So Madison Square Garden, MSG, who are also MSG sports entertainment, has operated a facial recognition and biometric profile system since 2018. "Hector Montseger was responsible for some of the most notorious hacks ever committed." "The honest special agent, Chris Tarbell." "Hackheads and FBI informants, participating in some of the world's most infamous hacks, that caused up to $50 million in damages." "A life in the shadows, cyber attacks on the rise." [Music] As always, everybody. Welcome to Hacker in the Fed. I'm Chris Tarbell, former FBI Special Agent at work in my entire career in cybersecurity, and I'm joined as always by my buddy, the Squeezable, the Huggable, Hector Montseger. "Hey, Hacker is a former black hat hacker, for those that don't know, who once faced 125 years for all his years of hacking, under the code name, Saboo." Our story is collided in June 2011 when I arrested Hacker, but then convinced him to work with me at the FBI. Hacker is now a red teamer, researcher, cybersecurity expert, one hell of a guy. Oh yeah, any co-founded safe hill. "Hey, what's going on, bud?" "141 episodes in, buddy. I'm trying to make it different every time." "He's 141 episodes. Look, I got all the great years to prove it. We're getting up there now." "141 free episodes. That doesn't even count the Patreon episodes." "That's true. Have you ever counted how many Patreon episodes we've done?" "No, no. I don't like to count. You know, they say you're not an expert until you do 10,000 hours, and I don't know where they're yet, so this may be an amateur podcast still." "Yeah, we're still NeoFights basically." "That's fine with me. I'm okay with that." "Do you think are we scriptkitties of podcast world?" "Yeah, we're the scriptkitties of podcast, for sure." "I've seen some of the infrastructure, at least from the outside of what other podcast is doing, and they have like automation with the website, to RSS feed, to like posting to this, from Twitter, and blogspot." "It's a whole thing." "You want to take it to that level? Are we going to start doing that?" "Yes, come on. Come on." "That's a bit much. It's just two buddies talking shit about cyber. It's not a, you know, that's a mainstream." "A niche podcast about cyber security and taining balls and former porn stars, and that's it." "Yeah, that's it. That's all it is, and that's fine. That's actually pretty cool. I mean, when you start listening to the other podcast in cyber, you're kind of 40. "The cringy, you know, and it's like, "Hey, change your passwords. It's change your password Wednesdays." "It's like, okay, I get that. We could do that too, but. Come on, man, let's talk about some technical stuff sometimes." "Did they get online and change their passwords together?" "Yeah, they do a whole thing. They're changing passwords. They're doing kumbayas." "Wait, wait. Are they using capital letters, numbers, and special characters?" "Yeah, bro, you know what they're doing is like, "Man, listen, you know, they got like a little cricketer out sheet, just like the dermis used to have, the OTP sheets, and do some one-time padding, and all this nonsense, and they still get popped anyway." "That, you know how it is." "Interesting. Interesting. Heck, I got some bad news for you, brother." "What's the bad news?" "I got a call this week from our arch nemesis, Alonus." "Oh, no. Not 'er." "I know. I know. It's her. It's always Alonus's fault. So we used to blame other people. We used to blame Will. We used to blame Phineas. No. Now it's Alonus's fault. You know what she told me? "What?" She told me that we do not talk about safe hill. We don't explain safe hill enough, and how great safe hill is for helping us out with the show, and helping us bring the show, and keep the show commercial free. So you know what she said? "I got to make a fucking commercial about safe hill in the show." "Oh, come on Alonus. What are you doing, girl?" "All right. Well, for those that don't know, that safe hill is a cyber security startup that Heck co-founded, and it was built by ethical hackers. Heck, do you guys have a platform card security IQ?" "What's going to secure IQ?" "I should probably get the name right." "Yeah." Alonus is going to have my nuts now. My TAN nuts, right in your hands. It's going to grab them and twist them. "Yeah." "I do like the Wu Tang." Do you remember the first Wu Tang clan album where it was like this whole scene where like, "Yeah, put his nuts on the dresser, beat him with hammer." "Remember that?" "No, but I've told you the story that met the man that was in front of me at Costco, right?" "Really?" "Yeah, you did, actually." "Yeah, yeah." "He was scoping out my cart, seeing what white people buy." "Yeah, he's a recon." "Yeah." "He kept turning around looking what was in my cart." "Now, just looking at him like, wait, let me love you." "That's a man." "He got that, was that fair something or milk?" "A fair life, yeah, no, fair life." "Not back then." "It wasn't around." "But anyways, secure IQ, AI-driven threat exposure management solution that finds the attack path into your environment and proves which one actually works before someone else does." Heck. "Yeah." "How are things at Safe Hill? What have you guys been working on lately?" "Well listen, but I'm gonna tell you something." It's been, and it's something that we've talked about on a Patreon where there's been a lot of research going on over the last, you know, two and a half plus years, not stop research, it's cool things, and so, we have our hands in a lot of different areas. One of the areas that I think would be fascinating for the audience here, and I kind of touch on it real quick, is always intelligence. Open source intelligence is actually pretty bad as you did a lot of that stuff when you was an FBI agent. You know, collecting, leveraging all sorts of different data sets, you kind of build out a story, right? And so, if you, if you, I don't think you've ever got to see one of our reports, our reports are pretty bad as. I have seen one before and I was very impressed. Yeah. Well, so, we, uh, what we've done here is, for years, we've done it manually, but you know, it's 2026. I'm going to automate some of that stuff. So, what we've done, we've been doing is building out like the automated processes to kind of gather information, kind of profile of assets or targets, and then kind of tell a story like that. And then of course, you have the humans coming in and validate that, right? So, that alone is my fascinating. We got a guy named Anthony, Anthony's been going really good with it. And we have a big physical pentase job with one soul, like we're actually breaking into the store soon. And that's part of it, right? We're doing the old synthetic report on locations, who's the sanitation company? You know, they coos the owner of the building at property and kind of tour that together and look at more suits for the plot. Tide together. There you go. It's pretty nice. Oh, that's interesting. I love it. Oh yeah. So, if, uh, if the hacker and the fed listeners want, you know, more about information about, uh, like, threat exposure management or the penetration testing services, how do they get a whole of you? Yeah. Well, listen, um, you know, I'm, I'm accessible. Feel free to send me a message on LinkedIn. Uh, good, you know, safehold.com directly or it could just email us at
[email protected]. And, uh, it asks us your questions, whatever you're interested in and go from there. If our listeners really, really hate this, can they reach out to a Lana's directly? Yeah, the cursor Lana's on. Questions that happen to fed.com. Oh, no. I'll forward it to it. Don't worry. Okay. Thank you. Thank you. Good. I'll be curator. You traveling all this week. Are you staying up in that, uh, smoky, uh, New York City? You know, the smoky New York City kind of overweigh from trying to go back, you know, back to the island. Oh, yeah. I'm trying. I think, I think soon, the next, you know, two weeks. All right. Is it, is it bad? Is the smoke bad up there? No, I got better. It was yellows. Hell, bro. It was like a shit yellow out here. Yeah, man. I don't think you can say that anymore, brother. I think it's, uh, that's racist. It might be. But I tell you, the knucks, man, they try to whack us. And for their troubles, for my trouble, they set me up a bottle of maple syrup here. -Oh, that's nice. -Yeah, man. And hey, I'm sorry, here's maple syrup. -Do you just take hits off that and you pour it out in pancakes? -Hey, listen, brother, you take some hits off of that. And this is liquid gold right here, brother. It's not like that fake, frugazzy syrup that we have here, you know? -Are you talking about Angel Mima? -Hey, listen, leave that to my mother. She's not the issue. The issue is the high-fuctose corn syrup and this nasty-ass shit would be. -Oh, that is true. That's true. My family was long-standing from Vermont, so we're Vermont maple syrup people. -Oh. -Is it liquidy too? Like the Canadian stuff? -I like a nice grade B. You want the darker one. -Great. -You think grade A is better, but it's not. Grade B is better. -Well, I've got to send you a bottle, bro. I'll show you. -Yeah. -I don't want you to get diabetes. That's why I don't want you to send you a bottle. -Well, close from the trees. What the fuck is this? When do diabetes-fucking-giving trees even diabetes come up, bro? -Yes, true. It's essentially like you'd be a vegetarian. It's essentially a vegetable if it comes from a tree. -Well, listen, we're talking about. I'm going to take a shot of this maple syrup for a quick. This is why I hear you get a-- put some hair in your chest. -Well, I don't know if you need that. I think you got plenty. -Well, I mean, I got the hair, but, you know, listen, I want the old school 1970s Greek chest. You know what I mean with the hair everywhere? -Oh. -Pour some of that on your chest. So it really sticks into your hair. -No, no, no, no. That's what they don't like. That's sticky. -That was my dad's worth nightmare.
hated sticky. He never wanted to be sticky. Yeah, that was his thing. Yeah, I can't do with that. So all right. Well, guys, heck and I had a fantastic Patreon episode prior to this show. So download, join the Patreon, help support the show. Maybe if you support us better, we can kick a lot of software. I don't know who knows. Chris Lahn is exactly help us out on the merch hacker and the fed.com. You're ready to get into it, heck. Yeah, that's awesome. One big freaking story this week. How to WordPress core bugs chained into a pre-auth RCE. First of all, explain that title to the people. What is what is chained into pre-auth RCE mean? All right, this is fantastic. So imagine a scenario where you go to a website and you go to the website and it's just there. It's like let's say Facebook or Twitter or whatever. And you see content and then you can log in and create an account. Once you create an account and you log in, that's also authentication. When we're talking about pre-authentication, we're talking about all we need is access to the website, not an account, no credentials, nothing needed. Did you have WordPress? WordPress is a blog and it's a blog platform has been used by people all around the world for, you know, I don't know, 18 years or more. Maybe I forgot what year they were created. I think it's probably longer than that. Right? Longer than that. Yeah. And so WordPress itself, you know, it's pretty, it's pretty mundane, man. It's just a, it's just a way for you to log into your website and just upload some content, post a picture to and then write a press release and move on with your life. What companies do is instead of building out like entire websites and creating a CMS account and management system, they'll use WordPress for that, which is fine. You have WordPress deployed by these companies. You have a pre-authentication and then you have the chains component. And what that means is that it takes several steps. You combine several different steps to create an attack path. And these steps are the vulnerabilities which you're essentially using two vulnerabilities to get past, you know, normal security procedures. Well, let's talk about, you know, what the attack actually looks like. Right? So when the CVEs came out, there was a reference to a sequence junction, pre-authenticated. So this is a require an account, for example, then you're able to send up a load, which then would allow you to, you know, execute a query on the back end database on that website. Now, the idea there for the next step, according to the proof of costume this week, the next step was to create a rogue administrator account and then modify a plugin and then be able to execute commands that opens up the doors to RC. Okay. So that's what that looks like. WordPress, unfortunately, has a history of terrible security when it comes to plugins, all sorts of SQL injections, all sorts of back doors, front doors, developer accounts being hijacked and malicious plugins being uploaded. But that's not the case here. The adversaries, in this case, the researchers just used plugins to kind of backdoor once you get a rogue admin account to then one commence. And are any of these malicious plugins can they be used against people visiting the website? Well, yes, so what could upload a malicious plugin to the website after they've compromised? Sure, they can. That would affect users, just regular users that come to the WordPress site. Yeah, it could, it could be used to target users for sure. I mean, that's not the basis for this, but it's solely a possibility. There are several possibilities from something like this. If you have an old WordPress site and it's compromised by means of this attack chain, yeah, you're going to have stolen credentials, stolen, you know, user information, emails, password, ashes, the attacker could upload malicious stuff. We've seen in the past where there's been like mass targeting of WordPress blogs and then they will injects like a credit card stealer. We've seen that a lot, right? That's a big one. Sure. In fact, with like we covered the Casper Tells website at some point last month, months ago, right? Yeah. Where he has some sort of CMS, it was breached in some capacity. And then someone uploaded a malicious skimmer to steal credentials of his fans who were buying like, you know, Whispery wherever, right? So it's definitely a real concern and a real possibility. So the vulnerability is now impacting millions of sites and WordPress has released a security patch to fix it. But the problem historically is most people that are using WordPress are low level websites. I mean, sure. Right? Yeah, that's not that's not understanding it, right? That's not I'm not putting it down, but it's not it's not like someone running a WordPress site most likely doesn't have a security team. Yeah, checking for updates. And is WordPress historically had automatic updates or is the site administrator by default have to go and apply these patches? That's a great question. So right now, most modern installations of WordPress do have automatic updates by default. That should be a thing. All right. But you cannot, you cannot rely on that, right? You have to any error any network error is going to break the update. So if anyone's listening here and you have a WordPress site that you the, but you deploy for your website for your company or something that you know, some hobbyist project or whatever family project, go check it out. Log in his admin, make sure it's updated and might want to check your server logs as well. Because there's a potential that this been a breach. You can probably start by looking at your your admin group to see any new admins have been added or if any accounts have had their passwords changed recently and you know for fact, it's not a possibility, right? But yeah, if automatic updates are up, up to dates, they're running the server. You have version 7.0.2 running that you're much, you know, much better state. If you're running an old ass WordPress from 12 years ago, more than likely, you might be running it to problems from other vulnerabilities, not even this one. Because this one I think is very limited to 6x to 7, maybe 5x, but who knows? So interesting side story that came out of this one is that Adam Cues of searchlight security, searchlight, sorry, searchlight cyber, I'll give him his proper flowers. He discovered the remote executable vulnerability. Historically, XQIT brokerers have paid up to half a million dollars for comparable WordPress RCE zero days. He's he's reportedly found this one and it cost him $25 in AI tokens. Interesting, right? 25 bucks and a little bit of knowledge can make you half a million potentially. Well, here's what's fascinating about the way he did it though, right? Big shout out, big shout out again, shout out to, uh, says to searchlight cyber, I believe they own asset note. I could be wrong. They do have asset note. Ascent note is like an AS 7 attack service management platform. Now, what's fascinating about what he did in terms of discovery is that he follows and used just like just like we do. And one of the stories that he caught during his day to day is a story that was published by mathematicians online and open AI where a famous mathematical conjecture called the cyclo, double cover conjecture was solved using a very specific set of prompts. And so what he did was his opening I published the prompts, he copied it, he modified it and then he ran it against the source code for WordPress and bought a Bing and identified this attack. That is that that really is fantastic. Like it's it's not you know, it's not rocket science to just watch the news when it when a math thing like this is solved. But to think about it is, hey, well, if this is solved, what programs out there are using this? And because now that becomes a vulnerability that is ingenious. Yeah, yeah, I mean, it's the it's the prompt engineering side of it. It's what's cool, you know, the fact that he spent 25 bucks is amazing. Yeah. And shout out to Adam, you and I are just reviewing old episodes of Bangbus and Adam's actually applying what he sees on the internet to things. Yeah, exactly right. That's true. Interesting stuff. So Uber eats expose somebody. So really, Zaire, Zairey. Oh, this guy has a crazy name. Yeah, I'm just going Zairey Wilkins. No, no, no, we got the whole thing, bro. We got the whole thing. I am not trying it. All right. So here guys got to hear this one. This is awesome. Right. So I'm going to go with Zaire dot David. Okay. Zaire, don't have you. So Mario and Wilkins. I got it. All right. Maybe. No, that is, that's it, bro. That is it. He said 21 year old student at the University of West Florida. And he has an online name, Sybileth. I don't know. Sybil. Yeah. Yeah. I know. Was arrested by the FBI and charged with conspiracy to obtain information from computers for private financial gain. He allegedly finance procured and helped market eight malware latent video games distributions. Primarily via steam between May of 24 and February
26 the malware infected approximately 8,000 devices and was used to steal credentials and drain at least 220,000 dollars from roughly 80 cryptocurrency wallets. He was arrested following the FBI raid on his north of Lauderdale in Florida home. The case is being prosecuted out of Seattle, faces up to 10 years in prison if convicted. You want to get into the attack vector? You want to explain how that worked. Well, first off, we covered the story before. This was the story where there was backdoored steam games. We covered this at least twice. And we were concerned that there were going to be kids out there using their home personal computers that are being shared with corporate employees in the real world. And he proved it, right? He proved it because by developing and distributing backdoored games on the steam platform, it allowed him to compromise a ton of people. He got 200 plus thousand in triple alone. One of those victims was actually covered by VX on the ground. Pretty popular Twitter group, you know, the team out there on X, X Twitter. One of the victims was a cancer patient, literally dying. And they needed the money. It was like 25 grand, 24 grand. This guy stole from that one person. And that person unfortunately has passed away from his cancer situation. So yeah, this guy, Zaire Dantabias is a complete scumbag for what he did. Now, as for the technical bits, here's the technical bits, right? They were able to use whatever platform to kind of create these games. They inserted into these games, these backdoors, maybe on the second publication or update rather than the initial update because those kept, I'm sure this was sort of review of these games when they're first posted. At some point, they backdoored those games, infected a bunch of computers with malware. And based off of what the FBI saying, more than likely it was like an info-stealer family they used. It seems like they bought a rat, so remote access trojan from our 10 grand. So boom, right? They deployed that at home, a whole bunch of computers, they stole credentials, they stole wallets. Now, this is where crypto becomes crazy. You see how these guys are getting involved in hacking into exchanges? There's a big story on the UK. They arrested two guys who were involved in the MGM and a Caesar hack. So that, right? I did, yeah. These guys are, how we say, in Spanish, no Apple. They're neo-fights. They're complete. They're not criminal. How we say it out? We say it here. We say Fugaisi. They're Fugaisi for sure. Because this guy, Don Tavius, whatever the fug, he got caught because he had no way to, you know, converts that those crypto into like actual money or funds that he could use. So instead, he would just use the crypto and use crypto sites to convert those to the gift cards. And so he was basically stealing from cancer patients to buy Uber Eats. Yeah, he used BitRefill gift cards to purchase his Uber Eats. And then he used those gift cards to send food to his real address with his real phone number. Come on. Come on. That was going on here. Yeah, even in the back of the days of Craigslist, you always had the package sent to your neighbor's house and the neighbor that was at work all day. It facts, facts. And he just leave the instructions. Just leave on porch. Yeah, this is this is the reality folks. When Chris and I are talking about these kind of adversaries and you'll hear that you're hearing on Twitter. You hear it. You're seeing an FBI report. This sophisticated actor did this X Y Z. No, it's not sophisticated. You know what this guy did? This guy used a he abused a system of trust to upload a game that attracted your child into downloading. He was able to get your crypto and then buy himself Uber Eats. Well, you went to school. You know, it's such a tragedy because you know, especially now what I know, right? No, what I know now today rather than what I was I was doing this dumb shit, but I was definitely hacking back into this. You start to realize that there are actual victims at the end of this. You know, especially when it involves stealing their money. Like, come on. What are you guys doing? So this one's kind of fun. So an alleged Russian cyber spy in Boston case previously worked for Kaspersky sources say in Doc and show. So Dennis Oborosco, man, these names are killing me today. A Russian national faces US federal hacking charges in Boston for allegedly involvement in the state-sponsored void blizzard also referred to as laundry bear. What the cyber cyber espionage we covered that so many on this plate, the super names. Cyber espionage campaign targeting NATO aligned European government agencies and at least 11 US companies involving mass theft of emails and communications on behalf of the Russian government. Dennis previously worked for a senior specialist at Kaspersky Lab in Moscow from 2017 to 2019. And for the Russia's FSB intelligence service for approximately five years prior. He labors served as deputy director of an FFB license company. He pled not guilty to computer crimes during his July 9th hearing in Boston. No new arrest and additional charges, but looks like a guy that was tied to Kaspersky may have done some state sponsoring hacking for for Russia. I have heard a lot of crazy things about Kaspersky and how much Kaspersky allegedly is aligned with the FSB. Well, I've heard that plus I've heard the response from the Kaspersky people. They've made a lot of effort in saying no, no, no, we may be of Russian origin or we may still be located in Russia, but we assure you we are, you know, we're adhering to ethical standards and we're you know, we're not aligned with any specific government, we're just trying to offer cyber security services. You know, at some point I felt bad for them because there was a point in like 2018 or something where like I think it was Obama somebody, you know, it's not the 18. That's way beyond Obama. Somebody somewhere, I forgot who it was at what year they put like an embargo against Kaspersky. You remember that? That was the whole big thing. Yes, I definitely remember that. Oh yeah. And so I had researchers from Kaspersky talk to me at the time and they're like, bro, this is not fair. You know, I said, well, so fucking leave Moscow. What the fuck? If you want to do, if you want to do business in North America, but then that's like, that's like a Russian telling me, hey, if you don't like what's happening in the US, just leave the US. Like it's it's not realistic. So you just gotta just be, right? But it sounds like this guy worked for Kaspersky for about two years. He's aligned with the FSB. It's just another black high for Kaspersky. I'm Yausavir. I don't know how they could continue to survive, you know, within North America, I don't think they do business here. I don't know anybody that uses them. Not anymore. They used to back in the days. The first ones everywhere back in the days. I always said they, the Kaspersky was the best because they're the ones putting the virus in the out. Oh, my boy, he subscribed to, you know, one of the old theories that I'm with him, right? Which is that the virus scene of the 80s and the 90s is really what blew up that industry. I part of the industry. You know, if you were a fan of like viruses, malware back in those days, which I was, you know, you know, I was a really big. It's deploying it. But I was fascinated by the community. Chris, I really was because they had like all these massive programmers working together to figure out how to circumvent this thing or another. It's just like hacking, right? And so what I remember is one day there's, it's like malware research for, you know, hobbyists and then all of a sudden you have McCarthy, you have Doctor, whatever the hell, right? You have Kaspersky, you have AVG, you have like 10,000 security companies selling anti virus software. And all of a sudden every other day is a brand-new, scary virus that destroys your shit. And it just kept happening. So it just disappears one day. And now we have EDRs to deal with anomalous execution. Yep. Anyways, it was the same way in the DDoS mitigation world in the early 2012 course. 100% it was the same companies because I knew of one company that you know, so you're getting DDoS. Your whole website's down, you sell commerce, you can't do anything. They wouldn't even pick up the phone for less than $40,000. Sure. To take your phone call if you're being under attack, it's 40 grand. Listen, I remember those days clearly, Matt, because I remember I was at war when those companies were an Fnet, you know, and you think you're like, shit, back in those days you had the FBI rated FOOMnet, that's one of the companies, right? That was New Jersey. You had a big, big data set over there. Then you had like Colchance, you had PLEXIC, POSLEXIC, whatever the fuck. And all these different companies doing like bulletproofing DDoS protection and then it's like, wait, but where's all the DDoS is coming from, though? I don't know, man. I don't think it was real hard to figure it out. Oh, yeah. So, this may put a little black eye on your world.
champion New York Knicks. No, no, no, no, no, let's separate the New York Knicks from MSG. That's how you're gonna do it. Let's say you just start. I don't know. I mean, I see that or the wedding venue of Miss Taylor or Kelsey. Wow. That's her new name. Well, I get I don't know Taylor Kelsey. Maybe Travis Swift. I don't know. I don't know. Travis Swift does sound cool. If he came out the first game, if he, is he still playing for Kansas City? I don't think so, bro. I think if he is, I don't know if he tired or not. If he is, if he came out in Game 1 with Swift across his back on a new jersey, oh my god. Yeah. Oh, yeah. That'll be scandalous. And they'll make a few more million dollars off the scandal. So Madison Square Garden, MSG, we're also MSG Sports Entertainment, has operated a facial recognition and biometric profile system since 2018, secretly creating risk and threat scores and dossiers on attendees, celebrities, athletes, fans without consent or notification. Examples have included labelling individuals with low risk or high risk. You know, I've been in Madison Square Garden probably a dozen times since 2002. Yeah. I'm gonna guess I'm low risk and your Brown House is high risk. My Brown House is high risk. Yeah. No, I'm just left. I agree with you on that one. Sure. So on or around June 5th, the night of the NYX NBA finals wins, shiny hunters compromise the organization via Vichine, which was a voice fishing of a low level employee gained access to their Microsoft, Entra ID and exotrated data approximately one month later, shiny hunters published about approximately 45 gigabytes of data containing approximately 26 million records, including biometric surveillance logs, internal threat assessments, VIP, dossiers, celebrity personnel, details and customer complaint emails all about the facial recognition system. So shiny hunters, we bitch and moan, but now they've done a little bit exposing of what these major corporations are doing. Yeah. And I I felt like as a tip of the iceberg, you know, MSG can't be the only one doing this. The estimate stories and exposés of, you know, kind of like what they've been doing with cars, a tracking, potential bad actors going to MSG. A good example was, you know, Oakley, Charles Oakley was bad for MSG for having a conflict with security guard. And then, you know, every time you try to show up, it was a whole big thing. They always kicked them out, they blocked them at the doors. So this has been, you know, something that folks in New York have been talking about, like, hey, what's going on with MSG? You know, what are these guys doing? And yeah, now we're actually seeing the data. The data has been published at least some of it has. And I'm sure there's some journals here in New York coming through that data as we speak. Do you, you're not surprised by this, right? I'm not surprised by it. I'm not happy with it either, you know, there's one thing to have surveillance, right? Because you know, you're running MSGs. It's a potential vector there for terrorists, right? Mass casualty event will be massive from MSG. And I get all that, right? There's a reason why they have a lot of security there. I get all that. But then the problem is when you start using AI, you start centralizing that stuff, start keeping our pictures and databases. And then you start profiling. That's why I have a problem with it. As somebody from New York City, they grew up with racial profiling. You guys don't know what that is. Google it. Type it at NYPD, racial profiling 2000s. Your boy Hector was profiled just because of the way I looked. And I was stopped an average of two times a day. I went to work. I got stops. I came back from work. I got stopped. In fact, Chris, when he arrested me, he said, do you got stopped so many fucking times? They even arrested me for murder during that time when I did not commit a murder allegedly allegedly. I didn't do it. I'm too much of a humanist, but I was so bad. I mean, the only reason I arrested you is because you're brown. Yeah, there you go. See? See what for? Finally, it's out. It's out. But all jokes aside, I'm not keen on that profiling shit. You know, especially if it's stored in long term, and it's then going to be used against people, right? You know what I can tell you again, I can't say it as a fact. It's all allegedly. You know who's got this data? Oh, NYPD. Every big security job in New York City is a former NYPD guy. Of course. And they got their hooks right back into it. So I think of the data that MSG is collecting goes right to them. Oh, yeah. Oh, yeah. Well, every freaking door man in New York City is on New York City's play role. New York City police play role because they they need info. They need what packages are going in place. And again, it's to get the job done. But you think your information is private. It is not. Well, that's the problem, right? You know, it's as a society in the United States, we're very quick to put judgment on China. China does this. They have a credit system. What we have a credit system too? Well, they have to ban it. Well, we have to ban it everywhere too. Well, they have centralized this. Yeah, well, we have that too. You know, it's very easy. You know, George Carter, I don't bring him up a lot, but he had some really good philosophy on this where he said here in the United States, we do something with language. It is very orally, which is like, you know, instead of propaganda is, you know, it's messaging. And instead of censorship is moderation. And so what you see here is no, it's not severe. And it's just security. It's bullshit. So yeah. I mean, so one thing we're not to overpass on this thing is these guys got in because they impersonated an IT support to a low level person who then provided their credentials. Now, whether then involve, you know, multifactor authentication, also, who knows? I was not. Hey, man, no, they're going to trick the person into giving them that. Hey, there's a bad word. We're about to send a code to your phone. What's the phone? What's the code? So, you know, if you're doing a voicemail, a voice call, you know, that's easy to get, get past the MFA. But, you know, they've also, it's interesting. So MSG has not issued a public statement on it, but multiple class action lawsuits have already been filed and decided to just ignore it about this. And it's not about MSG collecting it. It's their failure to protect it. They're suing because they, yes, you have my biometric information. I guess I agreed to it by purchasing a ticket and entering your facility. And you should have protected it better, isn't with the lawsuit. Not that you're actually storing this shit. You know what? I rather than nothing at all, right? I rather there be some accountability because yeah, if you're going to store that kind of information and you're getting ups with a low level attack, the same thing that happened in Vegas a couple of years ago. And you have not learned since then, then there's clearly some gaps in your security. You have to kind of sort out. I mean, where are you at a privately owned facility, saying, putting up a big science is we're going to take your picture. We're going to build a profile on you. We're going to track every, you're every fucking movement. Don't come in and watch the next if you don't want. If that, if that sign is up, then I'll make the decision. All right? What if it's in really tiny letters, right? Before you hit, you click buy. Well, that's that's the shitty part, right? Because that's how they do it. That's how a lot of these guys get through to violating our civil liberties. You know, and this is the basic fundamental privacy. But the problem here that we have in the United States, if you guys have been paying attention, is that you have people that are literalists, you know, they'll read the constitution literally, they'll read the Bible literally. And then they'll tell you, well, if the word privacy is not a constitution, then you're not entitled to privacy. All right? They'll tell you that to your face and usually comes from one party. You know, and it's the democrats. No, this is the republicans. They they're libertarians. Well, I didn't think they're libertarians. I didn't even know I didn't think they know what they are at this point. I didn't think they know whether the republicans are not. But that's besides the point, the real point is that there's no respect for our privacy here, whether you're a campaign customer or not. Look at all the drama that Americans had to go through. It's a lobby congress to deal with, you know, the deer company. You know that. You know, you have equipments. I have a John Deere. You have a John Deere. And up to recently, if you decided to work on that John Deere, then you've voided all warranty and you're screwed. You can't even get replace reports. I think things have changed more recently, but it's taken 25 years of fighting in court to get to this point, which is absurd. Yeah. The next one is the three-second theft. I thought this is how you lost your virginity, but apparently not. It's why AI VoiceFraud outruns every defense. So AI Voice Cloning enables rapid social engineering fraud. For example, a grand parenting or family emergency scams where attackers use just three seconds of publicly available audio to generate convincing synthetic voices that demand money or information under emotional distress. So we've covered this before. Sure. But you know, some concrete examples came out like in the summer of 2025 and over Florida, a woman in Sharon lost $15,000 after scammers cloned her daughter April's voice from the social media clipping and then simulated a car accident involving a pregnant woman. It did mean it cashed bail via fake attorney.
And it's getting worse and worse, you know, heck, I think we're putting ourselves in danger by putting this podcast out well It's it's too late for that brother. Oh, we it's too late. Well, it also saves us though Sure, we can all deny ability you didn't say that that's a Yeah, you know, Christmas is talking about tanning's balls out in the field That's that's for gaze is AI stuff heck wasn't in the Epstein's list That's all for gazing. Oh I was not on that list. That's right. That is right. Let's make sure we correct that Well, yeah, you know It's sad is very sad because this is part of a much bigger story with like the whole 764 Nonsense cults your cults of people online on discord Working together in tandem using technology and AI to extort children Extort little girls extort little boys They extort great is extorting grandmas. I read a story and read it Well, it's true or not because there was this optional source to it. It's no news article But you know, I read a I read a report not even a report. It was a guy doing a confession and You know, he had finished the he had detox and cradum Cradle whatever you call that. No, that should have the girl at the gas stations. Yeah, apparently is a massive drug It's like heroin, bro. Yeah, and it's not regulated at all yet. Yeah, it was like K2 when K2 was public, right? Bass salts people eating shows faces. Oh, yeah, so This guy said hey, I finally detoxed the man. It was a battle because I had my little niece choose 15 they found their roblox They made her take pictures of herself and then they forced to kill herself on live camera Whether that was sure night is whatever the reason we are out of the lead. No from court cases, you know and and you know convictions arrests especially recently of These 764 and he's all these different cults these subsidiaries. They have been targeting people just like this grandma store here um and They're relentless brother. They have no ethics. They have no humanity no empathy no sympathy is all for a quick buck and a couple of laughs, bro It's very much anti-human, okay? If we're shoving all these guardrails on on AI why can't AI determine that this shit is Is beyond what it should be intended to be used for well here's here's the double-ed sword I myself I'm an open model guy. Yeah, right? We have our own servers. We're using local models Right, and we're able to do so much to help people Just me just with safe film right and there's a lot of other people like me doing the same exactly online Now when you're winning a local model Chris you control the guardrails Okay, especially if you're using an uncensored, you know large language model Okay, now what does that mean that means that a lot of these bad actors will do the same thing But they'll use their uncensored models and their local deployments to do what you were talking about in this article here Without happy to do with an topic and open a eyes guard those whatsoever So so double-edged sword yeah, unfortunately, where do you where do you fall on you? You still even all the bad things that can come along with it. You're still you know open source guy like just I'm still use it the way you want to use it. I'm so the open model guy because I feel that we could do a lot more good than that Just like you know the second amendment with guns is a lot of people arguing on both sides saying that hey Having guns in a big city is bad But having no guns is worse and it's a hundred four bunch of reasons on either side with stacks from both sides You know and so you know as one of the situations like well, here's why is that Here's what I'm willing to do to do good, you know There's always gonna be a bad actor and all these different scenarios and that this is one of those It's crazy that all you need is three seconds from a like an online social media post and you can get the voice Sure, no, I've wasted even a gets a mother well This is why if you look if you guys look at the Ferrari story from several years ago Where you know the CEO of Ferrari gets a phone call and They're asking for information. I think it was this co-founder or partner investor And they were asking information about like hey, so what's the latest Ferrari model is coming out? He realized that already is off. That's that doesn't sound right So he asked the guy hey, so yeah before I get to that remember that book we were talking about And the person hung up before because it went on scripts They didn't have the copy for that to deal with that, okay So when you guys get a phone call And it's like hey, we just kidnapped your daughter and you know, we need $20,000 in the theorem or whatever right Um, well What can you do at that point? Well, I mean, it's their calling and they're actually describing that crime It's a kidnapping that I think some of these more are more like you know, oh there's been an accident They're in jail or something so yeah, that you you know, you're less you're less likely I guess to freak out about it. You think this is the way it happens. You think that the police call you and set the bail over Over the phone Uh tell tell a loved one that that's how it works. Yeah, we don't do that right. That's why we got it That's why the long force you got it. We don't do that You know, you see when you go to USPS website, we're gonna tell you hey if you received an email phone call text message from us Asking for x1 z that's not us. Yeah, you know, we might have to have the FBI do like a nationwide thing like hey We would never call you or ambulance is not gonna call you or the Lord is not gonna call you to ask for money over the phone Um, that's not how things work You say that I recently I was telling my daughter a story. I don't know how it came up But Emma Stone came up in conversation and I had to call Emma Stone one day. Do I tell you the story? No, I mean my minute now I had to call Emma Stone and it was such a bitch trying to get a hold of her Like I got her manager's number and I tried I got her cell phone number and all that and she didn't answer and like Trying to call a major celebrity in the first place difficult and then trying to convince them that you are an FBI agent What I'm telling you is legit is even harder um, so sometimes the FBI does call you Yeah Wanted to call. There's nothing to ask for money, right? That's true. That's true. That's true The FBI will never ask for money. Yeah, so we gotta we gotta we gotta pay attention to the cues right then what what is an FBI You're gonna do when they call you or an ambulance or a lawyer versus what an adversary might do right? I mean retired FBI I may ask you for some nudes Hey, this is Chris Carball. You have any moods laying around. You gotta send them to me now. Uh, that's AI AI said that not me But but if you do send them a questions at hacker in the fed calm Yeah, we don't need the more news. You're using the balls on the freaking email What Send them directly to Chris and hacker in the fed There you go. That works So hackers revealed the sono AI music generator script youtube and Genesis so a hacker breach sono Which is an AI music generation company and access internal source code and trading data sets details We believe that sono had scraped millions of songs lyrics and audio files from youtube music Deezer Genesis pond five Free sound and many more places the breach also is close customer data included emails phone numbers and strike payment information for hundreds and thousands of users So hackers are revealing these companies doing some dumb shit Yeah Well, they're doing dumb stuff illegal stuff and I I feel like we covered this already We talked about it and he said at least a bit was crazy about this story at all regardless is House this company allegedly, you know, they stated that no, we're not we're not copying Like you to we're not copying you know a copyright abuser We're cop we're copying music that's that's publicly accessible. It probably domain music right These adversaries sold the world. No, it's not the case. These guys are lying to you Now what's probably gonna happen is they're gonna get sued into the you know into the abyss by youtube by Spotify by always massive You know production companies and and music companies um Yeah, I mean it's a tough one It's right out to be shady and and and have you know crap security right I mean I don't know all right brother. I think yeah, I think we've reached the end I don't I don't I've sort of uh out No Well, no, no, no, wait, wait, we're gonna do the last story. We will do the last story. So I know you love this uh, so White House teleprompter operator made more than $100,000 betting on Trump's speeches So Gabriel Perez a long time White House technical assistant and president Trump's teleprompter operator since 2016 allegedly used non-public Knowledge to prepare presidential remarks and last minute edits to place bets on mentioned predictions market. So Oh Calhchis mentions prediction markets. He profited over $100,000 across more than a dozen speeches and events including the February state of the union a December prime time address and January world economics forum remarks The best replaced on whether specific words phrases or topics would be uttered Perez reportedly uh exited some positions mid speech when Trump deviated from script how
the fuck did he not think he was gonna get caught? - Well, one, yes, that's a great question. Two, Gabriel Perez in the White House. Come on, what is that? Let's go out here. - What do you mean? I don't know, that's how I was just saying it. - Hey man, I don't know. I sound like a brown person named to me brother. - You think they hung about to dry? You think they dangled him out there for this one? (laughing) - Well, here's, here's the reality. These prediction markets have really exposed the, I would say that part of us of the humanity, where it's greedy as hell, where you're willing to give up your job for a quick buck. $100,000, I'm sure he was making more than that as a teleprompter operator. And even then, even if it was making less than $100,000, he was working at the White House for like 20-something years. Like this guy was a senior member of staff at that point. For that space. - I know that you see a member of staff. If you're preparing for the White House, I'm gonna tell the proctor. You're not advising the president. - I'm not, that's not what I was saying at all. I'm not saying at all, what I was saying was he's been around so long within that job and he's senior level, right? There's no way that, you know, the homeboy was advising the president, but there's also no way that this dude was, you know, powerless like an intern. - Yeah. - Dude, obviously had access. And so to give all that up, for a quick bet on Kowshi or party markets, it's crazy. But we've covered several insider traders so far, double and tonnevere on the trader part. And so, you know, they seem to be catching the low level guys. You never seem to catch the people doing the insider trading on oil during a war. That's the one they won't catch. - Well, you keep saying that they're there. You think they would have caught them by now? - Yeah, you know, I don't know. I don't know what was going on with that, bro. (laughs) You know, but yeah, we're gonna see probably more of this. And, you know, - It's strange that people with the insider access, you know, it's, you know, I've heard stories of, you know, the FBI jumping on like fights, UFC stuff, you know, when the bets get too big, like all these betting places, either whether it's, you know, the draft kings, the MGMs or even the prediction markets. When a crazy amount of money comes in on one side, it automatically sends up a red flag, you know, it's sort of like, and I know they do this for a fact in the markets. If you're making more than like a certain percentage, they look at your shit and see where you'll get in this access from. Yeah, maybe you might be lucky once or twice, but you're not lucky every single time. - Sure. - Sure. - So, I don't understand how these guys keep getting caught. Like you said, to lose a six-figure job, just because you want to make a few extra bucks 'cause it was easy, it's crazy to me. - Yeah, no, no. - It's tough, man. And I get it, I mean, times are hard right now, you know? Quite, you know, for any of you guys, any of you people, wonderful, wonderful listeners listening, if you see an opportunity to do an insight thread of, insight thread, don't do that either. - Don't do that, don't do that. - Yeah, definitely I'll do that. But if you have an opportunity for an insight trade scenario, walk away, it's not worth it. I promise you it's not. You might make a quick 50 grand, but that 50 grand will of course you extra money years of prison, you lose your job, and you're always gonna have that dark mark over you, man. It's not cool. - Not cool at all, sir. Guys, support Hacker and the Fed on the Patreon. Support Safe Hill. If you guys want to know more about or learn about their thread exposure management platform or their penetration test services, reach out to Hecht on LinkedIn or visit Safe Hill.com. Email them at
[email protected]. Tell them you heard about it Hacker and the Fed. Let them know that their support of Hacker and the Fed is paying off. Just go over and visit them. Come on, help us all out. - It is a nice website. - Come on. - Merch is up at hackerandthefed.com. Five Star Reviews, wherever you download, subscribe to podcast, share some social media. Tell your worker, co-workers, tell your friends, tell your people that's got the diarrhea diseases going around the United States. - Hey. - Let's go on with that. - While you're sitting on the can, download hacker and the Fed. You got the diarrhea anyways. - You got the time. - Yeah, you got plenty of time. You got two weeks of the shits. The squirts are gonna happen. Is that the new ozemic though? - Oh, maybe. Maybe it's gonna be a taco bell of the new ozemic. - Listen, I read a guy on Twitter, he said he knows like 12 pounds of going to week with that, bro. So I don't know. - Literally, why it's on top of mine. While I was sitting here during the podcast, one of the mean girls just texted me and said her mom's got it. - Oh no. - Two weeks on the bowl. - Oh, man, two weeks. - Her mom's got a lot of room spare. This girl, woman, is very good shape. She's got one lady. - Yeah. (laughing) - Poor husband. - Poor husband, geez. - Listen. - I get not one of the mean girls, but mean girl mom. - Well, you know what, it's close enough. The mean girl, she's gonna be careful. You know what I mean? - We all better be careful. - You too, 'cause now it's tight. Now you're like a tool to reach a separation. - Have you seen the brown map? Have you got on the internet and looked at the brown map with the diarrhea spreading? - No, I haven't seen it yet. I just expanded it to my area. I now, in part of the brown map. - I'm sure I'm all part of the brown map. - You know what? - Different brown map. And what you're on, you're on the one who know a PD's brown map. For they got your data from MSG. - It's a specialist, a specialist map. That's crazy. I went to MSG game and he got me freaking pulled file from off that. That's brown guy entering. Brown guy entering. (laughing) - Oh man. - All right, brother, fun show. - It's beautiful as always. - All right, love a respect. I'll talk to you next week. - Cheers. - Love other cheers. (upbeat music)