Tempest Security Intelligence

Cyber Morning Call

Podcast de cibersegurança produzido pela Tempest com episódios diários, publicados logo pela manhã com aquilo que foi mais relevante nas últimas vinte e quatro horas em termos de novos ataques, vulnerabilidade ou ameaças. Tudo em menos de dez minutos e traduzido para uma linguagem fácil, produzido para que você possa ajustar o curso do seu dia de modo a tomar as melhores decisões de cibersegurança para sua empresa.

Author

Tempest Security Intelligence

Category

Technology

Podcast website

tempest.com.br

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

745 - Apache Tomcat e PHP-CGI estão sob ataque 18.03.2025

Referências do Episódio Threat actors rapidly exploit new Apache Tomcat flaw following PoC release StilachiRAT analysis: From system reconnaissance to cryptocurrency theft Technical Advisory: Mass Exploitation of CVE-2024-4577 BitM Up! Session Stealing in Seconds Using the Browser-in-the-Middle Technique ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery Roteiro e...

744 - Phishing afeta usuários do GitHub 17.03.2025

Referências do Episódio Fake "Security Alert" issues on GitHub use OAuth app to hijack accounts  What Is The New Steganographic Campaign Distributing Multiple Malware Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

743 - Ataque ClickFix abusa do Booking.com 14.03.2025

Referências do Episódio Phishing campaign impersonates Booking .com , delivers a suite of credential-stealing malware SocGholish’s Intrusion Techniques Facilitate Distribution of RansomHub Ransomware Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

742 - Roteadores Juniper na mira da espionagem chinesa 13.03.2025

Referências do Episódio Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers 2025-03 Out-of-Cycle Security Bulletin: Junos OS: A local attacker with shell access can execute arbitrary code ( CVE-2025-21590 ) #StopRansomware: Medusa Ransomware Analyzing OBSCURE#BAT : Threat Actors Lure Victims into Executing Malicious Batch Scripts to Deploy Stealthy Rootkits Lookout Dis...

741 - Patch Tuesday: Microsoft e Apple corrigem zero-days sob exploração 12.03.2025

Referências do Episódio Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability New - CVE-2025-24983 Windows NTFS Information Disclosure Vulnerability New - CVE-2025-24984 Windows Fast FAT File System Driver Remote Code Execution Vulnerability New - CVE-2025-24985 Windows NTFS Information Disclosure Vulnerability New - CVE-2025-24991 Windows NTFS Remote Code Execution Vulnerability New...

740 - APT Blind Eagle faz uso peculiar de vuln para Windows 11.03.2025

Referências do Episódio Blind Eagle : …And Justice for All UTC−05:00 SideWinder targets the maritime and nuclear sectors with an updated toolset CVE-2017-11882 - Microsoft Office Memory Corruption Vulnerability A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distr...

739 - Comandos ocultos são encontrados em popular chip de IOT 10.03.2025

Referências do Episódio Undocumented commands found in Bluetooth chip used by a billion devices RootedCON - Attacking Bluetooth the easy way CVE-2025-27840 Ripple Co-founder’s $150M XRP Heist Related to LastPass Hack : ZachXBT Feds seized $23 million in crypto stolen using keys from LastPass breaches Thread \ da Microsoft no X sobre o Moonstone Sleet estar usando o Qlin Roteiro e apresentação: Car...

738 - Campanha de malvertising afetou mais de 1 milhão de dispositivos, afirma Microsoft 07.03.2025

Referências do Episódio Malvertising campaign leads to info stealers hosted on GitHub GreyNoise Detects Active Exploitation of Silk Typhoon-Linked CVEs Kibana 8.17.3 Security Update (ESA-2025-06) Over 37,000 VMware ESXi servers vulnerable to ongoing attacks A Deep Dive into Strela Stealer and how it Targets European Countries Unmasking the new persistent attacks on Japan Unmasking GrassCall Campai...

737 - Zero-days em tecnologias VMware e Android estão sob ataque 06.03.2025

Referências do Episódio VMSA-2025-0004 : VMware ESXi, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) Android Security Bulletin— March 2025 Celleb r ite zero-day exploit used to target phone of Serbian student activist Silk Typhoon targeting IT supply chain Unveiling EncryptHub : Analysis of a multi-stage malware campaign  Not Lost...

736 - Squidoor: ameaça afeta setores na América do Sul 28.02.2025

Referências do Episódio Squidoor : Suspected Chinese Threat Actor’s Backdoor Targets Global Organizations You've Got Malware: FINALDRAFT Hides in Your Drafts Winos 4.0 Spreads via Impersonation of Official Email to Target Users in Taiwan Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools Spring Dragon – Updated Activity Roteiro e ap...

735 - CrowdStrike publica seu relatório anual 27.02.2025

Referência do Episódio CrowdStrike 2025 Global Threat Report: Beware the Enterprising Adversary -  Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

734 - Aprendizados no leak do ransomware Black Basta 26.02.2025

Referências do Episódio Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

733 - Novo backdoor se disfarça de lib para Linux 25.02.2025

Referências do Episódio Auto-Color : An Emerging and Evasive Linux Backdoor PolarEdge : Unveiling an uncovered IOT Botnet Massive Botnet Targets M365 with Stealthy Password Spraying Attacks. FatalRAT attacks in APAC. Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerram...

732 - Check Point detalha como ocorreu o roubo de US$1,5 bi em criptoativos 24.02.2025

Referências do Episódio The Bybit Incident : When Research Meets Reality The Largest Theft in History - Following the Money Trail from the Bybit Hack Angry Likho : Old beasts in a new forest Censorship as a Service | Leak Reveals Public-Private Collaboration to Monitor Chinese Cyberspace  Confluence Exploit Leads to LockBit Ransomware Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição...

731 - Falha de 7 anos é a causa dos ataques do Salt Typhoon, revela a Cisco 21.02.2025

Referências do Episódio Weathering the storm: In the midst of a Typhoon N.º 1: Tufões na América do Norte - Artigo da minha newsletter sobre o Salt Typhoon. DeceptiveDevelopment targets freelance developers Fingerprint Heists : How your browser fingerprint can be stolen and used by fraudsters. Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Roteiro e apresentação: Carlos Cabral...

730 - Palo Alto: Ataque encadeia 3 exploits contra firewalls da fabricante 20.02.2025

Referências do Episódio Palo Alto Networks tags new firewall bug as exploited in attacks ( CVE-2025-0111 , CVE-2025-0108 e CVE-2024-9474 ) Citrix Releases Security Fix for NetScaler Console Privilege Escalation Vulnerability Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger. Vulnerabilidade de execução remota de código do Microsoft Bing - CVE-2025-21355...

729 - Falhas de AitM e DoS afetam o OpenSSH 19.02.2025

Referências do Episódio Qualys Security Advisory - CVE-2025-26465: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client | CVE-2025-26466: DoS attack against OpenSSH's client and server An Update on Fake Updates : Two New Actors, and New Mac Malware StaryDobry ruins New Year’s Eve, delivering miner instead of presents Invisible obfuscation technique used in PAC attack Roteiro e apr...

728 - Mustang Panda abusa de binário do Windows para burlar antivírus da ESET 18.02.2025

Referências do Episódio Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection New Xerox Printer Flaws Could Let Attackers Capture Windows Active Directory Credentials Tweet da Microsoft sobre o XCSSET Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

727 - Grupo russo abusa de códigos de dispositivos em ataques contra redes Windows 17.02.2025

[Referências do Episódio] CVE-2025-1094: PostgreSQL psql SQL injection (FIXED) Telegram Abused as C2 Channel for New Golang Backdoor PirateFi game on Steam caught installing password-stealing malware Ascensão do uso de softwares de monitoramento e gerenciamento remoto em campanhas maliciosas Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerram...

726 - Identificada campanha explorando a plataforma Dropbox 14.02.2025

[Referências do Episódio]  Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks - https://www.securonix.com/blog/analyzing-deepdrive-north-korean-threat-actors-observed-exploiting-trusted-platforms-for-targeted-attacks/ Astaroth: A New 2FA Phishing Kit Targeting Gmail, Yahoo, AOL, O365, and 3rd-Party Logins - https://slashnext.com/blog/astarot...

725 - Falsos membros da gangue Babuk empregam re-extorsões 13.02.2025

[Referências do Episódio]  Babuk Impersonators Leverage a Brand Name & Previously Stolen Data to Engage in Re-Extortions - https://analyst1.com/babuk-impersonators-leverage-a-brand-name-previously-stolen-data-to-engage-in-re-extortions/ BTOMB RAT: Newly Discovered Android Malware Spreading via Phishing Sites - https://cyble.com/blog/btmob-rat-newly-discovered-android-malware/   From South Amer...

724 - Patch Tuesday de fevereiro corrige duas vulnerabilidades exploradas em ataques 12.02.2025

[Referências do Episódio]  February 2025 Security Updates - https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb Authentication bypass in Node.js websocket module and CSF requests - https://fortiguard.fortinet.com/psirt/FG-IR-24-535   United States, Australia, and the United Kingdom Jointly Sanction Key Infraestructure that Enables Ransomware Attacks - https://home.treasury.gov/news/press-...

723 - Operação policial derruba DLS do grupo de ransomware 8Base 11.02.2025

[Referências do Episódio]  Police arrests 4 Phobos ransomware suspects, seizes 8Base sites - https://www.bleepingcomputer.com/news/legal/police-arrests-4-phobos-ransomware-suspects-seizes-8base-sites/  About the security content of iPadOS 17.7.5 - https://support.apple.com/en-us/122173 About the security content of iOS 18.3.1 and iPadOS 18.3.1 - https://support.apple.com/en-us/122174 Small praise...

722 - Brasil é visado em campanha do BadIIS 10.02.2025

[Referências do Episódio]  Chinese-Sepaking Group Manipulates SEO with BadIIS - https://www.trendmicro.com/en_us/research/25/b/chinese-speaking-group-manipulates-seo-with-badiis.html  Zyxel HTTP Vulnerability - https://vulncheck.com/blog/zyxel-http-vuln Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

721 - Identificada exploração de falhas recém-corrigidas no SimpleHelp 07.02.2025

[Referências do Episódio] Not-so-SimpleHelp exploits enabling deployment of Sliver backdoor  - https://fieldeffect.com/blog/field-effect-mitigates-not-so-simplehelp-exploits-enabling-deployment-of-backdoors  Babuk Ransomware: a victim of Indodax hack - https://theravenfile.com/2025/02/06/babuk-ransomware-a-victim-of-indodax-hack/?source=post_page-----eefdf1af2e3c--------------------------------  C...

Listen to the Cyber Morning Call podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.