MOVEit and MGM Resorts Hacks, U.S. Senate's Email System Melts Down, Cisco Can't Stop Using Static Passwords, and Listener Questions

This week on Hacker And The Fed we offer updates on the MOVEit and MGM Resorts hacks, the US State Department has no idea if its IT security actually works, the Senate's email system melts down in the face of a security test, Cisco can't stop using static passwords, and we answer listener questions about Single Sign-on, circumventing company IT rules, and LinkedIn profiles. Links from the episode: MOVEit Maker Announces New Critical Vulnerability Affecting a Different File Transfer Tool https://therecord.media/progress-new-file-transfer-vulnerability   MGM Resorts Hack Update https://x.com/brettforrest89/status/1711885567695433765   US State Dept has No Idea if its IT Security Actually Works, Say Auditors https://www.theregister.com/2023/10/02/us_state_security_gao/ https://endoflife.date/windows   The Senate’s Email System Melted Down in the Face of Security Test https://www.politico.com/minutes/congress/09-8-2023/senate-reply-all-mess/   Cisco Can't Stop Using Static Passwords https://www.schneier.com/blog/archives/2023/10/cisco-cant-stop-using-hard-coded-passwords.html Support our sponsors: Get your Hacker and the Fed merchandise at hackerandthefed.com Send HATF your questions at [email protected]

Om Podcasten

NAXO co-founder and former FBI Special Agent, Chris Tarbell, and ex-Anonymous/LulzSec blackhat hacker turned network penetration tester, Hector Monsegur (aka Sabu), once faced off as adversaries in cyberspace before becoming close friends and now podcast co-hosts. Whether you are a legal professional, cybersecurity practitioner, or forensic investigator, Chris and Hector will bring you their unique perspectives on the latest developments in cybersecurity. Each month, Chris and Hector will sit down to discuss: Recent cyber attacks and key takeaways Regulatory developments that impact how companies and individuals guard their data New attack vectors and capabilities, including breakdowns of how they can be protected against Techniques to keep you, your family, and your company safe from cyber attacks Subscribe to be the first to hear about new Hacker and the Fed episodes. Contact us at [email protected] if you have a topic you’d like Chris and Hector to discuss on the podcast. Find out more about NAXO: www.naxo.com Follow us on LinkedIn: https://www.linkedin.com/company/81891840 Follow Chris on LinkedIn: https://www.linkedin.com/in/chris-tarbell-20b129278/ Follow Hector on LinkedIn: https://www.linkedin.com/in/hxmonsegur/ ----------------- By accessing this podcast, you acknowledge that the Hacker and the Fed podcasts and any information, opinions or recommendations contained therein are for general informational purposes only, and are not intended to provide legal, tax, financial, or investment advice. Listeners should consult their own advisors before making these types of decisions. NAXO has no responsibility or liability for any decision made or any other acts or omissions in connection with your use of this material and any reliance upon the information provided in the Hacker and the Fed podcast is done at your own risk. NAXO makes no warranty, guarantee or representation as to the accuracy, sufficiency, completeness, timeliness, suitability or validity of the information in this podcast and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material. Unless specifically stated otherwise, NAXO does not endorse, approve, recommend or certify any information, product, process, service or organization presented or mentioned in this podcast, and information from this podcast should not be referenced in any way to imply such approval or endorsement. The views expressed by guests are their own and their appearance on this podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by NAXO employees are those of the employees and do not necessarily reflect the views of NAXO. The third-party materials or content of any third-party site referenced in this podcast do not necessarily reflect the opinions, standards or policies of NAXO. NAXO assumes no responsibility or liability for the accuracy or completeness of the content contained in third-party materials or on third-party sites referenced in this podcast or the compliance with applicable laws of such materials and/or links referenced herein. Moreover, NAXO makes no warranty that this podcast, or the server that makes it available, is free of viruses, worms or other elements or codes that manifest contaminating or destructive properties. NAXO EXPRESSLY DISCLAIMS ANY AND ALL LIABILITY OR RESPONSIBILITY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR OTHER DAMAGES ARISING OUT OF ANY INDIVIDUAL'S USE OF, REFERENCE TO, RELIANCE ON, OR INABILITY TO USE, THIS PODCAST OR THE INFORMATION PRESENTED IN THIS PODCAST.