Tempest Security Intelligence

Cyber Morning Call

Podcast de cibersegurança produzido pela Tempest com episódios diários, publicados logo pela manhã com aquilo que foi mais relevante nas últimas vinte e quatro horas em termos de novos ataques, vulnerabilidade ou ameaças. Tudo em menos de dez minutos e traduzido para uma linguagem fácil, produzido para que você possa ajustar o curso do seu dia de modo a tomar as melhores decisões de cibersegurança para sua empresa.

Author

Tempest Security Intelligence

Category

Technology

Podcast website

tempest.com.br

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

670 - Apple corrige 2 zero-days 21.11.2024

[Referências do Episódio] ⁠About the security content of iOS 18.1.1 and iPadOS 18.1.1⁠ ⁠About the security content of iOS 17.7.2 and iPadOS 17.7.2⁠ ⁠About the security content of macOS Sequoia 15.1.1⁠ ⁠About the security content of visionOS 2.1.1⁠ ⁠About the security content of Safari 18.1.1⁠ ⁠Qualys Security Advisory - LPEs in needrestart (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, CVE-2024-...

669 - Palo Alto identifica nova vulnerabilidade no software PAN-OS 19.11.2024

[Referências do Episódio] Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 - https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/ VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813) - https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityA...

668 - Zero-days em Firewalls Palo Alto Networks e Fortinet seguem sob ataque 18.11.2024

[Referências do Episódio] PAN-SA-2024-0015 Critical Security Bulletin: Ensure Access to Management Interface is Secured - https://security.paloaltonetworks.com/PAN-SA-2024-0015   BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA - https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/  ...

667 - Google publica suas previsões sobre cyber em 2025 14.11.2024

[Referências do Episódio] Emerging Threats: Cybersecurity Forecast 2025 - https://cloud.google.com/blog/topics/threat-intelligence/cybersecurity-forecast-2025/   The Problem with IoT Cloud-Connectivity and How it Exposed All OvrC Devices to Hijacking - https://claroty.com/team82/research/the-problem-with-iot-cloud-connectivity-and-how-it-exposed-all-ovrc-devices-to-hijacking   Global Companies Are...

666 - Patch Tuesday: Microsoft corrige 4 zero-days 13.11.2024

[Referências do Episódio] November 2024 Security Updates - https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov   APSB24-77 : Security update available for Adobe Bridge - https://helpx.adobe.com/security/products/bridge/apsb24-77.html   APSB24-83 : Security update available for Adobe Audition - https://helpx.adobe.com/security/products/audition/apsb24-83.html   APSB24-85 : Security update...

665 - Ymir: Novo ransomware é identificado na Colômbia 12.11.2024

[Referências do Episódio] Ymir: new stealthy ransomware in the wild - https://securelist.com/new-ymir-ransomware-found-in-colombia/114493/   0检测的Melofee 木马新变种曝光,专攻RHEL 7.9系统 - https://blog.xlab.qianxin.com/analysis_of_new_melofee_variant/   Trend Micro and Japanese Partners Reveal Hidden Connections Among SEO Malware Operations - https://www.trendmicro.com/en_us/research/24/k/seo-ma...

664 - Vuln no Veeam é explorada por novo ransomware 11.11.2024

[Referências do Episódio] VEEAM exploit seen used again with a new ransomware: “Frag” - https://news.sophos.com/en-us/2024/11/08/veeam-exploit-seen-used-again-with-a-new-ransomware-frag/   PAN-SA-2024-0015 Important Informational Bulletin: Ensure Access to Management Interface is Secured - https://security.paloaltonetworks.com/PAN-SA-2024-0015    Palo Alto Advises Securing PAN-OS Interface Amid Po...

663 - Novo ataque da Coreia do Norte afeta o macOS 08.11.2024

[Referências do Episódio] BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence - https://www.sentinelone.com/labs/bluenoroff-hidden-risk-threat-actor-targets-macs-with-fake-crypto-news-and-novel-persistence/   The Lazarus Heist - https://www.bbc.co.uk/programmes/w13xtvg9/episodes/downloads    GuLoader: Evolving Tactics in Latest Campaign Targeting European...

662 - Cisco: falha crítica afeta dispositivos industriais 07.11.2024

[Referências do Episódio] Tempest Academy Conference 2024 - https://www.tempest.com.br/tempest_talk/tempest-academy-conference/   CVE-2024-20418 - Cisco Unified Industrial Wireless Software for Ultra-Reliable Wireless Backhaul Access Point Command Injection Vulnerability - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-backhaul-ap-cmdinj-R7E28Ecs   Threat Ca...

661 - Interpol conduz operação com 22 mil takedowns e 41 detidos 06.11.2024

[Referências do Episódio] INTERPOL cyber operation takes down 22,000 malicious IP addresses - https://www.interpol.int/News-and-Events/News/2024/INTERPOL-cyber-operation-takes-down-22-000-malicious-IP-addresses   Stable Channel Update for Desktop - Tuesday, November 5, 2024 - https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop.html   Joint ODNI, FBI, and CISA Statement...

660 - Novo ataque usa VM com backdoor 05.11.2024

[Referências do Episódio] Tempest Academy Conference 2024 - https://www.tempest.com.br/tempest_talk/tempest-academy-conference/   CRON#TRAP: Emulated Linux Environments as the Latest Tactic in Malware Staging - https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/   Android Security Bulletin November 2024 - https://source.android.com/docs/secu...

659 - 1ª vuln encontrada por IA é documentada 04.11.2024

[Referências do Episódio] [TREND MICRO NO FORRESTER] - https://www.trendmicro.com/explore/forrester-wave-xdr/01054-v1-en-www   From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code - https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html   G700 : The Next Generation of Craxs RAT - https://www.cyfirma.com/research/g700-the-next-gen...

658 - Pacote popular no npm é trojanizado 01.11.2024

[Referências do Episódio] Tweet da LottieFiles sobre o comprometimento do Lottie-Player - https://x.com/LottieFiles/status/1851848602093777273   Hackers target critical zero-day vulnerability in PTZ cameras - https://www.bleepingcomputer.com/news/security/hackers-target-critical-zero-day-vulnerability-in-ptz-cameras/   Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files...

657 - Coreia do Norte colaborou com ransomware Play, afirma estudo 31.10.2024

[Referências do Episódio] Jumpy Pisces Engages in Play Ransomware - https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/   Mishing in Motion: Uncovering the Evolving Functionality of FakeCall Malware - https://www.zimperium.com/blog/mishing-in-motion-uncovering-the-evolving-functionality-of-fakecall-malware/   EMERALDWHALE:  15k Cloud Credentials Stolen in Operation Targe...

656 - Servidores Confluence têm sido maliciosamente adicionados à Titan Network 30.10.2024

[Referências do Episódio] Attacker Abuses Victim Resources to Reap Rewards from Titan Network - https://www.trendmicro.com/en_us/research/24/j/titan-network.html   CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server - https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-...

655 - O jogo de gato e rato entre infostealers e o Google 29.10.2024

[Referências do Episódio] Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses - https://www.elastic.co/security-labs/katz-and-mouse-game   Redline, Meta infostealer malware operations seized by police - https://www.bleepingcomputer.com/news/legal/redline-meta-infostealer-malware-operations-seized-by-police/   Hybrid Russian Espionage and Influence Campaign Aims to Compromise Uk...

654 - Técnica é adaptada para abusar de mecanismo do Windows 28.10.2024

[Referências do Episódio] An Update on Windows Downdate - https://www.safebreach.com/blog/update-on-windows-downdate-downgrade-attacks/ Introducing a New Vulnerability Class: False File Immutability - https://www.elastic.co/security-labs/false-file-immutability    Joint Statement by FBI and CISA on PRC Activity Targeting Telecommunications - https://www.cisa.gov/news-events/news/joint-statement-fb...

653 - Nova variante do ransomware Qilin é documentada 25.10.2024

[Referências do Episódio] New Qilin. B Ransomware Variant Boasts Enhanced Encryption and Defense Evasion - https://www.halcyon.ai/blog/new-qilin-b-ransomware-variant-boasts-enhanced-encryption-and-defense-evasion   CISA Adds Two Known Exploited Vulnerabilities to Catalog - https://www.cisa.gov/news-events/alerts/2024/10/24/cisa-adds-two-known-exploited-vulnerabilities-catalog   AWS CDK Risk: Explo...

652 - Zero-Day no FortiManager está sob ataque 24.10.2024

[Referências do Episódio] Ada Lovelace Day 2024 - https://www.even3.com.br/ada-lovelace-day-2024-tempest/   FG-IR-24-423 - CVE-2024-47575 - Missing authentication in fgfmsd - https://fortiguard.fortinet.com/psirt/FG-IR-24-423   CVE-2024-47575: Frequently Asked Questions About FortiJump Zero-Day in FortiManager and FortiManager Cloud - https://www.tenable.com/blog/cve-2024-47575-faq-about-fortijump...

651 - Tempest identifica sites relacionados a golpe de kit natalino 22.10.2024

[Referências do Episódio] Akira ransomware continues to evolve - https://blog.talosintelligence.com/akira-ransomware-continues-to-evolve/ The Silent Game: Sophisticated threat actors targeting gambling industry - https://www.securityjoes.com/post/the-silent-game-sophisticated-threat-actors-targeting-gambling-industry Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Ar...

650 - Truque de engenharia social é usado em ataques com o Lumma Stealer 21.10.2024

[Referências do Episódio] [TREND MICRO NO FORRESTER] - https://www.trendmicro.com/explore/forrester-wave-xdr/01054-v1-en-www   Tricks and Treats: GHOSTPULSE’s new pixel- level deception - https://www.elastic.co/security-labs/tricks-and-treats   Unmasking Lumma Stealer : Analyzing Deceptive Tactics with Fake CAPTCHA - https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumm...

649 - Ecossistema do Ransomware Cicada3301 é revelado 18.10.2024

[Referências do Episódio] Encrypted Symphony: Infiltrating the Cicada3301 Ransomware-as-a-Service Group - https://www.group-ib.com/blog/cicada3301/   New macOS vulnerability, “HM Surf”, could lead to unauthorized data access - https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/   UAT-5647 targets Ukrainian and Polish enti...

648 - Zero-day no IE foi abusado por norte-coreanos 17.10.2024

[Referências do Episódio] AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) - https://asec.ahnlab.com/en/83877/   Fake LockBit, Real Damage: Ransomware Samples Abuse AWS S3 to Steal Data - https://www.trendmicro.com/en_us/research/24/j/fake-lockbit-real-damage-ransomware-samples-abuse-aws-s3-to-stea.html   Roteiro e apresentação: Carlos Cabral e Bian...

647 - Mandiant: 5 dias é o tempo médio para a exploração de vulns 16.10.2024

[Referências do Episódio] V Seminário de Criptografia, ​Política e Direitos ​Fundamentais - https://seminariodecriptografia.my.canva.site/   CriptoFrevo - https://criptofrevo.ip.rec.br/   How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends - https://cloud.google.com/blog/topics/threat-intelligence/time-to-exploit-trends-2023/   Should We Chat, Too? Security Analysis of WeChat’s MMTLS En...

646 - Novo malware para ATMs é documentado 15.10.2024

[Referências do Episódio] FASTCash for Linux - https://doubleagent.net/fastcash-for-linux/   New FASTCash malware Linux variant helps steal money from ATMs - https://www.bleepingcomputer.com/news/security/new-fastcash-malware-linux-variant-helps-steal-money-from-atms/   Silent Threat: Red Team Tool EDRSilencer Disrupting Endpoint Security Solutions - https://www.trendmicro.com/en_us/research/24/j/...

Listen to the Cyber Morning Call podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.