'm at, where I'm at these days, it's not that that doesn't exist completely phased out. It's this and it's crazy because I'm in a historical place where that used to be big. And like you implied Chris, you know, a lot of that community stuff is complete. You're certain New York City is surrounded by eight and a half million strangers. And like you're taught to keep your head down. Don't don't get involved and don't don't go to see your neck out there. Yeah. That's one since moving. I just one thing I really love. I love being part of the community and just being around things. So it's nice. It's beautiful. Well, listen, that's a blessing. Congratulations, bro. Let me tell you something. You are doing something that a lot of people would love to do. To do myself. To big shout out to you, big shout out to your fans. I know your family's always a part of that. And I'm looking forward to hear more. I know we still have Christmas. We still have all new years coming up. Would you slow down by Christmas New Year's? Are you still going to do stuff for the community? We keep going.
we go all the way through right through Christmas. We take a little bit between Christmas and New Year's we back off, but we are doing a toy drive now for the kids. All the kids that come to the pantry get toys and we spent lots of money to buy all these toys to give out of the kids. 'Cause we want to make sure everybody has a nice Christmas and a nice holiday and whatever they celebrate. So every kid that comes in gets a toy. Used to be like six and under and we change at this year. We said every kid, every kid that comes in, no kid is going to come in with his older brother and no older brother leaves sad. So yeah, yeah, listen, no kid left behind, man, I'm with it. You know, that's a whole different, no children left behind. No children. I think Uncle Jeffrey taught you that one. No, no, no, no, no, no, no, no. That was Uncle Obama. They'd talk to me about that. No, it was actually Bush. It was Bush too. No child left behind. That's cool system. That's right, that's right. Shout out to Bush. With Star Wars program, they already laughed at. But now we need it. Look at that. See how life works. So President Bush, if you listen to this, you know, he is. I believe that you president Bush and I was a laughing at you. He's other guys. You know, he's painting now. So a nice picture of painting, nice bush painting of saboo would be great. I have his book. Yeah, some half-hired fat art. Listen, brother, that would be dope. I mean, I would love to commission him for that. Like like something of me and you, you know, hanging out with some Mr. Tolls and some reindeer, you know? Probably definitely kissing involved. But I do have his book and he's actually not bad, man. He's a pretty good painter. Yeah, he made some beautiful art. So look at that. Guys, we've got a hell of a response for our free show. Remember, it's January 29th at 5.30 p.m. Eastern. Sign up. We put a link out on LinkedIn. We put a weekly show reminder, the form to sign up for the episodes on there. If you guys don't have LinkedIn or can't get to it, just shoot us an email. I'll send you over the link. We'll email you the link. Really excited about doing the live hacker in the Fed show. Hector and I have been doing it for Safe Hill, for Safe Hill clients for a few months now and get really, really positive returns on that. They're fun. Yeah, people love it. You know, it's like a hacker in the Fed episode, but you get to ask us questions in the middle of our stories. So you get to interact with us during the stories. And, man, can you distract Hector with a couple questions that pop up, you can get him off on a tangent and he will go. So January 29th at 5.30 p.m. Eastern, just reach out and we'll get you signed up to be a part of that show. Well, listen, I want to give a shout out to Don C. He's always at those events. And my boy is always blasting us with questions. He's always hand us up with some thought provoking, commentary, very big supportive hack in the Fed. He's probably listening to this right now. So Don C, you know who you are. Thank you. Once these live shows really start taking off, I'd even think about giving Don C a third mic. Let him just interact with the questions. Oh, yeah. And you know what? Honestly, if you haven't met him yet, you know, like a person, when LinkedIn or whatever, he's been in the IT space, director space. He's an executive. He's been doing it like 30 plus years. He's like OG. Don, man, he's time to retire, man. The retirement life is good. Yeah, right. It's not your retirement. Actually, no, right now is for a new CISO position. So you guys need a CISO. I got the guy for you. All right. He'll be able to link to, um, yeah, man. I love those events for all like those questions are fantastic. So yeah, hit us up guys, find our LinkedIn post or hit us up. And we'll get to the link to sign up for that. And so shout out to Alana for putting that all together for us. Shout out to Alane. She's awesome. Let's get on to our stories. We're quite a ways into the episode before we've even started talking about the Cypress. So there was an atomic macOS stealer and Amos stealer that exploits AI trust malware delivered through chat GP and Grock. So threat actors have now launched a sophisticated social engineering campaign delivering atomic macOS Steelers by poisoning SEO results with malicious shared conversations on legitimate AI platforms chat BT and Grock. They're keen macOS users into executing terminal commands for systems cleanup. So interesting story. I think this kind of sort of has less to do with AI and more to do with the mobile times with campaigns. Yeah, but they're using the trust people have in the latest chat GBT. So what they're doing is they're creating a conversation in one of your favorite AIs about cleaning up your Mac systems. And then they're posting that as a result of in a sponsored Google link. So Google's getting their pocket a little rich through this malvertisement campaign, which you know, I'm a little sensitive to on that whole thing. Making it look like you're actually cleaning up your computer with these commands, but they're distributing this sort of the terminal commands. Sure. Back door. Yeah. And people are copying and pacing it because it looks like a legit conversation. It looks like someone, you know, went into the AI. Hey, how do I clean up my Mac? They go through that conversation, the instructions and then they copy and paste and dump it. And now you have all your shit stolen from you. Sure. Yeah. Well, listen, you, you yourself, you've had, you, you spoke it on this topic a lot when it comes to advertising campaigns, poison like Google search results. And we also know why this continues and why these kind of things. Because, you know, continue to move forward without, you know, very little interference from the parent company hosting this poison. They're making money and they're going to continue to make money. Making lots of money on the foot. Shit load of money. And big shout out to the hunters. The hunters is a really cool company. You know, they're, they're really good with like identifying, you know, threat exposures and doing a lot of good research. This right here is a great research. And if you guys want to read this article, just go to the hunters.com. Take a look at their blog. The recent blog post the Amos dealer chat to be tea, Grock A.I. Trust. It was fantastic about this Chris. What I really love about this is like they did, they connected the screenshots together. So like on the blog, they show you, here's what we asked chat to be tea or what was asked of chat to be tea. Here's what chat to be came back with. And here's the actual search that we did on Google to find the results that led to the compromise, which is, hey, you can just run this command and it'll clear up your space on your macOS when reality is just you infecting yourself with malware. And these are usually info dealers and so on. Yeah. So the information they're taking, they're going after, they're going after, you know, key chain password, browser credentials, cookies, cryptocurrency wallets, system files, Wi-Fi creds, they're essentially establishing root level persistence. And there's no encryption, no ransomware. It's just info theft, you know, for the whole thing. And they're doing it because they're violating your trust. Your trust in Google returns, your trust in AI, your trust that, you know, this conversation was, is legit. And you Googled it and it's coming up. And so, you know, I personally think, you know, well, obviously the guys perpetrating are the bad guys. But secondary bad guys is Google for one, allowing to happen. And two, they put this story out. The story's been out for a while now and Google has yet to take it down as of Thursday recording, as of today, the December 14th. They have not stopped this attack. That's ridiculous, brother. That really is. You know, and that's, that's the thing that that upsets me is that, you know, we have these massive corporations, the Googles and the Microsofts of the world, that's, you know, they claim security, they promote it, but then you see things like this, right? You see like that. And Google has such insight. I mean, they can tell you exactly, you know, what the accounts that are attributed to, you know, the posting these advertisements, malvertisements, you know, even if they're using layers and layers. Google has such insight into what's going on on the internet and collecting so much data on every different system. They'll tell you what other systems, what other accounts are being used on that, that same system. The collecting IPs, like the insight they have makes the NSA blush, you know, you know, it's crazy that they could put a stop to this. Especially, so again, could they stop every single one of them that happens up? No, it's whackable. They come up too fast. But these, these were hunters is putting out the information of how this is being done. And still, letting it persist is insane. Yeah. And it just keeps going. That's the problem, right? So right now we're covering the story. I'm hoping that by the new week, it's sorted out. But the reality is, like we have no idea what the number, in terms of damages, we're talking about here. We have no idea like how many of you have been affected. You know, I'm looking at the URL. So what are the end points that they were using for? I'm on it right now. The URL that hunters put out in their blog. So the server exists. The domain is still re-resolvable. The URL for the payload is quote unquote dead, but the reality is they probably have some sort of redirector in places, which is common for dealing with like anti forensics. Oh, I'm sure they rotate that all the time. I sure that rotates off hourly. Oh, yeah. - Yeah. - It's way too easy to rotate that part. - That's true.
as a fact. Yeah, wow. So, but any guys, if people are trying to get you to do something that you don't feel, you feel as questionable and copying and pasting a command into a command line on your computer should feel questioned you unless you know what it is. You know, you should know exactly what the command is doing before you hit go. You know, command interface on a Mac is pretty attrusive into your your your system. I know you're trying to do best. You're trying to clean up in this one. They're trying to get people trying to clean up disk space because, you know, again, bad guy, you know, bad guy Apple is hitting you up with these you're running out of cloud space, pay for more cloud, pay for more cloud all the time. So you're like, oh shit, I don't want to pay for more cloud. So let me Google how I can clean up my Mac. Well, now these guys understand this, these and they're doing this SEO poisoning and putting their returns at the very top. And then, again, I just trying to hit it over and over again, they are exploiting your trust. And now, part of that trust is an AI. And I'm sure this headline, you know, the headline is talking about exploits AI trust and because AI is a big keyword. They're just getting people to try to click on anything really with AI. And this is loosely based on AI. This is more, you know, SEO poisoning and malvertisement. But guys, don't do things that make creep you out, especially on the internet. Yeah, don't run random commanding terminals. That's insane. To if does bring up a point Chris and that is, you know, when you're leveraging a chat, GPT type interface, right, whether it's chat, GPT or clog or whatever else, Gemini, you're trusting that's those data sources. You're trusting that platform to provide information that isn't going to be, you know, rodeos or or arbitrary nature. But when that interface or that platform is trusting third party sites, right, with no validation verification or nothing, then you have to think, okay, can I really trust these platforms? Can I really trust these services? We know about hallucinations. We've seen hallucinations all over the place. Absolutely. I get them all the time. But now, if you're trying to automate some sort of technical command aspect, whatever task, well, you can no longer trust that either because hundreds proved that that information could be poisons from a third party. But they're not even poisoning. This is a recorded conversation with their, with their showing here. They're, you know, they're showing, I'm sure they're able to prompt the AI to regurgitate what they're looking. They can simply put into the AI, hey, let's have a conversation. I want you to say this, I'm going to say this and just reprint it out. So it's inside a like a chat GPT prompt. You can get, you can get AI to say whatever. Now, I don't know if you get AI to say the end word. I don't think it will. But it'll go, it'll give you a command that includes a, you know, encoded base 64 command line that is malvertisement. It is a link to something that's got to fuck your computers up. Yeah. And if you're using the agent mode where it has to go outside of us like trusted verified, you know, a data well, then yeah, you're opening up the potential for this. And so maybe open AI and other companies have put more warnings on this kind of stuff like, hey, by the way, here's some commands, but we got this off a third party site. So just, you know, heat warning. The reality is don't want shit. You know, that's coming from anything you're not verifying yourself. But even if the AI put a warning here, it could just be edited out. I mean, these are again, just recording conversations. The bad guys could simply just change it. Yeah. Well, you just, you just scared half the audience of death because they've been using chat to the enterprise for like a solid year. And now you're telling them, hey, we can't trust us out. But anymore, as we tell it, well, you should always know your sources and trust your sources. But again, I think the bad guy in here is your Google returns. Like you, you know, that's where that's where the flaw in this system is. You have to trust where what Google is giving back to you and realize those people are paying, you know, why would someone, why is the first return in AI conversation, recorded conversation? It even says that, you know, this is a paid sponsored advertisement at the top of the page. Why would somebody paying for that conversation that you put at the top? Because they're trying to get you. They're trying to screw you up. They're trying to confuse you. They're trying to manipulate you. They're trying to victimize you. You know what brother? Yeah, I'm convinced. That's where I'm at. I'm. You're done with Google. You're done. I'm watching that. But just also added this also affected GROC as well. It's probably going to affect any other similar platform. Yeah, you know what? I'm going to get off the internet. That's what you're just asking Jeeps or Binging and think from now on. That's it. Oh, no, Bing. Oh, my God. I rather stole malware at that point. Jeeps. Wow. By the way, for the audience, we give you guys a visual. Chris is wearing an awesome natural shirt. And I'm wearing an iron maiden shirt. Look at that. We're two cool guys. But I'm also not wearing pants. So I'm wearing pants. I'm wearing sweatpants. Oh, wow. So Nike text. Gray sweatpants. Oh, yeah, I just love the gross ones. You got the lines. Yeah, I love the Nike text, bro. But now I got a beige one. I'm, I'm, I'm risque, you know, all right. I like it. Guys, be careful. They're trying to trick us. They're trying to trick all of us. They're trying to steal our shit. So be careful. Hector Home Depot exposed access to internal systems for a year, says a researcher security researcher Ben Zimmerman discovered a leaked get hub personal access token belong at a home depot employee exposing access to private source code repositories, cloud infrastructure, order fulfillment, inventory management systems and code development pipelines for nearly a year. Can you imagine this? Oh, yeah, we, we see this happens a lot more than, than we think. And, you know, the cool thing has been a boy here, Ben Zimmerman reported it, got a resolves, but the thing is, but a year of being on GitHub or whatever platforms of developers uploaded the code to judging by what I know from different security companies, researchers and so on, they're constantly and automatic and scanning repositories for tokens. I wouldn't be surprised. First, can you, sorry, can you go down and sort of break down get hub personal access tokens and why like a major corporation like this has, has things sitting on GitHub and why they'd use it? Yeah, so for those of you that are not super technical or aware of what GitHub is, it's a, it's kind of like a community oriented repository or a platform to hold repositories for code and projects. A lot of companies use it and they use it right, they have policies in state. Hey, we're going to open source one of our products and we're going to release it to the internet for free so that any developer could use it and these are usually libraries and, you know, extensions and so on. And then you have hobbyists and enthusiasts, people that want to just learn to program the use of GitHub to kind of hold their projects. Now, when you look at something like a personal access token, we're really talking about like an API token that gives you access to a developer's account and that's usually a thing for the purpose of automation. You'll plug that into maybe some sort of script you're creating that, you're hosting on your enterprise network and that script checks to see if, you know, you have a new repository and you update your repository and pull the code from the repository. Now, a lot of these access tokens have caused tons of problems in the past because they're very broad in nature, meaning that once you have a token, you essentially have a backdoor to the account and you don't need a password or multi-faculate indication to access the content of that account, settings, permissions, repositories, code, configurations, etc. So that's kind of where we stand with GitHub, access tokens. There are some websites, some companies that do have like access controls where they say like, hey, we're giving this API key, right, or just token and then you can set read permissions, write permissions, etc. But not in this case. In this case, the token that the researcher found gave like card-blank access to everything, you know, associated to that GitHub account, associated to home people. Is it clear that you're having just a user in your password and not an MFA or a two-FA on it? It's like a skeleton key. You buy a big house, you have a whole bunch of keys, you buy security cameras, you do all that good stuff, you invest a lot of money in it, and then one day you find out that your neighbor who's been there 30 years before you, so you know, they're up there, you lock yourself out the house and they say, oh, I've got your Chris on the inside and they'll let you in your home, you know, how the hell is this person just letting me in my home because they have essentially a back door to into your home. So I definitely agree, it's a screw up by the developer to have that key on there. But is it a screw up on Home Depot allowing the just token access to the GitHub? That's a great question. Now, we don't know what the policies for Home Depot and the developers aren't. One policy, if it didn't exist before today, it should exist tomorrow, which is if you are a developer of Home Depot or
or a contractor, and we provide you keys to our internal repositories, which are hosted on GitHub. You cannot publish those keys otherwise consequences. Now on paper, it is what it is, but you're basically telling your developer, "Hey, by the way, now we have cost of firing." You violated our policy. Those are the consequences. But the consequences for Home Depot itself is now there's one thing that you read there. One of the things they got accessed by the potential adversaries, which was order fulfillment. Those orders. Chris Tarbock could be in there buying a fucking drill on a Saturday. We don't know what that data looks like. And so now that's a breach of sensitive information. And so now Home Depot is open to all sorts of lawsuits, class action lawsuits. This was a massive blunder and what they could have done and what a lot of companies do, Chris, they'll take development and they'll just bring it in-house meeting that they'll still have GitHub, but they'll have like a GitHub enterprise installed and configured within their network. You can only access that from a VPN, right? But a big bottom boom, you've minimized the attack service. But when you're using the public version of GitHub, things like this happen. So just a clarification on the whole thing. The token was refoked and they've not seen any access of data exaltrated and your exploitation. But there is potential for a spline thing check and code tampering. I will say that you bring up a big thing with order fulfillment. They may be part of now a PCI regulatory check because PCI that controls credit card data. And there's a lot of requirements. If you do over a million dollars in sales on your website, and I'm going to guess that Home Depot probably does. Yeah. That's going to open them up to some sort of PCI validation or system check here based on this. But not only that, you know, our guy Pete Hegg said he's put very specific requirements. He said very specific hard requirements on federal contractors. Home Depot is such a massive business that I wouldn't be surprised if they're a federal contractor by means of logistics. No, I'm trying to blame Vima and all that. Exactly. Something like this could potentially lead Hegg's have to be like, you know what, we're going to ask Home Depot from federal contractors providing logistics or whatever to our federal agencies like FEMA. Like this has really massive consequences that now they're probably having internal meetings about how we're going to move forward from here. And that's for the guy that leaked the key for over a year. I feel for it because mistakes happen where humans were. We fuck up sometimes. Come on, Chris, we know that. Now if it's proven that this guy is just negligent, then yeah, he's in a bad position. He maybe gets sued by Home Depot. You were talking about it earlier. I think I interrupted you about them searching through for tokens like this. Sure. How is that done? Is that looking for specific tokens? You have known tokens and it's looking or is it looking for any sort of tokens? Like, like, how was this not found for a year? Even if Home Depot is not looking? How was it not found by anyone else? So here's what I know because I've done it, right? And I do it for everyone on my customer. So let's say you're my customer, you have to say Phil, and you say, hey guys, we need to like be on top of our credit exposure. Cool. We're going to find or eventually going to find that you have developers and you develop just get up. And then those developers are constantly uploading, removing, modifying, trading code back and forth. Some of those repositories of public, some of those are private. And we're searching through all the commits, all the uploads essentially quote unquote, they're called commits. Two of these repositories, two of these code bases. And we're looking for things like tokens, passwords, usernames, domains, host names, IP addresses. Those are all sensitive in nature. And usually what happens is you create like a reg X, regular expression filter, kind of grab all that stuff. Now, it's possible. And I want to touch on that at a second on the scanning part. But it's possible that the personal access token used by GitHub wasn't being searched for by these researchers. Obviously, Ben Zimmerman was looking for that because he found it. Okay. It's also possible that they found the researchers like Ben Zimmerman found so many tokens and it was kind of like noise. And then Ben just randomly looked through his list. It's like, oh, you know what? I checked this one. Oh my god, look, it's gold. Right? So there's so many tokens out there and then find the one that actually works is like finding a junk drawer full of those keys. And you have to check each key until it finally fits the lock and it opens the door. Yeah. And so to touch back with the scanning portion, there are security companies out there who a lot of their business and sales come from searching GitHub, searching Bitbucket, it's another one, another big platform, searching like all these different like repository websites for tokens. And then reporting that token to the customer in hopes that it converts with sale, right? It is what it is. Hey, by the way, we found this really bad token on your developer's GitHub page. Here's a link to it. By the way, we can do this for you 24/7 and then you know, whatever, right? The fact that we have some of those companies searching GitHub for tokens and again, when we said the money found for a year, it's so bummed out to me. Like, that doesn't make any sense to me. I feel like, you know, somebody found it and they're like, I'm not touching that. Maybe it's been being exploited for a year. And it lights us up the article saying that yeah, we have no evidence of, you can't prove it that you have no evidence of. Just because there's not a log of it doesn't mean it didn't happen. Like if a hacker comes in and deletes all your logs, you then can't say we don't have logs of it. I guess you can't. You can't say we don't have logs of us being hacked. You can honestly say that. Yeah. Well, or maybe GitHub's logging or audit log is not that, you know, extensive, right? I mean, I haven't checked it a while. I got, you know what, tonight I'm going to look at GitHub. I'm going to set up a repo. I'm going to put this up and create a token. I'm going to generate a bunch of noise. And I'm going to see what shows up in the logs because I'm curious how this was not found knowing. I know there's at least a dozen companies searching GitHub all day or date for tokens. So this is an audit. Guys, this is an outlier effect. So just keep in mind that this, there might be more to the story than that. We'll, I guess we'll see the next few weeks. The United States government has indicted a state sponsored threat actor named Victoria Dubrov. So she's a Ukrainian nationalist 33 years old that was indicted in two separate cases for supporting Russian state backed activists groups and involved in destructive cyber attacks and did us on critical infrastructures worldwide. She played part of the role was a supporting role with social media, video editing, misinformation and money management. But she assisted GRU officers and the group has claimed over 99 attacks since 2022. Her activities for the indictment were between 22 and 25 and it was just recently unsealed. The locations of the attacks were global all over the world, including US, water and meat facilities, Netherlands, water park, election operations on biotelogram, damage everywhere with this girl. But it looks like she was just part of the social media and the editing group, not the actual hacking part. I would say she was the topiary of the group. Yeah, I guess so. I guess you can call it that. This story was that. This story was that. It seems like a nice young lady that obviously got involved with the wrong crowd and she became a traitor along the way. Obviously, it gets her own people, her own country. Knowing that she's part of Ukraine and she's Ukrainian, living in Ukraine and helping the enemy is kind of crazy. So I'm sure that Ukraine is what I love to imprison her. But she was involved in so much damage against the United States that they exordated her. It's going to have to deal with some hard time here in the United States. She was involved in a lot of bad activity. Regardless if she was an actual threat actor, technical capabilities or she was doing the propaganda and media stuff for them, she was still part of the conspiracy. Like I said, yeah. She's facing 27 to 32 years and the State Department is also offering a reward for up to 10 million dollars for co-conspirators. Again, I told you on the Patreon episode that I'm going to guess that this is pressure on her to turn over what evidence she has against her co-conspirators. It sounds like they want her, the co-conspirators much more than they want her. It sounds like maybe she didn't give anything up and that's why she got indicted. Yeah. Well, it could be or the information that she had wasn't enough or she was lying to them to the law enforcement and they were in the quarter on it. Who knows what she's given up so far, right? But what we do know is that the other part of it though is in order to get her sent over here, she did have to be indicted. They wouldn't just send her over when I was at arrest. Yeah. Well, I was reading through the story, I read through the articles, I read through the tweets because VX underground had a good write-up on this story and they linked back to the indictment of documents and so on. The probably you have here with sort of like this is that's. You know, it sucks because I remember, you gotta remember, when I was an aviator, it was before Bitcoin, before all of this nonsense, ransomware and all that. But the thing is that she knew what she was doing was wrong. She knew that eventually she would get caught. She knew that Stagen, Ukraine would mean that eventually she would have to deal with the consequences of it. She knew after they started heating scatter systems and modifying things of water and attacking schools and she must have known, hey, by the way, I'm gonna get rocked for this. There's no way that she could complete ignorance on this one. And it was over 99 campaigns. This is like a multi-year issue, bro, like that. - Maybe it's her boyfriend. Maybe she's her boyfriend. She can't die with her boyfriend. - Maybe it's a boyfriend. - But man. - Hey, listen, love makes us do some wild things. - Sorry, I've been doing it. - 'Til death do us part, come on, that's crazy. - Now, no brother, ish, nice. - So we'll keep an eye on that. What goes there, she's got a trial set for February, but we'll see where it goes with it. So. - So do you see the UK Information Commission's office that find last past 1.2 million pounds, which is $1.6 million for their security failures that enable the unauthorized access to a third party cloud backup database during the 22 breach, exposing personal data of 1.6 million UK users. So we covered the story quite a bit when it happened, but now the regulators get involved and they're gonna want their peace. It seemed to me this price was a little low. - It's about a dollar per victim in the UK at least. - Honestly, this is what we talk about Chris, that the accountability in our country, and the UK, we talk about the UK, kind of doing the whole risk-slapping thing, when it comes to the adversaries. Yeah, I feel like it's too low as well. And what, in fact, well, you and I are talking right now, we're having a chit-chat and we talk about our t-shirts and what we're doing next week. Last past year's made the 1.2 million pounds, right? During that, that'll, two minutes session. So what's the point of this? This is not accountability. This is, hey, we acknowledge that you messed up, and we want you to acknowledge that you messed up, but let's get over this. Let's move on from this. - It's attacks, you're taxing them. And how does that affect the users in any sort of way? How do they recoup what they've lost? The crypto keys and the access to all their special accounts that were taken by this, you know? - Yeah, well, remember, as a result of this, compromised a lot of crypto holders were compromised. People lost access to the wallets. It lost access to like, you know, co-storage wallets. I wouldn't be surprised if the, in terms of damages worldwide is over a billion dollars from this breach. I would love to know what's the damage for these 1.6 million users. And then do a comparison between that damage for the 1.6 million residents of the United Kingdom versus this fine. And why is, why it is so low? - Yeah, and-- - Yeah. - The Arnold even go into the calculation. I'd love to know what the calculation - Yeah, I agree with him as to how they came up with this number. - Yeah, no, this is wilds. In fact, it even obsessed me. It obsessed me because it's like, what the fuck is the point? At that point just, just, you know, after an apology, a public apology, that's it, you're done. - That's it. - Don't forget about the credit monitoring. You get six months of free credit monitoring. So sick of that bullshit. - Yeah, six months of credit monitoring, the credit monitoring alerts you after the fact, after you've already been breached. So what the fuck is the point of that as well? You know, this is turning into a fucking rat, Chris. You're kind of pissed me off here. - Some damn lawyer came up with this years ago and every judge sent them and said, "Yeah, that sounds good, credit monitoring." You know, and they're probably getting kicked back from the credit monitoring companies. 'Cause who's else is paying for credit monitoring except for people that suffer from breaches? You know, the companies that have a breach, they just, they're the only ones paying for it. 'Cause now everyone, everyone has free credit monitoring 'cause these companies have paid for it and that's their only penalty. - I have yes in my life. And you know what I'm asking a lot of people, YouTube. We speak to thousands of people at a minimum, hundreds of people a year and at the maximum, if we have a busier thousand of people, you and I, I don't know about you. I have yet to meet anyone that's ever paid for that service. Out of pocket because they wanted that monitoring. Never, they were accident. You still body. - Can I tell you something? I think you know, bristers slightly off. - Wait, what do you mean? - You realize you're talking to thousands and tens of thousands of people right now. - No, yeah, you right. Ten thousand, tens of thousands of people right now. What I mean, what I mean was like, they've speeches, right? - Oh, presentations here. - All right, I'm just being sure that you realize that it's, I know you and I get caught up in this and we think we're just talking to each other. - Yeah, there's a bunch of other assholes out there listening to us right now. (laughing) Well, you know what, if you guys are paying for a credit monitoring, please who is the email, give us some comments. I would love to know, but I have yet to meet anybody that at the very least would admit it, right? - You know, I tell that joke at our speeches and that have people raise their hand if they were part of the, the, - As you matter. - As you matter, as a hack. I should also ask if they ever know it's ever paid for credit monitoring. - Oh, I get the same number of hands. - Crickets. - Well, it goes to so that that's, oh man, I would love to look at the numbers contracts rather. Or the companies that offer credit monitoring versus like who's actually purchasing these book, you know, services from them? And how much they're paying. I'm curious, I would love to know how much companies are paying for this. It's probably included as far as like insurance packages. Oh, fuck it, no, it's bad. It's always a gimmick, it's always a bamboozle. It's always something, the flip-flam, you know what I mean? Hector, we got a beautiful email this week. We got questions at hackerandthefed.com. I really wanted to share it with the audience 'cause it's great news. And so, you know, we're a community here and I wanted to share this community. So Jordan reached out to us. And Hector got back to him quickly. Before I even finished reading Hector and reached out to him. So Jordan wrote, "Good afternoon guys. I just wrote a few months back regarding transitioning over to the red team at my current company and was given great advice. As of a few weeks ago, my company saw my leadership potential and had promoted me to manager of our red team services. I still get to do all the fun day to day stuff, but it gave me a nice compensation jump and shows their confidence in me going forward. I wanted to say, thank you guys for all that you do. It really has changed my life. Also, subscribe to the Patreon recently as well. Love the extra content. Keep it up also. Keep it up guys. Also, best of luck with Safe Hill Hector. I hope you guys have a wonderful new year. Jordan, we are so happy for you. I love to hear these things. A few years ago, if you guys have been with Hector for a while, we had a guy who said it was his dream to work for the NSA. He emailed us and we gave him some advice. He gave us a bag and forth. Next thing we know, a couple months later, he let us know that he now was a member of the NSA. He got his dream job. He's doing offensive work with those guys. So we'd love to hear these stories. We'd love to hear that you guys are successful. And we've helped play a tiny little part, a pushy-do in the right direction, or even just giving you a little bit of advice that made your life more successful, and made cybersecurity better. That is very true. I gotta say, brother, I love it. It makes me happy to hear when there's progress and success. Especially when it's been emailed, it's a part of the community. That's part of what this is about. You and I first started the project as a way to hang out with each other, especially when we're with each other. It's a good way to dump on what we're seeing every day, and then it turns into, hey, you know what? Let's try to help these folks out there and try to do something with their careers and their stuck. So you and I used to do the entire episodes of us doing like Q&A, right? I mean, I had a Q&A on jobs and industry, and this and that. But shout out to Jordan. Very happy for us. I said, we're even immediately. Bro, I am so proud of stoked to keep it up. If the rest of you out there, we have to email up. We are on LinkedIn. This address, you know, asks us questions. We're here for you, you know. It's always my pleasure. And I'll wake up at 2 3 in the morning and see email there. I'm like, yeah, I got an email, I can respond to it. Your boy Hector's lonely, all right? Just send us an email. Just tell us what's going on. I got you. I don't even want to know how many dick pics you got in the last week after I asked you. I got about 11 dick pics. I did not want to see. Yeah. Well, thanks for sharing with them, you prick. Yeah, I mean, this is what it is, bro. You know, some of the word, we're nice. What can I say? This is some kind of the people out there. Guys, reach out to us at
[email protected]. Hector loves it. I love it. I love hearing your success stories, keep them going. Anything we do to help you. And I bet you, Jordan, if you hit a wall and need some help and need some advice, if you reach out to Hector anyway, he will help you with whatever advice you need to make you more successful at your job and keep your things going. Support us on Patreon. Jordan just joined Patreon. Loves the content. Today it was about mental health in cybersecurity. So we don't expect it. When Hector and I sit down and do the Patreon, there is no script whatsoever. We have not talked about anything. The stories just go where they go. The conversation goes where it goes. We try to bring it back to cybersecurity. And, you know, some days it's all cybersecurity. Sometimes it's mental health. Sometimes it's just us bullshit and talking about taming your balls. So, support us on Patreon. Keep it going.
free show free, keeping it commercial free. We hate reading commercials. We hate podcasts with commercials. So we decided to do it through the Patreon. And we may actually be including another new platform here in the new future, but we'll keep you updated on what we're doing with that. Five star reviews, wherever you get your podcasts, keep us going, keep the show growing. Share us on social media. We put out a LinkedIn post every Thursday morning when the new show comes out. Share us, repost that. Share us with your network. Put us in there. You know, join the hacker in the Fed LinkedIn page so we can get into your networks. Tell your co-workers, tell your friends, tell your wives, tell your boyfriends, tell your girlfriends, tell anybody to listen, listen to hacker in the Fed. That's right. And one last thing I'll say is, for those of you that may have heard or not heard on LinkedIn, that posted something during like Cyber Monday last week or the week before whatever was, kind of pointing out that, you know, hey, next year, 2020-26, you know, for those of you that are decision makers and you have to get a pentest or something along those lines, some sort of cyber risk services, feel free to hit me up. You're going to email us some questions at hackanddefeb.com or even add me on LinkedIn and I'm glad he pushed you upstream. But yeah, you know, it's going to be interesting a year and it's going to get very busy and time's, time's fleeting. So feel free to reach out if you have any questions on that. No commercials on the free show. You prick, they just fast forward to throw that. Yeah, it's just, I'm teaching. I'm teaching. I love what you do know about Safe Hill and I'm glad you guys are so successful over there. Appreciate you, bro. Friend, I've had a good time. It's a good show. Fun times. Yeah, man, that's usual, bro. It was always a great pleasure for me to hang out with you and spend a couple hours with you. It's kind of like my highlight of the week. I mean, I'll also be, bro. Perfect. So if you do end up traveling tomorrow, safe travels, and hopefully everything is successful. Sounds good, brother. Love and respect, brother. Talk to you later. Cheers. [BLANK_AUDIO]