Tempest Security Intelligence

Cyber Morning Call

Podcast de cibersegurança produzido pela Tempest com episódios diários, publicados logo pela manhã com aquilo que foi mais relevante nas últimas vinte e quatro horas em termos de novos ataques, vulnerabilidade ou ameaças. Tudo em menos de dez minutos e traduzido para uma linguagem fácil, produzido para que você possa ajustar o curso do seu dia de modo a tomar as melhores decisões de cibersegurança para sua empresa.

Author

Tempest Security Intelligence

Category

Technology

Podcast website

tempest.com.br

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

695 - Ataque afeta Departamento do Tesouro dos EUA 02.01.2025

[Referências do Episódio] Treasury says Chinese hackers remotely accessed documents in 'major' cyber incident - https://www.npr.org/2024/12/31/nx-s1-5243850/china-hacking-treasury-cyber-security   Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents - https://thehackernews.com/2024/12/chinese-apt-exploits-beyondtrust-api.html   Beijing denies involvement in US tre...

694 - Ataque afeta, pelo menos, 16 extensões para o Chrome 30.12.2024

[Referências do Episódio] Cyberhaven’s Chrome extension security incident and what we’re doing about it - https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it   16 Chrome Extensions Hacked, Exposing Over 600,000 Users to Data Theft - https://thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html   Inside FireScam : An Information...

693 - Fortinet detecta pico em ataques contra roteadores D-Link 27.12.2024

[Referências do Episódio] Botnets Continue to Target Aging D-Link Vulnerabilities - https://www.fortinet.com/blog/threat-research/botnets-continue-to-target-aging-d-link-vulnerabilities   Contagious Interviewが使用する新たなマルウェアOtterCookieについて - https://polite-sea-077fba000.1.azurestaticapps.net/tech_blog/contagious-interview-ottercookie   CVE-2024-3393 PAN-OS: Firewall Denial of Service...

692 - Novas falhas em tecnologias da Adobe e Apache 26.12.2024

[Referências do Episódio] Security updates available for Adobe ColdFusion | APSB24-107 - https://helpx.adobe.com/security/products/coldfusion/apsb24-107.html   [SECURITY] CVE-2024-56337 Apache Tomcat - RCE via write-enabled default servlet - CVE-2024-50379 mitigation was incomplete - https://lists.apache.org/thread/b2b9qrgjrz1kvo4ym8y2wkfdvwoq6qbp   CVE-2024-45387: Apache Traffic Control: SQL Inje...

691 - Sophos corrige 3 falhas críticas em seus firewalls 23.12.2024

[Referências do Episódio] Sophos discloses critical Firewall remote code execution flaw - https://www.bleepingcomputer.com/news/security/sophos-discloses-critical-firewall-remote-code-execution-flaw/   Lazarus group evolves its infection chain with old and new malware - https://securelist.com/lazarus-new-malware/115059/   Now You See Me, Now You Don’t: Using LLMs to Obfuscate Malicious JavaScript...

690 - Nova campanha do NodeStealer foca no Facebook Ads Manager 19.12.2024

[Referências do Episódio] Python-Based NodeStealer Version Targets Facebook Ads Manager - ⁠https://www.trendmicro.com/en_us/research/24/l/python-based-nodestealer.html⁠  NotLockBit: A Deep Dive Into the New Ransomware Threat - ⁠https://blog.qualys.com/vulnerabilities-threat-research/2024/12/18/notlockbit-a-deep-dive-into-the-new-ransomware-threat⁠  A new playground: Malicious campaigns proliferate...

689 - Falha de RCE no Apache Struts 2 está sendo explorada 18.12.2024

[Referências do Episódio] S2-067 - CVE-2024-53677 - https://cwiki.apache.org/confluence/display/WW/S2-067   New critical Apache Struts flaw exploited to find vulnerable servers - https://www.bleepingcomputer.com/news/security/new-critical-apache-struts-flaw-exploited-to-find-vulnerable-servers/   2024-12 Reference Advisory: Session Smart Router: Mirai malware found on systems when the default pass...

688 - Documentado uso de malvertising em diversas campanhas 17.12.2024

[Referências do Episódio] ESET Threat Report H2 2024 - https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2024/ “DeceptionAds” - Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising - https://labs.guard.io/deceptionads-fake-captcha-driving-infostealer-infections-and-a-glimpse-to-the-dark-side-of-0c516f4dc0b6 CoinLurker: The Stealer P...

687 - Ataques de Password Spraying afetam o Netscaler 16.12.2024

[Referências do Episódio] Password spraying attacks on NetScaler/NetScaler Gateway – December 2024 - https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024 The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit - https://googleprojectzero.blogspot.com/2024/12/qualcomm-dsp-driver-unexpectedly-excavating-exploit.html   NodeLoader Exposed: The Node.js Malware...

686 - Pumakit: descoberto novo rootkit para Linux 13.12.2024

[Referências do Episódio] Declawing PUMAKIT - https://www.elastic.co/security-labs/declawing-pumakit#stage-2-memory-resident-executables-overview   CVE-2024-49071 - Windows Defender Information Disclosure Vulnerability - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49071   CVE-2024-49147 - Vulnerabilidade de elevação de privilégio do Catálogo do Microsoft Update - https://msrc.mi...

685 - Guerra de APTs: Secret Blizzard se infiltrou em outros dois grupos 12.12.2024

[Referências do Episódio] Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine - https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/   Lookout Discovers New Chinese Surveillance Tool Used by Public Security Bureaus - https://www.lookout.c...

684 - Patch tuesday de dezembro tem zero-day no Windows sendo explorado em ataques 11.12.2024

[Referências do Episódio] Atualizações de Segurança de dezembro de 2024 - https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec   December Security Update - https://www.ivanti.com/blog/december-security-update   SAP Security Patch Day – December 2024 - https://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2024.html   CISA Releases Seven Industrial Control Systems...

683 - Glutton: novo loader instala backdoor do APT Winnti 10.12.2024

[Referências do Episódio] 黑白通吃:Glutton木马潜伏主流PHP框架,隐秘侵袭长达1年 - https://blog.xlab.qianxin.com/glutton_stealthily_targets_mainstream_php_frameworks/   Threat Advisory: Oh No Cleo! Cleo Software Actively Being Exploited in the Wild - https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild Cleo Product Security Advisory - CVE-2024-...

682 - Vuln no GitHub Actions permite adulterar pacote no PyPI 09.12.2024

[Referências do Episódio] Compromised ultralytics PyPI package delivers crypto coinminer - https://www.reversinglabs.com/blog/compromised-ultralytics-pypi-package-delivers-crypto-coinminer   Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection - https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/   URL File NTLM Hash Disclosure V...

681 - BlueAlpha abusa de Cloudflare em ataques na Ucrânia 06.12.2024

[Referências do Episódio] BlueAlpha Abuses Cloudflare Tunneling Service for GammaDrop Staging Infrastructure - https://go.recordedfuture.com/hubfs/reports/cta-ru-2024-1205.pdf   Mitel Product Security Advisory MISA-2024-0029 MiCollab Path Traversal Vulnerability - https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029   Where There’s Smoke, There’s Fire -...

680 - Guerra de APTs envolvendo russos e paquistaneses é documentada 05.12.2024

[

679 - Vuln de 2014 no Cisco ASA passa a ser explorada 04.12.2024

[Referências do Episódio] Cisco Adaptive Security Appliance WebVPN Login Page Cross-Site Scripting Vulnerability - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CVE-2014-2120   Exploit released for critical WhatsUp Gold RCE flaw, patch now - https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-whatsup-gold-rce-flaw-patch-now/   Veeam...

678 - O SmokeLoader ressurge 03.12.2024

[Referências do Episódio] SmokeLoader Attack Targets Companies in Taiwan - https://www.fortinet.com/blog/threat-research/sophisticated-attack-targets-taiwan-with-smokeloader   Unveiling RevC2 and Venom Loader - https://www.zscaler.com/blogs/security-research/unveiling-revc2-and-venom-loader   Gafgyt Malware Targeting Docker Remote API Servers - https://www.trendmicro.com/en_us/research/24/l/gafgyt...

677 - Cresce o número de anúncios de jogos de apostas maliciosos 02.12.2024

[Referências do Episódio] Shady Bets: How to Protect Yourself from Gambling Fraud Online - https://www.group-ib.com/blog/shady-bets/ IT threat evolution in Q3 2024. Non-obile statistics - https://securelist.com/malware-report-q3-2024-non-mobile-statistics/114695/ Ransomware Roundup - Interlock - https://www.fortinet.com/blog/threat-research/ransomware-roundup-interlock Roteiro e apresentação: Carl...

676 - 20 vulns são descobertas em wifi industrial 29.11.2024

[Referências do Episódio] Over Two Dozen Flaws Identified in Advantech Industrial Wi-Fi Access Points – Patch ASAP - https://thehackernews.com/2024/11/over-two-dozen-flaws-identified-in.html   Malicious PyPI crypto pay package aiocpa implants infostealer code - https://www.reversinglabs.com/blog/malicious-pypi-crypto-pay-package-aiocpa-implants-infostealer-code   Malicious NPM Package Exploits Rea...

675 - UEFI bootkit para Linux é detectado 28.11.2024

[Referências do Episódio] Bootkitty: Analyzing the first UEFI bootkit for Linux - https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/   Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers - https://thehackernews.com/2024/11/critical-flaw-in-projectsend-under.html   VMware fixed five vulnerabilities in Aria Operations produc...

674 - Zero-days no Firefox e no Windows instalam malware RomCom 27.11.2024

[Referências do Episódio] TEMPEST TALKS - https://www.even3.com.br/tempest-talks-2024-497677/   RomCom exploits Firefox and Windows zero days in the wild - https://www.welivesecurity.com/en/eset-research/romcom-exploits-firefox-and-windows-zero-days-in-the-wild/   Analysis of Elpaco: a Mimic variant - https://securelist.com/elpaco-ransomware-a-mimic-variant/114635/   Matrix Unleashes A New Widespr...

673 - Grupo hacktivista russo agora opera ransomware 26.11.2024

[Referências do Episódio] TEMPEST TALKS - https://www.even3.com.br/tempest-talks-2024-497677/   CyberVolk | A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks - https://www.sentinelone.com/labs/cybervolk-a-deep-dive-into-the-hacktivists-tools-and-ransomware-fueling-pro-russian-cyber-attacks/   Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spe...

672 - Trend detalha os recentes ataques do Salt Typhoon 25.11.2024

[Referências do Episódio] TEMPEST TALKS - https://www.even3.com.br/tempest-talks-2024-497677/   Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions - https://www.trendmicro.com/en_us/research/24/k/earth-estries.html   The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access - https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-atta...

671 - Mais de 2000 firewalls da Palo Alto já foram atacados com novos zero-days 22.11.2024

[Referências do Episódio] ⁠ Post da Fundação Shadowserver sobre a exploração das falhas no PAN-OS - https://bsky.app/profile/shadowserver.bsky.social/post/3lbh6k7p7pc27   CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) - https://security.paloaltonetworks.com/CVE-2024-0012   ⁠ CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Man...

Listen to the Cyber Morning Call podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.