Skip to content
TrackPodcasts
technologyNov 27, 20251:01:24

Microsoft Admits Everything’s Broken, What Now?

About this episode

Chris and Hector cover the surge in insider-driven cyber incidents, the escalating aggression of Scattered Spiders, a CrowdStrike employee caught leaking internal data, and a retaliatory attack that shut down thousands of accounts. The conversation moves through Microsoft’s admission that core Windows 11 features are failing, the FCC’s rollback of telecom security requirements, and the collapse of federal cybersecurity capacity after recent government shakeups. Join our new Patreon! ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠[email protected]

Get every episode summarized

Each time Hacker And The Fed publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

1,288 searchable segments. Every word is indexed and playable.

Microsoft Admits Everything’s Broken, What Now?

Hacker And The Fed

0:00
1:01:24

Full transcript

Hacker And The FedMicrosoft Admits Everything’s Broken, What Now?. Machine-transcribed; use the interactive transcript above to jump the player to any line.

If you want to hide ship, if you want to tell a user that hides your from their wife, how are they going to do it? How do you hide your unit searches? Any idea? This though fucking do it. It's not worth it. You know what I'm of that lifestyle? Because what's in the lifestyle? You start going deeper and deeper into it. Now all of a sudden you're fucking toward doing like dark web gambling. And then you're like, you're in the fucking market page. The market place like, you know what? I did hear about heroin in the 80s. I mean, just try a bag out. You know, it's not worth it, guys. You know, it's better to be happy than not. And fucking cheating your wife is the definition of a legal set. Hector Montseger was responsible for some of the most notorious hacks ever committed. The honest special agent, Chris Tarbel. Hackets and FBI informants. It's anticipated some of the world's most infamous hacks had caught up to $50 million in damages. It life in the shadows. Cyber attacks on the rise. Welcome to Hector in the dead.

I'm Chris Tarbel, former FBI special agent working my entire career in cyber security. And I'm joined as always by my friend and podcast co-host Hector Montseger. Yeah. Yeah, I was waiting to play. Hector's a former black hacker who once faced 125 years in prison for as many years of hacking under the code name. Saboo. Our story's colliding June of 2011 when I arrested Hector. And then I convinced him to work with me at the FBI. Hector's now a red teamer, researcher, cyber security expert and co-founder of Safe Hill. Hey, that sounds really cool. Hey, how you doing? How you doing, brother? I'm doing well. Thank you for asking. Let me say happy Thanksgiving. Yes, right. That's right. By the time the source publishes Thanksgiving, happy Thanksgiving. It'll be coming at 5 a.m. on the morning of Thanksgiving. I'm sure you'll be eating some turkey and watching some football. Oh, yeah. Probably in some sort of coma. Yeah, nice little food coma. Have some nice turkey with some stuffing.

Big fan of the stuff. I will tell you. And if those the listeners who don't celebrate Thanksgiving, start celebrating Thanksgiving, it's one of the best holidays. Just pick the day that you get together with your friends and your family and your neighbors and you just have a nice meal and you're just thankful for being with each other and having each other. It's the most important thing in life. All these people, I'm sure there's a lot of people out there right now. They're chasing their careers and they're chasing fame and they're chasing money. Telling your brother, I've lived for a while. I've had it all. Family, friends and neighbors and people that love you and you love them back is the most important thing in the world. Oh, yeah. Well, listen, I want to lose people. I've come to realize that it ever realizes actually a long time ago that, you know what? I may not have much, but I have everything. My family to me is something that I really appreciate. I adore friends as well. So yeah, Thanksgiving for me is just getting together,

spending time with them, being with them, laughing, joking, eating some food, you know, relax and watch your movie or something. Maybe a game. So yeah, if you're not from the US, you're not really, or Ad or you don't really celebrate Thanksgiving, forget the history of it, right? Forget the bullshit. It's just an opportunity to spend time with your family. I think it's great. So we'll do the traditional Thanksgiving table. What are you thankful for this year? I know you're not thankful the obscene list is coming out. Yeah, you keep fucking with me. I am not going to that list, bro. I know, I know it's Sabu is on the list. Sabu was on the list. Not even Sabu. Sabu went to the island, not heck. Sabu was a jerk. What I assure you, he was on that list, either. I'm thankful really, honestly, for the people that I have in my life. No, seriously, I've had some of amazing folks that have had supported me and have been there for me during some of the roughest times of my life, even the cool in you.

And so, thank you. Yeah, you've been a big part of my life. But there were times, brother, when I was locked up, I was in my cells, and oh my god, it's terrible. What am I going to do here? And so, I was trying to remember in myself that poem is Victus. Remember that? That was a good one. And I would try to think of ways to just keep myself motivated and going. And even times now, right now, right after this podcast, I'll be here alone in my career, but do that in my little apartment. But I could call my family, call my franco, call you up. And that to me means everything. So that's what I'm thankful for, having a good, support system of good people in my life. That's really important for me. For you. Yeah, I'm thankful for, I obviously family and friends and all that. Like I said, it's been a great year. Sure. Transition, not that's for transition. Don't get excited. That's what to say, even transition was great.

No, but the podcast is growing. Again, this may sound corny. I'm very thankful for our Patreon listeners. We just recorded the Patreon. And again, I said it over there. There are best listeners, because they're keeping the stupid commercials off of the show. I do not want commercials on the show. I hate podcasts with commercials. So very thankful for those loyal listeners that keep growing. I'm thankful for you and me in my life. I know we met under very odd circumstances. And not many people can say that, but I do look forward to all of our conversations. Recorded and not recorded. I have to be honest with the not recorded ones are even better. But yeah, my family, my friends, in this. What about your buddies over at Safe Hill? You guys did a great thing this year. You got to be happy, very thankful for what you built over there. Yeah, with Safe Hill, what I'm super excited about is like the effort and the teamwork to me that's a buyout.

The buyout? Yeah, all right. Every startup streams will be bought out. We're not there yet. But I've teasing, I've teasing. But honestly, it's just been the team and they're fantastic. Yeah, you got a great guy's ain't got us. Oh yeah, they were all fantastic. They're a really cool team. And but not only that on the business side, on the personal side, like I said, don't talk with these guys and the ladies. They're a chopper about life and what's going on with them. And they're just like, they can do the help them by all means. You know, I was having a conversation that that long ago, maybe a few weeks ago, somebody was like, you know, kind of prob it. They was like, I want to see you pay yourself. What am I doing? In some cases, I'm paying some of my people more than me because I see their value and I see that they probably deserve more. And I'm trying to get them to that point. And so I don't mind paying myself less than them. It's not an ego thing, right? We want, I want everybody to be happy. I want the team to succeed.

Safe Hill's been a beautiful project. And a beautiful business, beautiful team, I love it. Good, when this comes out, we'll have another event. We're going to host a happy hour, the week after. And hopefully, we talked about it. Hopefully you're talking to some of your people over there of how we're going to have, be able to invite some of the listeners to the happy hour. Oh, yeah. Oh, yeah. Well, we do know that a lot of our listeners are in the C-suite space. You know, we've had people reach out and, or we do events, we know a lot of people that listen to the show that are like C-so's and so on. Yeah, so we're going to make that so fun because it'll be like semi-technical. We're going to the C-so stuff and the technical stuff. Or we can just have a session where we're just talking, you know, crap hola about cybers. Yeah, I love the live shows because it's just like the recorded shows, but with people raising their hand and asking questions. Types. That's fun. I enjoy it. So it's a little bit more stressful because you can't edit something out if you fuck up and say something wrong. But it's fun. But, Kassel, you sound like a bro, you've done such a great job. Like you.

Oh, I appreciate it. But I don't, I'm not even real talking about my tan in my balls as much over there. Yeah, because you know, it's, it's, it's, it's, it's a little weird with them in the room. Yeah, I'm sure I got a little comfortable. It was like 40 people, 40 people staring, actually, huh? Neither one of your balls. But that's all right. Oh, we have fun. We have fun on the show. We have fun over there. So it's good. I'm glad we have this. I'm glad we have built this into something that we, we look forward to doing now. Oh, yeah. 1000%. So well, guys, happy Thanksgiving. Yep. Hopefully you're enjoying yourself. Hopefully if you, you don't do Thanksgiving, you're going to do Thanksgiving because it's, it's a great time just to sit down and enjoy a meal with, with friends and family. But you love, so let's get into all the cybers. And then you have a rant today. I do have a rant today. It's going to be juicy, a little spicy. I think I think the function of doing it. All right. I'm going to hurry through these, these stories just to get to the rant. I'm super excited. So Hector scattered spiders who we talk about probably about every week now, they just

launched a new telegram channel. And the activity shows a clear escalation in both tone and targeting. So on November 21st, scattered La Pous Hunters, which used to be La Pous or whatever they call themselves scattered spiders and shiny hunters, they launched a new telegram channel with they're called part seven with 88 subscribers. And they're bragging about 300 plus victims in four months, claiming more profits going up and up and up and teasing a big reveal on November 24th, which is today. Yep. That's very record this with threats against researchers and companies. And they've named some of their hits. They AT&T Verizon, LinkedIn, DocuSign, DHS, the Department of Homeland Security, Disney and many more. And they're likely using social engineering via vision or SimSwaps and also stolen credit cards and insider recruits. And they're focused on a quality target, possibly with customer extortion over the standard

ransomware. So they're ramping it up, brother. Oh, yeah. No, they're pretty busy. They're going with it. It's like you said, the rhetoric, they're very aggressive now. And the number of different targets that they have is pretty insane. We talked about it briefly offline. They initially had that big hit with Salesforce Drift a couple months ago, right? And now they have another one, Gainsight, which allows them to compromise a whole ton more customers like DocuSign and Sonic Wall F5. But F5 really hard last month as well. So yeah, they're just escalating. They did have at least one member arrested at some point. They've had some affiliates arrested over the last few months. A few weeks ago, we covered the story where, or even last week, where international law enforcement are hitting bulletproof hosting so they're taking out some of their infrastructure. Yeah, it's pretty wild, man. It's pretty wild time. Yeah, I don't see it slowing down either.

These guys seems to be evolving, coming together a little bit stronger. And they're really kind of with taunting law enforcement. So we'll see what it has. You know, they're having tour leak sites for their data drops. So maybe there's some insight on that. You know, there's some decentralized team coordination and some threats against some Austin guys, whether they're going to get docs or not. But I get these guys are just going to start ramping it up more and more. Or maybe this is exactly what they want. It's guys like us sitting on here talking about them. It could be, right? It's all news is good news, whether it's bad or not, right? So it continues to propagate their name, their brands of shit. They're really the most like our reason to stuff like this. We did stuff like this where we would think, you know, do a story like, hey, we're about to hit, you know, some law enforcement, you know, whatever. We propagate, propaganda is there. So. Did you, when you were the bad guy, did you follow the media reports about you?

Yeah, I followed the media reports and then basal to media reports. I would then move accordingly. I mean, HV Gary's, for example, right? And you know, when I saw that they did an article with financial times or whatever was a basal of the article, I created a new operation. So against the company. So it was, it was something that we definitely did. I did at least. I don't know much about the other because I can't speak for them. But for media, I definitely followed the news. Let me ask you a little bit. We'll go off a little tangent. Me and my buddy Mike, we had a conversation about this. Now, I have never really been part of a news story where 100% of the news was correct. Yes. It always was off. Have you ever been part of a news story that was on every story? Almost every fucking news story is almost incorrect. Even once I do the interview with them, it's sometimes incorrect. And I'm not really sure why I've come to realize that maybe it's the way I communicate. At least for the ones that I interviewed for, right? Or I've talked to people before publication. But even the ones about you about an operation unit or something like that, it's wrong.

It's all wrong. But I think that's why I'm not to get political on the free show and all that. But I think that's why media gets labeled with fake news because there are so many mistakes in it. What do you believe in? Don't believe. Well, that's a good point. I mean, it's hard to look at news outlets, right? Like CNN or Fox News, they're like, yeah, you know, some of these are right. Or what? It's hard because it's just like you said, a lot of it is incorrect. A lot of it is exaggerated. A lot of it could be information warfare. You have to keep in mind, these journalists are not, a lot of them are not like, you know, talking scholars in the sense that like they have page D's and this or that. But some of them are so pretty. Yeah, it's a little pretty, you know, but a lot of these guys are just really good writers. They're good writers and they're good enough writers that they were hired by their publications.

But a reality, I've met some really degenerate journalists. I've met them. Oh, you've got some good, you got a good story about a journalist in there. I don't know if you'd ever go public with it. You got a good one. I've met a lot of journalists and I've sat down with them one-to-one and this is great guys. Don't get me wrong. You know, there's some really good guys that I met and then there's some of them that are just like they're, they're fucking crazy and they're doing like, co-conshit and fucking, you know, performing fillet show in the back room somewhere in the fucking club. You know, that's just the dudes. That's just the dudes. We're never so about the ladies. And so when you have these people that are more fucked up than you and I, wait, you're saying we're fucked up? Absolutely the audience members. The audience members, you know. Not me, you're in the club. Yeah, I could, yeah, yeah, it could include you somewhere. But what? Yeah. But no, they're humans and they make mistakes. And so this is why I always tell people in my family, in my life, hey, you see an article, it sounds pretty like out there, you may want to look at other sources, then you can, you know, you leverage corroboration,

right, between the different sources. I like ground news. Ground news is pretty dope. And I always shout out to them. They're not a sponsor. They're not a sponsor. They're a sponsor of every other podcast in the world. Not this one. But it's dope because they don't take one story from like 10 different sources and it'll give you some perspective as to how it leans. And then it's on you to figure out whether or not you're going to be online with either either side or you take enough of the stories to kind of come from your own conclusion. They try to automate that for you, but in reality, in real life, you should be doing this really. They're talking about the folks, right? We should be doing that. So when it comes to me, Chris, I've had some of the wildest stories written about me. Okay. The big one. Remember that whole magazine? Remember the journalist and what's like the girl school and like starting harassing the girls and sitting next to them and lunch? That guy was such a scumbag. And he did a big publication. So those that don't know, this is when Hector was working with the FBI and the FBI had not

announced he is doing this. There was a journalist that went to Hector's girl's children's school and it was harassing them. Oh, yeah. Like legit harassing them. Like a grown man sitting next to a five year old in the lunchroom and trying to interview her. It was insane. And so anyways, he got a really upset that he couldn't harass children in school. And so he published a skating article on the New Yorker magazine, a New York magazine, if we are which one. And 80% of his lives, he even interviewed a fake girlfriend that I never even knew this little woman was and he came up with a whole bunch of shit in there. So yeah, I'm very curious. I'm very sensitive to journalism and news stories reporting. Yeah, it takes a lot to convince me these days. Yeah. Yeah. Sorry. We're not for a little tangent off of the cyber's on that one. I don't know. That's all good, man. A little tangent to the story. Sort of leads off this story. That's why I had to leave with the story is now CrowdStrike fires suspicious insider who

passed information to hackers. Yeah. So in October of 25, CrowdStrike caught an immediately fired an employee who was sending the screenshots of internal Octa dashboards and other sensitive portals to outsiders. The screenshots contained live links and metadata, but no source code, API keys or customer data. The employee was the only vector. No remote hack of CrowdStrike was reported. And they call themselves again, scattered lap, lap hoos hunters. And they put these screenshots on that new telegram channel that we were just talking about. So this guy sends inside information to these guys. They posted on a public telegram page and he gets fired. Yeah. Yeah. What do you, what do you think's behind all this? Well, I think that there's a problem with security companies who get too deep into like threat intelligence.

Sure. And I would have called it like a Stockholm syndrome, but some of these, some of these employees get so close, they feel like they're part of the system or they feel like, hey, you know what, I'm going to give them a little bit so they can give me a little bit. So here's a screenshot of our platform, not realizing, bro, that you just, you just really, you're violating your company's policies. That's one, you violated all ethical and professional boundaries. But beyond that, what you also have done is you could have potentially hurt your business at a point that, that there would be some real loss. I'm not sure what the stock market looks like right now for this after this. Maybe they had no impact. But that's not going to go. Well, no, CrowdStrike dip two percent of this happened. Oh, yeah. Yeah. That guy was an asshole. He really? Now, that was nothing compared in July 24 when they took down an airline. Yeah. That was a real dip on CrowdStrike. But yeah, when you got people inside the company putting information out to hacking

groups, now when I first read this, I was like, well, maybe this guy's trying to do like undercover operation himself. You know, look, I'm going to be a hacker. I'm going to get some chat logs. I'm going to get some inside information. And who knows? Maybe his boss was directed this way. And he's the fall guy this whole thing. But, you know, there still could be criminal charges to come out of this. Yeah, no, this is terrible, especially with the 2% drop. That's probably what I was going to hurt him the most because, you know, you could forgive an employee being a dumbass sometimes. But when it affects the stock price, then you have to add to investors. You have to add to stakeholders. But not only that, when you're like one of the biggest eDRs, if not the number one eDR on the planet, and you don't work with the government and airlines, like you just mentioned, something like this could erode kind of spirituality integrity, right? They could lose billions in contracts as a result of something like this. So yeah, I could see this guy totally getting hit with some sort of charges.

It's just strange week after week, ever week, we're now covering stories of people in our industry, either getting fired or even getting arrested for sharing information with what we call the adversaries. Well, I'm liking the accountability. So we've seen some accountability, right? You just mentioned a couple of guys have been arrested for, you know, big insider threats. And that's a beautiful thing. What we're not seeing are the leadership and accountability. That's something that's still missing, you know. We're seeing the opposite of it, but I think it might have to be part of a rant in the near future. It's part of something, it's part of something. But yeah. So we'll see what happens with this one, you know, this guy, I think charges are going to come to this guy. They're going to show or they're going to try to pin this guy was part of the group, conspiracy charge or something. You know what this reminds me of? This reminds me of that Ellie time story. We had the journalist wanted to give us access to Ellie times. It's a little bit.

Yeah, I mean, user name and passwords are a little bit more egregious than some screenshots. But, but yeah, now I can see where the motivations, the guy we wanted to like provide some sort of evidence and head control or fucking cross-checked Falcons dashboard and some other shit. You know, it's, it, it smells like it's not the same obviously. Not one to one, but insider threats are always scary because what the hell can you do against the insider threat? You know, yeah, I guess on the other side of this, I mean, we have seen and we reported that these groups are doing increase in recruiting insiders. They're paying. So, you know, let's see, let's go through this guy's crypto and see what's going on here. Maybe, maybe he's paid on this. We'll see what happens. Next one, Hector, former contractor admits to hacking employer and retaliation for termination. Whoa. Another insider? No, man. The IT contractor, Max Schultzel, was fired the same day with an hour's he impersonated

a still active coworker to give valid credentials and then used a remote power shell to reset 2,500 active directory passwords to the same weak value, instantly locking almost everyone out nationwide. Then he deleted the logs, the cover is tracks. So, you know, he gets fired and he goes in and he just screws the whole company. Now he's being charged by the US Department of Justice and he pled guilty in the US District of Southern District of Texas to intentionally damage under 18, USC 1030. It's facing over to 10 years in prison and fines. It's going to be sentenced to the end of January. This is a tough one because this guy just wanted to hurt his company. He could have done worse. Look at his methodology. Let's think about it real quick. No malware, no ransomware. He used the tools that were available to him to close the damage.

He could have did so much worse. He could have destroyed AD, active directory and completely just took that company offline. He could have removed the backups. I'm sure he's back and so accessible over active directory like always on the same flat network. By the way, I'm not saying this. Let's be leaning on this guy because what he did. But he could have did so much worse. He tried to pull a Saudi aramco without the destruction, basically. Yeah. He essentially shut down the company. He locked out 2,500 users all at the same time. Now you have IT that's got to spin up to get those accounts open. But while they're doing that, those people are not productive. You're paying them to be productive. They're estimated to be over $862,000 in damages. Yeah. And remember, one thing I learned with the Fed is that when it comes to medicine, it really ties back to damages.

It raises your guidelines. Close to a million dollars in damages. So that's going to raise them up. They might hit him with the 10 years, honestly. I'm going to say, I'll give him 46 months. Six and a half. Oh, six and a half. Yeah. I'm a gambler, man. I put the over under six and a half. So let's remind ourselves of the sentencing. I'm going to go with like 40 months, right? No, no, you get to pay over under. I said the number. You get to pay over that or under under under six and a half. All right. I'll send a counter rewind. All right. We'll add to the show. So January 30th, what will it? It sucks, right? Because you know, the dude obviously made a really terrible mistake. I wish he would have went out for a beer or something before he did what he did. You know what I mean? Like, come on. You know, I get these fuckers every time. They're Google search history. Oh, yeah. This guy Googled how to delete Windows event logs. Oh, no. Jesus. No. Like use an incognito to a tab, brother.

Hey, I'm kidding. That should don't work. That should don't work. That's a scam. There's no such thing as incognito. It's all being sent out there. You're sending out a Google search no matter what. So yeah, that is anybody that's trying to hide their ship from their wife through incognito in a work. If you want to hide ship, if you want to tell a user that I had shipped from their wife, how do you do it? How do you hide your new searches? Any idea? Don't. Just don't do it. It's not worth it. You know what I mean of that lifestyle because what's it like that lifestyle? You start going deeper and deeper into it. Now all of a sudden you're fucking toward doing like dark web gambling. And then you're like, you're in the fucking market page. The marketplace like, you know, I didn't hear about heroin in the 80s. I mean, just try a bag out. You know, it's not worth it, guys. You know, it's it's better to be happy than not and fucking cheating your wife is. You know, yeah, this was a big reminder. Remember this guy got fired and he's still had access.

If you guys are part of a company, you're off loading of a employee should involve taking his access away, his or her access away before you tell them. Sure. You should start locking accounts out long, not long. If you're going to do it that day, do it the morning, just start shutting computer access off. Yeah. Well, we like a couple of years ago, we read that report from the Department of Interior. Remember that? And they said like within the governments, with a random sample of agency to be tested, they had like 26, 22 to 26% of employees, government employees that were still active, that should have been on board. Right? So that's a big problem within the government. It's a big problem within, you know, organizations I'm looking at. There are some cases when I'm doing like an active direct your audit and I'll find like, let's say the company has like maybe 5,000 employees. They have 22,000 accounts and 80% of them are inactive but they're not removed.

Technically you could still leverage those accounts. It's a big problem. In fact, I know this at least once he's so listening right now, we hold on a second. Let me check out our, you know, user director. See what that was going on there. Yeah. Well, I mean, you're always talking about how wide is your attack service? Sure. If you have 17,000 extra accounts. Oh, yeah. Sit down there. Oh, yeah. So yeah, like I said, you know, just, you know, DOJ saying in 2025 that insiders and retaliatory attacks are surging, they're up 28%. Oh, again, just you guys running a company out there, you know, push for automated, deep provisioning tied directly to the HR systems, you know, HR people that should be part of the off-boarding. There should be a toggle switch to kill their account, kill access to their account. You're going to want to forensically, you know, keep the logs associated with their account and activities on their account and all that stuff. But you should kill, you should kill the password and access to it to, you know, administrator accounts only.

Yeah. And this is where the conversation about like sock to compliance becomes a thing. Like, I know there's some frameworks that people are like, yeah, yeah, yeah, I follow that. But not really. Sometimes like a sock to compliance would mean that, yeah, you've created policies and you've created, you know, user groups and you've distributed group permissions and all that. But the cool thing about that is while you're going through sock to compliance and you're getting to level one, level two, the cool thing is that by the time you're done with level two, even by level one, you have like the deep provisioning, okay? Your services are synchronized, connected through, you know, IDP or something. So even if you have like Slack and Google workspace and all these different services connected together, the moment you do the same with user from Google Workspace and the same with that group or user group, if you have something from user, then they lose access to everything else, right? So just, you know, yes, it's a pain in the ass to send it all up. But trust me, it's a couple hours of work.

Maybe a couple days of work, depending on how big your company is. And you wouldn't have a problem like this. But remember, part of this guy's methodology was knowing enough about his colleagues, he was able to reset where the passwords, right? Well, maybe, well, it's colleagues, but the organization, he knew how, he knew how the organization works. Yeah. So that part, you're not going to be able to get away from it. Yeah, that's exactly right. So well, you have something like that. Here's a story like this, you have to look at your, your motor supply render. Rather, you're the way you operate and the way you, you know, on board a deep provision and the way you reset accounts, because you want to make it so that it's difficult for someone like this, even an insider to be able to reset your accounts, you know, you have to, you have to, you know, add in technical controls to avoid this stuff. I know it's easier said than done, but trust me, man, you got to get to a point where this is not going to be a thing. I've been saying for years, Chris, there's going to be more and more insider threats and we're seeing those numbers pop up now, you know? And now the Department of Justice backs you on that. You were just a few years early on saying that. A little early year, but you are definitely not your dominant.

Oh, shit. I like that. Shit. All right, Hector, Microsoft finally admits almost all major Windows 11 core features are broke. What? What if breaking news? Everybody would it feels like breaking? I was a no one. So the start menu task bar, settings apps and file explorer failed to load or crash on first login after updates. Right now this only affects Windows 11 24 H to and earlier 25 H to builds in fresh profiles of non persistent environments. So the root cause of July 25, culminative updates and the later broke the provisional order of core X AML, win UI three system. That's two. There's a bunch of BS, some XAML, when you are crap. Basically folks, they release patches and they broke a lot of your systems.

There's a lot of you guys in the around, you're probably listening to us from your phone because maybe your system isn't working right. And by the way, you know, the non persistent environments is actually pretty huge Chris because okay, so you know how we talk about like, hey, if you're going to onboard an employee, you should probably give them their own workstation laptop, right? If you can't afford that, then you need to, you know, you got to figure out a way to separate the employees personal life and the professional life. So companies have gone with like VDI or auto pilot or something, basically virtualized desktops. That's what's affected here. Bro, those are millions of people that are affected by this. This is no joke. There's no easy pickings here. This had to be really fucked up for Microsoft to admit that it was all broken. I wonder what the, what was the breaking point for them to actually admit it? Maybe somebody with a spine on the board of directors or some stakeholders. Well, now I know you're lying. There's no spines in that room. Come on.

You know, you know what's happening over there. Well, they've been losing a lot of contracts. They've been losing money. Ever since the whole Fiasco with Pete Hankseth and the Chinese coxorts, right? Ascorts? Yeah, yeah. Microsoft has been getting hit hard and it's all self-inflicted wounds. This is another example. I don't know what the hell is going on in Microsoft, but they're at this point, they're fucking virus. Yeah, they're getting hit left and right. I don't know what's going to happen going forward. I don't know if people are going to start moving away from Windows products. It's really hard for me to believe that in America that we're going to move away from Windows. We're so Windows dominant. Well, and this is why I'm not a Phantom Monopoly, brother. You know, I'm not a Phantom Monopoly's Addle. You know, there was a point when when computers became really popular, it was about the 90s to 2000s and every time you wanted to a store, best buy a target, PC, Richards, whatever, whatever story you like to buy stuff from. These Windows machines came preloaded with the computers and so you had to deal with it

with force to use this shit. Forced to use this crap. You know, I know we have a free market. Technically, you could have bought a computer and then install Linux on it. But Linux at the time wasn't very user friendly. Now it is. They're a little bit too late to the party, but people are used to Windows. And the problem is when you have them in an office like this, you start to not give a fuck anymore. This right here is an example of not giving a fuck about your customers. This shouldn't even be a thing. It's disgusting. It really is. It is. We'll see where it goes, but I don't think anything's going to change. I don't have high hopes. Oh, yeah. Jerks. Bunch of jerks. So the FCC eliminated cyber security requirements for Telecom companies. And so November 20th, the FCC voted two to one to remove cyber security mandates for telecoms, which end rules for network security, patching. Just watch it your face and incident reporting, triggering a Republican pushback, despite

China's salt taffoon attacks on AT&T and Verizon. So no force fixes for 5G and 4G flaws. And it leaves routers and VoIP systems exposed to brute force attacks. And small carriers can't afford a volunteer fix like the zero trust stuff. So this does not seem good, Hector. Yeah, I never understood this. I don't mean to get political crisp, but the Republicans will have a reason. Like I get it, right? Let's government overreach again. I can understand what they're coming from. But cyber security is clearly a weak point for us here in the United States. And the one thing that I'm surprised by is a certain party pushing for the removal of whatever the fuck that we have. Cyber security mandates, guideline requirements, security, advisory boards. These are all things that actually help us. Well, we have to look at it logically.

The Republicans are doing this because they think somebody is handcuffed or some regulations styming growth or something like that. Or at least they're trying to articulate that to make it sound like all the fucking speed cameras that are done in the name of safety. They're not done in the name of safety. Yes, they stay in it safety, but it's for revenue. So this must be the same thing. So what are they touting? What benefits are they going to get by rolling back all this shit? I mean, it's okay. So the no force fixes for 5G and 4G flows. So let's say you're a telecom AT&T and then there's a new vulnerability pops up for that protocol. You have to spend five $10 million of fixing. That's just part of doing business. But that would eliminate that. You don't have to fix it now if you're a telecom. You don't have to set any filters or block those routers or force the upgrades of routers

or updates of routers like Cisco, Juniper. Smaller carriers don't have to invest in SIMs or invest in zero trust. So what this does is it roads like the national security of our country because a lot of these telecoms are getting compromised. Remember, it wasn't long ago that you and I covered the Chinese typhoon, salt typhoon, focusing on compromising our infrastructure, including telecoms. This right here, my friend does not help at all. You mentioned that the small carriers can't do things. It's sort of, I guess they're saying it widens the cyber gap. We're all ISPs. They can't match the big carrier defenses. It's good point. So is it a push to put everybody into the big carriers? Absolutely. Like, big conspiracy hat. It's a push people over towards the Verizon's that will, you know, or the team OBS or whoever responded to subpoenas for, you know, they're the big thing.

We're US senators. They're telephone records of subpoena. Sure. Sure. So one company responded, one company didn't. So are we just, we want more users in there. So we can have, you know, big daddy watching us. And trust me, I used to be a big daddy. Yeah. Well, to some people, to some of us, you still are big daddy. Like, like, like, the big Chris. You know, there's party arguments on all sides with regards to this, this scenario, which is like, there are. Again, I just can't find the Republican side of this one. Of what, what, who these benefits? Why, why are we doing it? It saves companies money, Chris. That's what it is. It's part of money. They got lobbied by somebody. Are these the same companies that are laying off thousands of people every day? There was another big layoff today. Sure. I think Verizon laid off a shitload of people. This is why I don't understand why we, we fucking, we, we fold to these companies. They don't respect our people that are, are, are slow with innovation. They don't want to pay for cybersecurity.

So then, and they don't give it, two fucks about, you know, its customers. You know, we, we, we joke our joke, Chris. I'm sure you remember a T-Mobile telecom, right? They get hacked every other month. All over the world, if you ever use T-Mobile with your life, your information is sitting in someone's computer somewhere. Zero consequences. Now, not only do they have zero consequences, now they don't even have to upgrade their systems. They could save money, Chris. And so like, I don't get that shit, you know? It just seems really, it seems really strange. We're coming off a big China link, S.V. and Osh, two R telecoms where they, the China was going after our leaders. They're going after Donald Trump's phone and everybody's phone accounts and all that sort of thing. And then on the flip slide, you got guys like Uncle Pete that are trying to make things stronger over a Department of War. Like, the focus on cybersecurity and then taking the break off and going, they're reversed the telecom space. It just doesn't make any fucking sense to me. I would love someone to get on here that's smarter than me and it can figure out what the big picture is on this thing. What if Uncle Pete wasn't even aware that this was happening, right?

I'm sure he's not. I mean, what is he, how was he connected anywhere to the FCC and their eliminate, like you think that guys got time? I would roll and back then. I would love for this story to get to him and be him, freak the fuck out because he's the only one right now with his team that's trying to do anything with regards to cyber security in his country. Like, it's fucking crazy. The dad's a thing, but it is. And so something like this, I'm sure he'll be like, what the fuck? But the FCC. I'd like to have a tickle fight with Uncle Pete. Yeah, after a couple of drinks, you know, hang out, have some drinks, you know. We'll tickle fight. That'd be nice. We'll tickle fight. Not the wrong way to take two men having a tickle fight. But the FCC is in a weird place because in a way, they're like an independent agency, you know? But then on the flip side, it's just to be shit like this. So what the fuck is the point of being an independent agency if you're still going to be lobby, brother? What the fuck is the point? You're not helping anybody. And part of my language. But still, this pisses me off.

And then you have these freaking weak ass Democrats. The best they could do is set a Senate hearing. And then nothing happens to the Senate hearing. No. So like Democrats, if you guys are listening, set those fucking Senate hearings are crazy because they don't even let the person talk. It's literally just show boating in front of the cameras for themselves. Yeah. You know, and look, there's 350 million people in this country. Okay? According to this, according to your notes here, this is definitely going to widen the cyber gap, especially for rural ISPs. You know, God bless the rural ISPs. They're trying their best to provide resources or services to clients. They can't do what T-Mobile does. When T-Mobile will give you like six months free. And then after that, a two year contract at $99, they can't do that. They can't afford that. They're the ones that are going to be hurt by this. Yes, it costs the money to upgrade their shit. But on the flip side, you know, you can have these big companies charging even less now because there's less spend and these rural ISPs are like you said, it's going to force

these rural users to use AT&T, to use Verizon. It's going to force them to use Comcast, right? That's not a free market, Chris. That's not. Starlink. Starlink. There's other alternatives out there, shit, but it's going to force people into to kill off these rural ISPs. That's a shit. That's not a free market. That's bullshit. I want my mom and Papa ISPs. Yeah. I want my dial up to work. Yeah, that's very true. I still, I still, then, you know what, I used to have a dial up account. Let's back up. But I just realized my apartment is even wired for RG 11. So what the fuck is the point? I know. You can't do it anymore. If you have RG 11, you can, but you can't know. Our friend, we've reached that time of the show where it's all about Hector's reign. Oh my God. Chris, audience. My friends out there, I have something for you. It's a rant. In the rant, I'm going to try to keep it as non-political as I can, but there is politics

involved. Okay? So just bear with me, know your voice as neutral as possible. What upsets me about this story about the rattle is the impact on society. That's really where I'm at. So Chris, I'm not sure if you know this, but yesterday was like the official day that those was disbanded and merged into the OPM. Did you know that? No, I did not. Yeah, so it's a big story. And so what upsets me about the story is that, you know, a lot of what we discussed, even I remember getting an email from one of our listeners saying like, I don't know guys. I'm not sure I can listen to you guys anymore because you guys are political. It's not about politics. We're a cybersecurity podcast, basically. We talk about cybersecurity. And I had trust me. I had many options for today's rant. I could have come in here. I kind of came in here. I kind of got on the mic and yelled about the supposed 28 point US peace plan for you,

Ukraine and Russia and how it has implications on cybersecurity. You know, in the peace plan, it sounds like it, you know, it's basically someone that accidentally emailed Moscow's Christmas list to the state, the state department. You know what I mean? Or I could have talked about X, formerly Twitter, formerly a functioning website, rolling out. It's about this account transparency feature that showed where accounts were created and where they were actually based. Super useful. For me, for example, it shows that I created my kind of Russian Federation. And I traveled to the Russian Federation to create my account. No, I used to act machine in Russia to do so. It was very useful because you got to see where accounts came from or where they were created or based out of. And for about 12 glorious hours, it had a weird side effects of exposing a bunch of accounts screaming things like real American Patriot actually being based in India or Nigeria or Russia and maybe even sometimes in Thailand.

And I was like, hey, I'm going to say hints folks that we're being targeted at information warfare. And suddenly X, they were like, nah, never mind. We're going to do a feature rollback. The date is not 100% reliable. Everyone go back to pretending that bots don't exist. But no, we're not doing that today. Today, we're going to be talking about douche. Not the cute dougal meme. Not the coin your cousin bought in 2021. It swears about to move. I mean, the department of government efficiency. The federal or federal, sorry, the federal startup revolution, they got this banded yesterday and folded into the office of personal management like a doomed beta test, Chris. They finally got mercy killed. We've seen those before. Now I want to start by saying that the the quite part loudly, those wasn't a bipartisan reform project. It was launched by executive order on day one of the second term of the president's led by Elon Musk as a special government employee. We've talked about the special government employee of what that meant for those 90 days

or 120 days or whatever it was. And staff through political pipelines to pursue a very specific agenda, shrink the state, smash regulatory capacity and treat public institutions like enemies that need a disruption. The reset, Chris, you heard the reset a lot and those podcasts you listen to. If it had been neutral, efficiency work, it probably would have looked like audits, mission reviews, mission reviews is important. Instead it looked like a purge with a chainsaw. And that's a reference to Elon Musk going on stage with a chainsaw. Yeah. Now to be fair, those did find some waste. They caught on news telecom plans. Chris, we talked about that one. They identified redundant licenses, goofy consulting contracts. And let's not pretend guys that a government with millions of workers has zero low hanging food. Absolutely, you're going to find some waste. There are going to be savings, but that's where those confuse a few dumb contracts for a mandate to dismantle reality because running a country is not like running a startup.

You can go to Twitter headquarters and fire 80% of staff members and keep the website running. You can't do that with the country. A startup can move fast. It could break things. A government that moves fast and breaks things break things like hurricane forecasting. We saw that in Texas, aviation safety. We've seen plenty of those disaster recovery, cyber defense, which we're seeing every single day today. Benefits delivery. We saw that happen in the last 30 days. And then of course, national security concerns, which I was motivated to write this rant about and do this rant with you guys today because of national security. In startups, Chris, bugs are annoying. And government bugs kill people. Now let's look at some stats because I did do some heavy lifting. I looked at the Doze government website. I looked at Homeland Security articles. I looked at pretty much everything I could that was available to me. So Doze is public ledger, which is those.gov or whatever it is now. It's probably going to be opium.gov in a couple of days.

Their public ledger claims about 214 billion in savings. But according to watchdogs and the sources I've seen, the different reporting platforms, all sorts of different journalists, whether they're right left. What they found is those numbers were padded by counting contract ceilings as savings. A contract ceiling is something like, hey, we're going to do this X for you at $500 billion over the next 25 years. You kill the contract two years into it. They're counting the 25 billion. They're not counting the 800 million that was spent in those two years. So you have that. Double counting cancellations. And of course, the one that I found very egregious was claiming credit for contracts that were already expired. We saw that. Contracts that were on the way out, those took credit for it. Now meanwhile, nonpartisan oversight went the other way.

There was a Senate permanent subcommittee on investigations by Norby Staff Report that found that those generated at least a minimum, and this is nonpartisan, at least 21.7 billion in waste in its first six months, mainly by paying hundreds of thousands of people not to work, while those dismantled their agencies plus legal fallout and rehiring costs. Remember, they had to rehire a lot of the people that they fired. It was close to different agencies. Independent estimates, and this has come from a Yahoo article, so whatever. Take it as you will. But independent estimates reported, it makes you coverage that put those linked costs at around 125, sorry, 135 billion, potentially outweighing the claims savings. So what's the honest answer? Even if those found some savings, the way they did it almost certainly cost more than it saved. And so, you can see by arson, Chris, it's not efficiency.

It's a bill that you have to pay later with interest. And I want to go into that with that looks like. So can I push back a little bit on those numbers? Sure. So you're saying that they cost money by paying federal employees to not work? Yes, that was part of their methodology. That's right. We would have paid those government employees no matter what. That's right. And I worked in the federal government. There is a lot of federal government employees paid to not work. That's 100%. You're not wrong on that, right? So the numbers are padded a little bit on both sides. The problem with this story though is that they had to rehire a lot of those people. And there's a bigger impact, which was that was that was their fault. That was a judge that decided that. They wanted to fire them. They wanted to save that money. Well, they obviously didn't. They was going to backfire us because here's the thing, right? And so from your experience working with the federal government, you know you saw that there were problems, right? Especially people that were working that were not working.

We're getting paid to not to work, right? There were probably lots of them. Lots of them, right? But it's not the majority of them. That's the reality. It's not the majority. Correct. So when you're when you're doing blanket firings, Chris, and this is what I'm really touching on, and then we get to the cyber port, right? Okay. When you're doing blanket firings like that, you're losing much more than savings or you're losing much more than a bunch of employees that you have to rehire anyway. You're losing memory, you're losing knowledge memory of that agency. And I want to break it down for you. So those are the era that's a 200,000 fireings or layoffs and 75,000 byouts across the federal workspace. This includes FAA and all those agencies. And also we had the thing of intimidation tactics like email us five bullet points of what you did last week, policy sets of roughly 2.4 million federal workers and over a minimum complied and actually responded back. But the subtext and this is this I've read this on like all sorts of different subreddits

or Twitter or Facebook group messages. Their federal employees felt like this was a do it or your next subtext. It wasn't about accountability. It felt like that was a loyalty ritual and a targeting system. And when you do that to a cleared workforce, you just don't lose the head count. You lose institutional memory. A good example of Cesar. Cesar lost like it's entire red team. You can't just rehire and rebuild that red team because there's a lot of context that's missing now with those guys are all fired and ladies. So federal federal clearance roles are like furniture, right? You can't just replace senior threat analysts. Some guy with 12 years of nation state TTP knowledge with a new hire and a welcome pack. It takes years and years to build that competence and even longer to build that trust and even longer to build a team 12 years. That's Trump is not going to be president 12 years. It's going to impact us that long. Yes he is.

Well, if you if you're trained to a constitution, you might believe that, right? Trump 28, baby. Well, it's affected us. What happened with those affected us on cyber defense, which everybody want to get into. But it's going to take multiple years of budget cycles to stabilize, potentially a closer decade to recover expertise in morale. You don't pass institutional memory with a sprint Chris, a development spirit. That's my point. This is long tailed damage. Now let's look at the impact of the agencies involved here. We have the National Oceanic and atmospheric administration. Those gutted forecasted climate science roles. I'm not sure why. I'm sure there's a political angle and that I'm not going to cover that. But this means weaker hurricane modeling and slower disaster warnings. We saw some of that happen in Texas, you know, earlier this year during hurricane season and all that. The CSA, cyber security infrastructure security agency. This is what's important to us.

Cut out the red team capacity, key contracts. I saw places like the smaller towns, smaller counties that were relying on CSA to provide them with SIM services. That got cut out. We almost lost the CVE system overnight because you know, the funding was like literally not there. The Department of Homeland Security, Cyber Safety Review Board, we talked about that. Almost 12 boards plus instantly dismantled this board and they have not been rebuilt Chris since then. And other cyber security embodies that were disbanded right while major incidents were being investigated, specifically sold typhoon. We go into the IRS, we go to FAA, you guys saw how effective FAA was not even a month ago. Okay. But we go into the insider threat. We cover two insider threat stories today, Chris. And this is where those bad policy becomes national security hazard.

Those embedded outsiders, it's a sense of federal systems with access pathways that skipped the normal vetting and least previous controls. And why do we know this? The courts, subpoenas. We had whistleblowers, at least two whistleblowers. At the cost of their jobs, they came out and exposed it and exposed it. And what these guys are doing, a bunch of 20 year olds that were recruited by Palantir and Peter Theos team to come in and support Doge. And these guys just went in, they were uploading, in our information, Chris, to systems and AI models, which some of them didn't even leave to no get-hups. This is counterintelligence malpractice. It was a back door to our federal government. And you don't need to hand root access to people who arrived thinking that government is in a lazy code base. We also can't ignore that some of those hires were part of things like the comm. You want to talk about scattered web Christmas, you want to talk about scattered web today. Right? Skyddewebs, shiny hunters, all that bullshit lapses, lepsos.

Some of these guys were around these people on Discord. We know that. It's public knowledge. You know, what have guys even got beat up unfortunately? It's not right, they got beat up. That was big bulls. That was big bulls, right? You got beat up? Yeah, more than beat up. Yeah, you got hurt. And that's not fair. I should have happened to them. But unfortunately, he's had to apologize publicly because some of the things he said. But, you know me, I'm a history guy. So I took some notes on how the lines historically for me. When I look at Doge, right? Obviously it's been a mistake. Obviously it's disbanded. Obviously, this is a fucking matter moving forward. But it's so about history here because I don't want us to repeat history as a society. I don't want them crazy Democrats to come in next year and try to replicate Doge with their own model. They do a copy and paste. But predatory, predatory insight is for a power student. They purge expertise, break oversight, and they call the records reforms. Their rhymes with the spoiled system loyalty over competence.

We saw this during the McCarthy era, loyalty purges, fear campaigns, drive out experts, experts, and we can institute this for years. We saw this with the Nixon era, the plumbers logic. A parallel cruise by passing norms, operating loyalty, leaving men behind. Fuck that. Federal employees to follow the Constitution and be loyal to the country, not a party and not a specific president. It's a different era, same playbook, infiltrate purges, destabilize the rebrand. Now, you know, they do have some more notes here. I want to kind of drag this on, but this one thing I'm going to tell you guys, that with those dead during these eight months, before they got purged and merged into, it's wherever the hell they're at now, right? I know that I read that a lot of these guys moved into OPM. They're probably going to be moving into other agencies now as high as. But here's the thing. Zero, zero, big O. Prosecutions, court cases, indictments.

With regard to fraud. Those as big Sunday point was, we're going to cut the fat. Well, here's what they did instead. They cut the muscle and muscle is expensive to regrow. The government's product is not speed. The government's product is reliability. Its job is to not fail when everything's on fire. And so when you have doors replacing that with audit theater and loyalty rituals and reckless access, they found some good contracts. Great. But they must took that for permission to destabilize the state. And so yeah, those as dead and the lesson isn't that reform is hard. The lesson is you can't reform a country that you do not understand. With people you did invent using methods, methods designed to terrorize the workforce. And that's kind of where we are. It didn't make America leaner. It made America weaker. And that's where I'm at. I don't want us to repeat history. That's my rant today, Chris. I don't want to repeat history.

I don't want the next party is going to come in because the Democrats are going to win next year, 2028 or whatever. I don't want these guys to come in and try to repeat this nonsense because this was a failed project. You can't treat a country like a startup business. It just doesn't work. And it's been proven. So there you go. So wait, you telling me Trump's going to run as a Democrat in 28? And he might win as a fucking Democrat. That's a funny part. There is no language that you can't switch parties and run twice again. But I don't want to give anybody an ideas. It doesn't say anything about parties. You just can't, you can't be more than president, but in terms of matter what party you are. Good enough. Guys, supporters on Patreon, keep a good show, commercial free, five star reviews, shares and social media. We put out a thing on LinkedIn every Thursday morning about the show. Repost that. Put it out there. Spread the words. Spread it into your feet. Get people listening to hacking the Fed. Tell your coworkers, tell your friends, tell your lovers. Hector.

Hey, I love you brother. Love you too. Cheers. Cheers.

More episodes

More from Hacker And The Fed

View all episodes →