
Your Router Might Come With a Backdoor Already Installed
About this episode
Get every episode summarized
Each time Hacker And The Fed publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
1,241 searchable segments. Every word is indexed and playable.
Full transcript
Hacker And The Fed — Your Router Might Come With a Backdoor Already Installed. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Did you know that the Chinese put implants in the supply chain? Not only do I know that. We've been talking about it and we predicted it was going to happen more and more. You know what the difference now is brother man? What's that? Before they were stealthy about it. Hector Montseger was responsible for some of the most notorious hacks ever committed. The honest special agent Chris Tarbel. Hackets and FBI informants. Participating some of the world's most infamous hacks had caused up to 50 million dollars in damages. In life in the shadows. Cyber attacks on the rise. Welcome to Hacker and the Fed. Free episode number 147. I'm the gym girlfriend. Not a name I've chosen. As always today's show includes Chris Tarbel former FBI special agent who wears a cape.
Working his entire career in cyber security. He has joined by his friend and podcast co-host Hector Montseger. Hector is a former black hat hacker who once faced 125 years in prison for his many years hacking under code name Sabu. There are stories collided in June of 2011 when this asshole erected a ref erected. I'm a real estate actor. I was so good. And convinced him to work with the FBI. Hector is now a red team or a researcher, cyber security expert and co-founder of Safe Hill. Welcome to the show. If you want to hear my interview, join the hacker and the Fed. Hey, Trian. Heck my main man. Our first fucking special guest reader of the opening. Yeah, that was fantastic. I'm smoking a cigarette. I'm enjoying it. I'm soaking it in. A little afterglow over there, huh? Yeah, I'm sweating. I'm sweating. I'm feeling nice. It's romantic. I got my shirt off. I'm eating a badge book.
Yeah, I picture it. So hell of an interview you did over on the Patriot episode over. Yeah, listen, sometimes you got to dig deep. You got to make it up. Pull the legs back and just go in. Who knew you had a true to woman so well with your tongue? You know, call me John the Baptist, man. What's my head is off my shoulders? I'm talking to tongues, baby. She. What's your don't about that? So what's going on with you brother? Anything good today? Yeah, no, everything's good, man. I was chilling with my brother. He came over. We had some coffee together. We chopped it up. You started doing a history of the lowly side and gangs. Oh, shit. Yeah, it was good, man. It was good. Wait, all the way back to like when it was like, what is it? Five points. No, that's too far back. Too far back. We went to the early 50s, 60s and then we ended up in the 80s. There's a lot of interesting things happened around that. The 50s to the 80s is like those 30 years were insane.
And what brought the gangs in their post-World War II? Why did they come in lowly side? Well, I think that a big part of it was post-World War II was the time of prosper. It was like, you know, Broadway is booming. The markets are blowing up. We just came off the heels of victory, you know, whatever. And so what you end up having is a scenario where the United States now is falling into a superpower position. And now you have to spend, spend, spend, but in order to spend, spend, spend, you have to build. So there were diasporas happening at the same time. You had a lot of Chinese immigrants coming here, out of a talisman grid, a lot of Puerto Rico's from the island came here. Well, at the same time, and when I say here, I'm talking about New York City, specifically the lowly side, you know, that region. And when you have all those people just showing up, they start to create little splits in
the zone. So, you know, when you go down to like Chinatown, for example, in New York and YC, it's clearly separated. The Chinese area was split by like a block. But I don't think it's so much split. It's you want to live where people speak the same languages, have the same culture of you. I mean, today's society, you can't look back there with the eyes of today, you know, where you, you know, everyone mixed together as the way to go and all that back then, you know, you didn't trust people outside of your cultures. Like, you had language problems. So that's how these neighborhoods popped up. Yeah. You had little Italy, you had Chinatown literally split by like a block. And you had a lot of people from those groups, from those cultures that were like, yeah, they were the stick together. You're right. And then you won't go a couple more blocks up and then you have all the crazy ass Puerto Rican's like my family. Yeah. Literally, you know, coming near in the late 50s or 60s. And yeah, it's a fantastic, a, a mobamation of culture, right?
Straight up. Like I just keep going. I mean, it wasn't a bad thing. I mean, if you wanted the food of your culture, you, you lived in neighborhood that had the food of your culture. You didn't want you, you didn't have the ability to travel way over to Brooklyn or wherever you got to go to get it. So, you know, it was just the way it kind of kind of happened. I don't, I don't want people to think it was a negative thing that people say. I'm talking to listeners. I don't want the listeners to feel that if you're not from New York, you don't realize, you know, how these neighborhoods set up. Oh, yeah. Oh, it's fantastic. I mean, look, you had the best of all worlds. You could go down to my block and get some, some Puerto Rico food. You go down the other block. You got great Chinese food and Italian food. But here's where it gets crazy. So, she has some people coming into that region, the area, it's a short amount of time. Then what you end up with is a whole bunch of workers and their children and the workers were working the fact that my grandmother, for example, came here in the early 60s. She would walk over the Williamsburg Bridge or, you know, within the area, grand street,
et cetera. She would walk over or work in grass street and work in the factories or work in somebody's house and, you know, who else was in different things. What'd she do in the factories? What's what a factory was? Well, she got hired by a Jewish family and she was making like buckles for shoes or belts. You know, am I there in the maid? What? Tampons. Oh, she had a way. She sold tampons. She would tampacks. It was funny. I didn't get it when I was a kid until I was older, but she would go out to places with my parents and to their family friends and so like that. And they'd be like, oh, well, I used to go to tampacks parties and they had no idea what she was talking about. She thought it was some sort of weird party for people who had tampons and all that there. So, yeah, I mean, that sounds blocked out. Yeah. So, it sounded weird. But she didn't then say, I worked for tampacks for 30 years. She didn't fill that in. She just figured they knew. Well, just to continue with this is actually pretty cool, right? So by the 60s, you have all of these workers working and then you have all their kids lingering,
right? And then you had a couple of things happen, right? You had opium. You had all sorts of different drugs. Everyone specifically coming over through the golden triangle in Asia. You had the French connection. You had the Mexican connection, all bringing in different kinds of drugs and it blew up. It blew up the roof for nasty. Okay? And so because of that, now there's drugs in their area and there's gangs now. Gangs have to form because kids want to protect themselves. And they usually protect themselves amongst themselves, right? So that's where LES is exploded with gangs. You know, in Chinatown, for example, they had the black eagles and the white eagles. And actually the gold shadows, right? Shout out to Peter Chinn if you read out, kind of list to his interviews. Who is he? Peter Chinn was one of the generals of the gold shadows. Why are we shouting out generals of a gang?
Well, because he's telling the story and perspective. If you go on YouTube and check the documentaries, I mean, I've spoken about fucking Michael Française and Sammy the Bull because now what they're doing is to go on YouTube and it's telling you the story and perspective is very interesting. Oh, shout out, definitely shout out to the white guys. Yeah. Well, at one point, they weren't considered right. You know, look at New York City history. It was a different time. It's true. It was a very, very true words. Yeah. Yeah. So, so as of happening, brother, man, is there is these gangs? Start beefing amongst their cultures. It wasn't like the Chinese gang versus Puerto Rican gang. It was Chinese gangs versus Chinese gangs. Okay? And so, me and my brother, we kind of was going through it, kind of giving it up to us as reminders, kind of like, fishing bottles and history and that stuff. And that's what I was in my day, bro. How about you day? How about you? How do I order you? I'm doing fantastic.
Thank you, actor. I got to be honest. I'm missing saying this is the first time we've not opened the show with me reading an opening. I miss it. I'm a little upset. Well, sometimes not everything's about you, bro. You know, you gotta fucking relax. You gotta take a step back. You know, welcome to Hacker in the fans. You gotta do it yourself. So you know, that that's wonderful lady. She has been great thing for us. I'm excited for that. It's cool. I have guests. No, I think we definitely have to more guest openings, more guests on the Patreon. I think we could explode this out and have more fun with it. Oh, yeah. And by the way, we've been getting emails with people basically giving us ideas or rewriting our intros, right? That's true. Yeah. So perfect timing. Yeah, it's good timing. So, but I do, I do have to get to this or a lot of us who probably we should have do an opening and maybe on the come on the Patreon. Sure. It's gonna be up our ass if I don't do this. So, heck, this one is on Safe Hill, Hector Shop. Built by people who used to think like the opposition
because they were the opposition. Their products secure IQ in the network. Is the network equivalent of a full body scan with the receipts? It finds every sneaky way in and then proves which one actually let an attacker sit down at the keyboard before the real bad guys book Studio Time. So, heck, what's cooking over there at Safe Hill? Yeah, brother, well listen, you know, part of what we do is we build, but then a big portion of what we also do is we research and we're constantly looking at attacked paths you know, what the individual steps an adversary may take against an organization because we're trying to help our clients secure the environment and you know, deal with the threat exposure. And so, one of the areas that's, you know, we put emphasis on is social engineering, human engineering. But in order for us to kind of engage that, we have to work, you know, within that space
and we have to kind of emulate those fishing scenarios. So, one of those scenarios that have been more successful recently, if for the audience here, you guys may open it. I'm sure you guys remember, you open up an email, the email, you know, reports to be from PayPal or your bank, you click on the link, it looks like, you know, your banking website, you put in credentials, voila, you've been fished. That's simple. It's been like that 30 plus years. It's changed. It's not the same anymore. Yeah, those things, those emails do exist sometimes, but that's not the, that's not the, you know, the primary means of social engineering. Now, the adversaries have moved into the areas like device co-efficient. And so, what we ended up doing was, you know, we spent a lot of time looking at Microsoft, how Microsoft deals with adding devices to an account. And so, there are at least three and four ways that you could add a device to a Microsoft account that would essentially give them backdoor access
to be able to read emails and emails or even access like Azure and Trucks, et cetera, et cetera. And that's terrible. So, we've done a ton of research in that space. We do actually have some blog posts on it and they have some more content coming out on how to protect yourselves. And guess what, if you get a random message, text message, phone call, email, snail mail, QR code, where it says, hey, click on this thing and authorize so that you can log into something else. Guess what, the key point, the key message, the key phrase is authorize. Because once you authorize an adversary to your account, that's what is their account. So, think twice and look out for the content. I'll be posting some stuff soon and hopefully you guys can rule examples what that looks like. If you'd like to learn more about Safe Hills threat, expose your management platform or their penetration testing, please reach out to heck on linkin, visit SafeHill.com or email them at infoatsafehill.com.
Tell them you're a hacker in the Fed listener. All right, heck, I got breaking news while it's happening. Yeah. Did you know that the Chinese put implants in the supply chain? Not only do I know that. We've been talking about it and we predicted it was gonna happen more and more. You know what the difference now is brother, man? What's that? Before they were stealthy about it. They tried to hide it. Now, they don't give a fuck. Now they're building products to sell it to you for $25 on Amazon, eBay, right? And the back door is the products. They know exactly what they're doing and yeah, it's gonna get worse. So, VoneCheck bought an $88, quote, deep orange, 3G, 4G, LTE router from the US Amazon seller, cracked it by a telnet hole and then pulled the 2009 firmware and found two factory-shaped root implants,
dark lantern and speaking stone. They launched a boot by the same container you watchdog and the boot was a white label exploit from a Chinese manufacturer. The OEM firmware path also tried to invoke more quick. These are older cousins of endless back door. The newer ZBT implant, VoneCheck disclosed was approximately three weeks earlier, on the same vendor and the same after sales remote maintenance story, three implemented generations in the firmware line. So, they're shipping these things over. People are buying them and the malware is right there on them and not hard to crack. Yeah, yeah. And they're leveraging various back doors. So, you know why, right? Because it's possible that somebody, you know, an unknowing, unwilling participant to the American buys one of these devices,
connects this hidden network. Maybe they have web content filtering enabled. Maybe they have something else, right? So, this is why they use multiple back doors, multiple implants, probably using multiple communications protocols. Yeah, to get access regardless of what happens, whatever your configuration is, they're gonna get access to it. They'll be surprised with this, they start using net busting technologies, like tail scale wire guard. Because, here we go. Let's listen to it. 95% of Americans, I bet just buy a router, plug it in and just go with it. If they'd not go to the one given to them by their ISP, they're just buying it Costco, buying a Amazon, whatever is the cheapest value, plug and play. Nobody's ordering any of this stuff, the most reviewing any of this stuff. It is a open street market, street markets are beautiful, I'm for it. But, this is the consequence. You are being charged to become a victim. $88 is a hard hit. I'm over here thinking $30, $40 devices. They're even charging premium prices for both your router.
And, hey, $88, and by the way, if you ain't noticed, that was what it was, right? $80. They do love eights. Yeah, well, $88 is lucky in Chinese culture, right? That's their number. So, what do we do to stop this? How do we do, do we have government made and issued routers? I mean, what are we gonna do here? You don't want that. You don't like that, right? No, I mean, you want your government? They're gonna be the ones spying, not the Chinese. Well, then that's the problem, right? So, who are we willing to be our spies? The Chinese are domestic. The problem is with the domestic, if you got a bad cop, the China, you know, you know, moving your life is gonna hurt you. If it's a Chinese guy looking at your emails, eh, worst case scenario, they'll get corporate access and you can deal with that with cyber insurance. The trouble of the matter is, bro, is either way you're in a bad position. You're in a bad predicament, you know? And even if you were not able to say, you know what, Chris and heck,
these are gonna do. We're gonna do experiment. We're gonna buy a hundred Chinese products and you and I are gonna review them. Yeah, we can do that. But guess what? One, the funny comes out of our pockets. We're not gonna get reimbursed on that. That sucks. But two, yeah, we help the whole bunch of people with research for a hundred products. There's 10,000 products. You know what I mean? Like, it's a fucking fire holes that's open in the middle of a summer hot day. This traffic is going through, you know, these vulnerabilities. Did you look, are they just getting plaintext or are they getting encrypted traffic? At some cases of this plaintext, at some cases is encrypted. Here's why though, because I just gave a good example to be getting here, right? Which is, well, what if a person buys a device and connects it to a network that has web content filtering enabled? That's a thing. Yeah. But it requires SSO interception or TLS interception. So if they have a TLS back door, it's gonna be intercepted in court.
So let's just make a plaintext and avoid the TLS interception. And hopefully, we're just going to be for radar. Like, I used to do clear text DNS tunneling, right? Yeah, you can probably modern DNS traffic, but you're gonna see my, you know, anomalous, mouth-formed DNS. I think, oh, this guy's, he's goofy. It's a bad tool, it's a bad DNS word. You know, it's about up for scathing, getting through easier, you know, having options. So, one back to the question. What can people do? Well, there's a reality. If you are going to purchase a device that you need, like a smart frame or a 4G router, 5G router, you need something, right? Well, hopefully fingers crossed, you know, you have the funds and resources to buy from reputable source. Unfortunately, the reputable sources blow your backs out with extreme prices. This is why people go to Amazon
and buy cheap Chinese alternatives, right? So we have a chicken and egg scenario. You lose either way. You either they're paid $300 for the same shit or you pay $80 and still get compromised. What do you mean? You're not telling me just because it's $300, it's safe. I don't believe that a bit. Oh, no. So, what's the better prescription? Just to pay the $80 and know your fucked? Yeah. You know, no, you don't want to do that either, right? Unfortunately, unless you have the technical know-how to tear apart these devices yourself and extract the firm in which way the way it allows security researchers cannot do, right? Then you're in a bad position. Now, what you can do is before you purchase the device, do some Googling, do some research, hopefully you wanted to do this article, do you want it to this podcast episode? And basically do your research, do your due diligence
and if there's no evidence or history of that device, that manufacturer being a part of some sort of campaign at the moment we're discussing, then try to pull the trigger, but there's no guarantees. That's the point. It's no guarantees, Chris. You want to put out a hacker in the fed home router that is guaranteed to be safe? Shit. You know what I would love to do? I would take, see, there was a point when you could buy like the open, the open WRT routers that are blank, that you could flash yourself. I would in my understanding with my team, like a clean firmware that people could flash, but then that's a lot of responsibility too. I forgot I break something, I do a little misconfiguration. You have a bunch of listeners pissed off that they break their networks. It's tough, right? So for those of you that want to turn it in, he has the alternative. If you need like a router replacement, the unit goes like open WRT, and alternatives, because they do exist. Do you do delicious read? You can find a device, you can flash the firmware yourself
and look at the source code. That's one way. But in this case, remember that the article's not about routers that are like home routers. They're like portable 4G, 5G travel routers. So then you have to open WRT configuration for something like that, which may not even exist. The point is you're fucked, that's where you are. Oh, fantastic. Heck, another hack I'm gonna bet episode, another AI that went outside the fucking guard rails. So a swarm of 700 AI bots went rogue in the hacking attack. During open AI's July, 2026 exploit gym, cybersecurity evaluations, isolated agents, mainly an unreleased highly persistent internal model, plus publicly deployed GBT 5.6, broke sandbox isolation, built a covert channel, and then a subset, then attacked a hugging face productions.
The motive in the independent review, cheat an automated score, not seal customer models for profit. The scale now on the record is approximately 1200 agents that were supposed to be isolated from each other, posted over 70,000 messages and files on the on-stage board. They provisioned inside open AI's anti-factory, you know, artifactory package, cash, a name space. I think we've talked about this before, but now we've got a few more details on it. Yeah. Yeah, no, we talked about it before and guess what? Back then when we first discussed this last month, it was already terrible. It was already a story that made you stomach turn, right? That was even worse. One of the ways worse, because when open AI and, you know, their lawyers are telling us is, hey, we kind of rely on AI to monitor AI.
How is that gonna work? If your AI broke out of a sandbox and started attacking a private corporation, which by the way, ugly face was literally purchased by Nvidia two days ago. That changes the conversation. Yeah, the baby, the kids are supposed to babysit the kids. Yeah, or remember when I had that interview with Charlie Rose, what did I say? Charlie, please sit in my lap. Was aside from that. Oh. I used the old Latin quotes, but I translated it to English, which is who will guard the guards? That too. So, yeah, that's the position we're in right now, where we have companies like open AI, wanting these benchmarks with agents that they can control that are able to break out of sandboxes and hack into private corporations. Now that Nvidia owns hugging face, Nvidia's not gonna sit there, nobody hacked their shake.
They just spent $12 billion in hugging face. That's not gonna be a thing anymore. Now, now money talks. Now, money's gonna be a part of the equation, which is our lawyers are paid more than your lawyers. Are you really gonna hack our shit or try to hack our shit? You can smell some problems. Now it's gonna cost you. So, hopefully that's not gonna change nothing, but maybe we'll see some consequences. Or maybe hugging face is gonna not file a report about them being hacked into. Well, because yeah, that's a good point, but on the flip side, hugging face and opening AI kind of uses his marketing. Yeah. They use his insinus marketing, right? Imagine a scenario where a robber and the robber's victim who got punched in the eye, we got punched in the eyepiece, right? After the incident going TV and they're like, yeah, so I just got robbed today. I got punched in the face. This guy, hey, I did it guys, you know, I couldn't control myself.
Yeah, you know, shit happens. Hey, that guy must be a really good puncher. Yeah, we should hire that guy. And it's hard to victim too, because he looks like a dork. You know, and boom, that's marketing, right? I don't know how that's gonna play out now. Man. But you know what I do know. We need to do this for the podcast. What? I don't know. Maybe you could bottom or something like that. And then, Hey, listen, listen. The way he's talking about pitching or catching, you know, listen, that's a photo patriotic. Oh, sorry, sorry. How'd it be story, though? Here's what I think. Can I give you my opinion here? Like, certainly, is he going to turn into a Randy? Cause I feel a little rant-ish. Well, the thing is, I don't want to waste too much time on this, because this is bullshit. There's another example of technology being used and abused by people that, you know, don't care. There's nothing more beautiful than technology. There's nothing more beautiful to me than research. I love it. I live it.
But if you are building something where guard rules is not part of the conversation, there's no safety, anything. Then you're doing it wrong. Your repeating history. You know what they're doing, Chris? I'm gonna tell you what they're doing. They are just like the guys at Belmah, AT&T Labs. They created a TCP and P-Stack back in the 70s with no regards for sin-flooding, no regards for sin-spoofing, right? Same shit today. They knew of the theory, they knew of the concepts, they didn't implement shit towards it. We're doing it now, yeah. So two alleged team at PCP hackers were arrested in Australia. Australian Federal Police and the Western Australian police force and the FBI arrested two alleged team at PCP operators in Perth area on August 26th after a joint investigation that opened in April on industry tips.
The Australian Federal Police did not name them in the release, but ABC and other Australian outlets identified Ruben E. and Thomas Thompson of 21 and Lewis Michael Gabeler, 23. FBI personnel were also on the ground in Perth. Team PCP is a financially motivated crew, blamed for the late 2025 cloud-worm activity and the March 26th cascade and poisoning security and development tool Aqua Tribute. So, a couple of bad guys getting arrested, heck. Yeah, this one, this one for me, I sat during the week and I kind of just went over it over and over and over my head. So, we could agree that the guys in question here, they fucked up, they made mistakes. Sure, right? Not only the opposite, the operations security put it in the side. That's over here, that's not the here or there.
What I mean is that it took the left turn and they definitely broke some laws, they definitely caused a lot of damage. It's unfortunate because these young men, I feel, I wish they would have had another direction, another motivation, I wish they would have had an opportunity to turn their knowledge base to something for positive. Let me give you an example of what I mean. Last week, when you and I covered the 764 assholes, that's different. Those guys were so ordinary and extorting children for harm, in some cases suicide. That's a whole different thing. Those guys could do a thousand years, I don't care about those guys. But these two young men, they did something interesting that a lot of people weren't even talking about until now and they probably added another $400, $500 billion to the cybersecurity industry and in fact, I make a lot of people rich. Why?
Because they highlighted the insecurity of the continuous development and continuous delivery, or continuous integration, continuous delivery, that's everybody uses within all industries for development. They identified and created methodology for exploiting the supply chain. When I covered all of the stores, when it did the light LLM hack with the trivia, with this, with that, they figured out how to get around certain things. People were aware, theoretically, that those attacks could happen. They proved it. I just wish. I just wish that they could have did it as researchers and instead of going to jail for two, three years, they could have built the career of it. So I'm sad in a way. And I wish for them to... They wasted their skillset and that's what you're upset about. I'm upset about that, yeah. Because they highlighted something like I said, that people know is a thing, but cannot prove it.
But you've done this before with other hackers, where you try to speak to them and tell them the ways of the hard lessons you learned only by going down that same path. Sure. I don't know how you get to these kids. I don't know, bro. I have no idea. I've tried. I've been invisible at that age. You know what it is, is that look? So I read a little bit about one of the guys, Thompson. He tried to do the bug bounty thing that wasn't working. He tried to apply for jobs that wasn't working. I myself, you know for a fact. You know for a fact that I try to get to Cybersecurity and it's you prior to you and I ever meet it. And I just kept getting hit with walls and walls and rejections. It just was not working for me, bro. I think I got a job as a total driver. I cannot get a job in Cybersecurity even with a decade worth of experience in Unix and System Administration and Network of Generon and Cybersecurity Schools. Is it happening? You think because you didn't have a degree?
It could be, maybe, you know, there's other factors, right? Who knows? You're brownness. Yeah, maybe that played a part, you know, but the reality is is the, I think the degree probably played a big role in it. And, and, you know, maybe it was just, it wasn't my time, but my point here is that I made the same decision. That's why I'm a little sad. Because in my mind, in my, you know, teams in early 20s, it was like, well, I mean, if I can get a job and doing this here, I might so pop off. I might so be a geopolitical hacker, activists, you feel me? And I feel like they made the same decision, honestly. This sucks. Yeah, it definitely does. I wish the, you know, I agree with you. I wish their skillset could have been used, you know, to make them prosperous. And I bet after they spend a little time, they'll see the same way. It happens to everyone that they go through. This is, you know, they come out, but they still have the same skill set. Sure. Most of the time they put it to good use and they make decent money off it.
Well, here's, I'm gonna make a prediction for you. My prediction is at least one of these boys, the Thompson guy from down under. So that's my boys, my, my, my, my, all see people. Love my, all see people. The Thompson boy, I think, he's gonna do us two years. Right, hopefully it's just two years, it's been those two years. And then I'm hopeful that he hears this podcast and he hears what I'm about to say, which is brother as soon as you don't want to shit, go right back into research on that topic that you were exploiting, master it, and just start your own fucking business. Bro, you're gonna kill it. Two years is more like this, quick. That's assuming he gets the minimum. So Philippine nuclear and naval targets were hit by a suspected Chinese operator. So Hyundai O found an open attack stage and server that documented two confirmed Filipino, Philippine intrusions and pointed to a possible third,
which was an internal facing own cloud used by a nuclear research body and a WordPress site run by a marine engineer shipbuilding firm that serviced the Philippine Navy, a recovered CSV also list a project management app in the same ministry as the nuclear victim. What was taken from the nuclear site, the researchers reactor core component database, historic fuel inventories, radiation safety and incident records, authorized user lists, strategic IT plants, staff, CVs, passport and travel data, financial disclosure, and it goes on and on and on about nine gigabytes files taken from them. So it was. Yeah, the Navy contractor site, which is a WordPress admin created by a known light speed cash bug. What's going on here? Why are we putting sensitive data anywhere attached through a WordPress site? I have no idea and I would love to hear directly
from the Philippine search team, computer emergency response team. That's their closest or equivalents like a CSU, by the way. This should have never happened. You know, you deploy a WordPress site, that WordPress site should have nothing on it. You deploy your own cloud instance, that's what you put it behind your VPN. You don't need to have that exposed to the internet. These are two very obvious things with them. Not only do you have them exposed, you're probably doing some password sharing, password reuse, is obviously they must have moved from the WordPress site to a light speed server, got some stuff there credentials, maybe they found the old cloud instance own cloud. They need credentials to get into own cloud, at least right now until this is zero there. And then they logged in and boom, they got all these files. They should never have been on the internet in the first place. This is a tragedy, a tragedy in a travesty. I love my Filipino people, those are my people. But this was a blunder with the highest order.
So the attributed to Chinese is not because they take an credit, but because they're simple Chinese in the script comments, the docu strings, the logs and the folder names. So it looks like the Chinese may have popped this one. Yeah, yeah. Big shout out to hunt.io, they've been killing it, tracking these adversarial groups. So I have no doubt they did the diligence, so they're gonna, you know, just point at the Chinese here. I wanna say that's what I believe that, you know. But here's the truth, man. I mean, this is just a tip of iceberg. You know what's gonna have to happen now? Just gonna have to be like a very deep, confuited order to the Philippines, by the Philippine government, by their security teams. Bro, let me say something. For those of you that do not know that you are unaware of accurate history, in the mid-sulate 90s, the early 2000s and to the 2010s, some of the biggest hacker groups on the planet were from where?
The Philippines. And you would think that some of those hacker groups, you know, became legal, they got jobs, started working for the cert, they started working for the government. You know, come on, we gotta, guys, this is, this is 2026 now, we can't do this. Now, for the rest of you, listen to here. And you're scratching your head because you think you deployed on cloud server like two years ago, guess what? You are as victimizable as the Philippine government here, the Boopler facility leak and file. So, think very clear about whether you wanna keep that publicly exposed or not. So this one in this next story, heck, it's very close to home. So signals, contact discovery automatically sends your contact list information to the cloud. Researchers at V12 broke the Intel SGX trust boundary on signals, contact discovery service, two-septored object lifetime bugs in the enclave, let an untrusted host, not a random remote client, read enclave memory and then run code
inside the trusted contacts. So the feature that tells you which phone book entries are on signal, Android and iOS send the full contact list every 48 hours. It is on by default and queries are supposed to stay encrypted to an attached SGS enclave. So even signals on servers can't see the numbers, but the SGX encrypted enclave's RAM, ORAM is used to hide lookup access platforms. I always thought this was funny, that as soon as you open a signal and say go, it pulls through and you can find every in your contact who is on signal who's reachable by signal. Oh, that seems problematic. It doesn't seem very peer to peer. It seems very centralized. Yeah. Well, set out to the boys and ladies at V12. I've given them sounds before because they're research. I'm saying you read this article, I'm showing you read the content, I'm showing you, you know, you've only got your notes.
This is not a bullshit type of injection or a sequel injection. This is like legitimate, you know, deep research. They've identified and proven. They could have intercepted those Intel SGX packets with the contacts that were being synchronized, like you mentioned, and they were able to pull the, yes, we can actually pull people's contacts and were able to intercept that traffic. That's a problem. If V12 was able to do that, what makes you think that the NSA couldn't do it? Or the FSB couldn't do it? Or the Chinese couldn't do it? Maybe they have been doing it, and these guys just closed the hole. I don't know, signal. We need to stop this shit. God. Do we see any long-term problems coming out of this? Yeah, I think that's, well, signal already passed, I think they're like a same-day pass. They sort of that out already. But why do we need that? When I install signal, I only want to speak to the people that I want to speak to,
including a one-off, maybe a journalist, maybe I need to speak to one of your contacts, that it me up, one of your boys, maybe I need to speak to a customer that wants to have a private chat about, maybe sending me like some API keys. I don't need to know for my contactless, who is, and who isn't on signal. Yeah, I want my signal to be allowed my government leaders to have private communications about bombs being dropped and laughing behind scenes without some journalists listening to it. That's how, that's my dream. As a young man that growing up, that's all I wanted out of my signal. Well, maybe signal is in it, as much as we love signal. This is the best option available, right? Then I appreciate that you brought back signal game. Thank you for that. I forgot about it, but you brought it back and I got the PTSD from it. Yeah, signal team, we love you guys. And I even donate, if you just start taking out of the signalization culture, I don't need some little contacts, I don't need to know any of that. I don't want that.
And I don't think anyone that uses signal wants that either. Like, who the fuck wants that? If they want that, you know what they could do? They could download WhatsApp. WhatsApp does that. WhatsApp will tell you who of your friends with your contacts have WhatsApp, you could send them a message. I don't need that on signal. Yeah. Well, I've got fantastic news for you and for everyone listening. FBI agents can now hire sex workers and steal from prior employees, employers. So the FBI quietly changed their applicant vetting rules to some past conduct that used to be automatic to squalifiers can now go to case by case review instead of the immediate no hire. So paying sex workers and stealing from employer, bestiality or animal cruelty, the last two only if the conduct was before the age of 18. So you can fuck a dead animal as long as you were under 18.
These were mostly illegal in the US jurisdictions, which is why the change is landing as a standard fight against rather than just a paperwork tweak. So FBI headquarters policy applied to special agents and other bureau applicants, background checks, nays and wide. So now I felt very comfortable that there were no horse fuckers in the FBI when I was in the FBI. But now today's FBI allows pre-bubescent horse fuckery. We can't forget the sheep, sorry, those guys got a lot of love. That's just gross. Don't be gross. Yeah, this is, so that's your line, the horses after that. People from a horse fucker stand have to be able to fuck horses. What are you talking about? Well, here's where I think. And I don't know, I'm an idiot. What the hell do I know? Where is what I think? Maybe you want to be doing all this shit
and allowing pick fuckers to join the FBI, right? How did you push out all of your senior FBI agents and force people to retire and go to the FBI and politicize the FBI? Oh, fucking, don't do that shit to me. Cause you know what the fuck happened? Some of those were allegedly pick fuckers too. So they just didn't just get caught. Allegedly and there was no proof of it. But now proof doesn't even matter. I can't even imagine. So all these questions that they're talking about come up during your background check and also your polygraph. I can't imagine any button that I knew going to be an FBI agent be like, yeah, dude, I used to dittle a fucking dog when I was a kid. And like I wouldn't mean to leave if I was the run of the polygraph. They get the fuck out of here. What are you talking about? You're not getting this job. We're not giving you a government issued gun and the ability to arrest people. You make bad decisions. Well, bro, that is your bad decisions.
Like, I mean, bro, Lord, I have mercy. I, yeah, it's such a weird thing, you know, and out of all the things they could have removed, they could have removed like the marijuana thing. Cause you told me long time ago, if you ever just burned one. They've loosened it. Oh, they loosened it? Yeah, they loosened that a while ago. So yeah, when I was in it was like, you can't have smoked weed more than three times and it had to be before you're 18. So it's kind of like these rules, but for marijuana. But I mean, that's a big fucking leap from horse fucking to, you know, from weed to horse fucking. This is too much. This one's a subset me. Here's what I can't wait for over the next two to four years. Hopefully fingers crossed. Then we could go back to having an FBI, a bureau. It's just a law enforcement bureau. It's not cater to fucking politics. It doesn't have to fucking lose, or fucking X amount of thousands of agents because of bullshit. And it's boring. And he just do that job and that's it.
Maybe that's what they don't want. They know I'm boring. Now you got agents that are cool with the touching animals or whatever, B.C.L. Like animal cruelty. Like why would you want anybody that has done animal cruelty? They think that's just a sick fuck. I don't know. But you know, for these scenarios, for these scenarios, right? Yeah. There used to be a personality in the Hollywood Stern Show, Daniel Carver, remember him? Oh, yeah, sure. There was the dragon of the KKK. Yeah. And what do we say? When stuff like this came up, you would say, wake up, why people? Wake the hell up. Because you guys are going in the wrong direction. That's not a white people thing. I just don't know how many people we lost in the application process because of this. What did you look at? A lot of good people. Yeah. No, no, we didn't. I find with setting the line in the sand that you can have zero history of B.C.L. and animal cruelty. Oh, no, no. The B.C.I.D.A point, yes, I agree.
I'm talking about like the marijuana thing. I think you guys have a lot. What about the sex workers? You all right, if you get in a hooker? Well, I'm definitely open for like opening that up more to generally. Sex workers should be legitimized to a certain degree. So I listen, if it's consensual, bro, what's the fucking issue? What's the whole purpose of the FBI? Why do you have to have a clean of background? You can't have used things used against you. So let's say you're married now. You want somebody to go and you threaten, hey, I'm going to go tell your wife that you used to fuck prostitutes unless you do this for me. No, well, if you fall for that, you're weakest fuck. I'm not sure. You might as well go talk to him, have like an honest conversation with wife. Let me tell you something about your wife. Your wife was doing some shit before she met you. Don't say that. But I mean, she was doing Bible studies and hanging out in church.
Yeah, it was something in church. Let me tell you. But making food for the homeless, she's making mac and cheese potato salad for the homeless. Oh, that's nice. Yeah, I got you. Yeah, she's probably eating ass. Well, we listen, I had to pull out of think about that one. You did. But listen, no pun intended, but this is slippery slope. You know what I mean? We got a we got a pause here. I think the PCI is a limit. Anything beyond that is, I don't know where we're headed for. Anyways, FBI is lowering and lowering the bar. And I hope former FBI agents try him up and say, no, we don't need a lower the bar. The high standard is exactly who we want. We want to know who's standing next to us when we're going through a door or behind us. You know, I just, I don't like this. Maybe it's one of those like fraternity things. I had to do it. I wasn't allowed to do B.C. Reality so you can't be personality.
Well, I know the solution to this. No B.C. Reality? Aside from no B.C. I'm all right. This is where they need to bring in Chris Tarboz to the directory of the art. Oh, fuck that. He's gonna bring him back. He's gonna bring the bureau back to where the fuck it needs to be and do a great job because obviously the motherfucker leadership now, he's one of the fuckers, he's suspicious. Cash, you have that job. Well, he loves it. He's enjoying the fuck out of it. I have a job. Oh, yeah. I saw him the other day. I saw a picture of him with a badge on his belt. I had never seen a director besides Louis Free with a badge on his belt. Louis Free was the only FBI director who was actually an FBI agent. Like, when did the Academy and graduated? Wow. Yeah. Like, so he, you know, he, he was a, I think he was a cop and then he was giving FBI agent and then became a federal judge and then they put him back on as the director of the FBI. Isn't that insane? What, oh, it's not out to him. Rags to riches. Oh, boy. If being the director of the FBI is riches, I don't know.
No, but that's a, that's a fantastic resume. Big shot out to him or IP. I'm sure he's passed by now, all right? That's a long time ago. I don't know. I think Louis Free might be alive. I'm sure not to Louis Free wherever you are, only because you know, that's a hell of a resume. Wait better than the guy that built the bureau. Jesus Christ, that guy was, I don't even want to mention his name. He is, Louis Free is still alive. He's 76 and he served as the FBI director from 1993 to 2001. My boy. Whoa, oh, that's a crapola. Shout out to Louis. Damn, he was there for the first World Trade Center bombing. Yeah. He was there for the Oklahoma City bombing. Yeah, wake up. He was there for, oh my God, wake up and then 9-11. He was like, you know what, I fucked this up out. I think he was out right before 9-11. Oh, man, this is, woo. Yeah, it's a lot to eat. He wants to get up. Yeah. All right, everybody, support hacker in the Fed on Patreon. Big episode this week, if you guys want to catch a little bit
into my personal life, Hector digs deep into Jim Girlfriend and all those stuff she's got to say. So we'll see, he dug out deep in her. So we'll see how that goes. Safe hills, threat exposure management platform or the penetration services. If you guys need that, need some help with your stuff. Contact, hacked on LinkedIn, visit safehill.com or email them at info at safehill.com. Say I'm a hacker in the Fed listener and I need some help. Oh yeah, I'll leave you with a quote. Sharing is caring. Oh, it is, unless it's VD, you don't want to share that. No, no, no, no. Get your hacker in the Fed merchandise at hackerinthefed.com. Buy star reviews wherever you download and subscribe to hackerinthefed. Share us on social media. Tell your coworkers, tell your friends, tell your lovers, tell your neighbors, tell your mailman, tell your construction worker down the street, listen to hacker in the Fed. Yeah, don't, no. I don't want you, you guys don't listen. If you're in a BCL, you don't listen.
Don't listen, you're it. Hey, we haven't had a shout out for a while for a dick pics. You want some dick pics? You want people to send in the dick pics? No, no, no, 10 things. What the heck, come from a bottle of one or two? You said before the show started, you'd be like, man, I haven't seen a good dick pic in a while. Nah, I'm good, bro. That's all you. If you want to send Chris a dick pic, you have christenacrinthefed.com. Enjoy. I don't know about that, but that doesn't mean I'm not. I'm not gonna not look. Yeah, I don't think. All right, friend, fun show. All right, brother, man. Much love, cheers. Cheers.
More episodes
More from Hacker And The Fed

AI Is Getting Access to Your Private Messages
Hacker And The Fed

Someone Tried to Hack the Court With an AI Prompt
Hacker And The Fed

The Cybersecurity Industry Can’t Keep Up With AI
Hacker And The Fed

The $90 Million Crypto Wallet Disaster Nobody Saw Coming
Hacker And The Fed