Tempest Security Intelligence

Cyber Morning Call

Podcast de cibersegurança produzido pela Tempest com episódios diários, publicados logo pela manhã com aquilo que foi mais relevante nas últimas vinte e quatro horas em termos de novos ataques, vulnerabilidade ou ameaças. Tudo em menos de dez minutos e traduzido para uma linguagem fácil, produzido para que você possa ajustar o curso do seu dia de modo a tomar as melhores decisões de cibersegurança para sua empresa.

Author

Tempest Security Intelligence

Category

Technology

Podcast website

tempest.com.br

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

620 - Cisco corrige duas falhas críticas no Cisco Smart Licensing Utility 05.09.2024

[Referências do Episódio] - Cisco Smart Licensing Utility Vulnerabilities - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw - Mallox ransomware: in-depth analysis and evolution - https://securelist.com/mallox-ransomware/113529/ Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca...

619 - Grupo chinês ressurge com novo backdoor 04.09.2024

[Referências do Episódio] Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion - https://www.trendmicro.com/en_us/research/24/i/earth-lusca-ktlvdoor.html   Earth Lusca - https://malpedia.caad.fkie.fraunhofer.de/actor/earth_lusca   Zyxel security advisory for OS command injection vulnerability in APs and security router devices - https://www.zyxel.com/global/en/support/security-advisories...

618 - GlobalProtect falso é mais uma vez usado em ataques 03.09.2024

[Referências do Episódio] Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant - https://unit42.paloaltonetworks.com/global-protect-vpn-spoof-distributes-wikiloader/   Head Mare: adventures of a unicorn in Russia and Belarus - https://securelist.com/head-mare-hacktivists/113555/   DarkCracks, 一个利用被黑GLPI, WORDPRESS站点充当中转的高级恶意载荷&升级框架 - https://blog.xlab.qianxin....

617 - Norte-coreanos abusam de zero-day no Chrome 02.09.2024

[Referências do Episódio] [TREND MICRO NO FORRESTER] - https://www.trendmicro.com/explore/forrester-wave-xdr/01054-v1-en-www   North Korean threat actor Citrine Sleet exploiting Chromium zero-day - https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/   Stable Channel Update for Desktop, Wednesday, August 21, 2024 - https://c...

616 - APT29 usa os mesmos exploits que spyware comercial 30.08.2024

[Referências do Episódio] Threat Actors Target the Middle East Using Fake Palo Alto GlobalProtect Tool - https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html   Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence - https://www.trendmicro.com/en_us/research/24/h/godzilla-fileless-backdoors.html    The Malware That Must Not Be...

615 - Irã: Operações de contrainteligência do APT42 e novo backdoor do APT33 29.08.2024

[Referências do Episódio] I Spy With My Little Eye: Uncovering an Iranian Counterintelligence Operation - https://cloud.google.com/blog/topics/threat-intelligence/uncovering-iranian-counterintelligence-operation/   Peach Sandstorm deploys new custom Tickler malware in long-running intelligence gathering operations - https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-n...

614 - Nova exploração de zero-day pela China é detectada 28.08.2024

[Referências do Episódio] Taking the Crossroads: The Versa Director Zero-Day Exploitation - https://blog.lumen.com/taking-the-crossroads-the-versa-director-zero-day-exploitation/   Versa Security Bulletin:  Update on CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability - https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-fi...

613 - Chrome alcança a marca de 10 zero-days sob ataque em 2024 27.08.2024

[Referências do Episódio] Stable Channel Update for Desktop - Wednesday, August 21, 2024 - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html   Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information - https://embracethered.com/blog/posts/2024/m365-copilot-prompt-injection-tool-invocation-and-data-exfil-using-ascii-smuggling/   SonicWal...

612 - Afiliados do ransomware Qilin estão roubando credenciais no Chrome 26.08.2024

[Referências do Episódio] PEAKLIGHT: Decoding the Stealthy Memory-Only Malware - https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware/   From the Depths: Analyzing the Cthulhu Stealer Malware for macOS - https://www.cadosecurity.com/blog/from-the-depths-analyzing-the-cthulhu-stealer-malware-for-macos   Qilin ransomware caught stealing credentials...

611 - Switches da Cisco são explorados pelo grupo Velvet Ant 23.08.2024

[Referências do Episódio] China-Nexus Threat Group ‘Velvet Ant’ Leverages a Zero-Day to Deploy Malware on Cisco Nexus Switches - https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/ Critical Privilege Escalation in LiteSpeed Cache Plugin Affecting 5+ Million Sites - https://patchstack.com/articles/critical-privilege-escalation-in-litespeed-cache-plugin-affecting-5-million-sites...

610 - Um curioso uso do comando COPY…FROM 22.08.2024

[Referências do Episódio] Stable Channel Update for Desktop, Wednesday, August 21, 2024 - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html   MoonPeak malware from North Korean actors unveils new details on attacker infrastructure - https://blog.talosintelligence.com/moonpeak-malware-infrastructure-north-korea/   Enterprise Server 3.13.3 - https://docs.github....

609 - PWAs permitem ataques contra iOS e Android 21.08.2024

[Referências do Episódio] Be careful what you pwish for – Phishing in PWA applications - https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/   New Backdoor Targeting Taiwan Employs Stealthy Communications - https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns   GreenCharlie Infrastructure Targeting US Politica...

608 - Falhas sérias afetam MS Office e Teams para MacOS 20.08.2024

[Referências do Episódio] How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions - https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/ CISA Warns of Critical Jenkins Vulnerability Exploited in Ransomware Attacks - https://thehackernews.com/2024/08/cisa-warns-of-critical-jenkins.html...

607 - Irã usou ChatGPT contra eleição dos EUA 19.08.2024

[Referências do Episódio] Disrupting a covert Iranian influence operation - https://openai.com/index/disrupting-a-covert-iranian-influence-operation/   Iran steps into US election 2024 with cyber-enabled influence operations - https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/5bc57431-a7a9-49ad-944d-b93b7d35d0fc.pdf    Unmasking Styx Stea...

606 - 90 mil ambientes expostos à extorsão 16.08.2024

[Referências do Episódio] Leaked Environment Variables Allow Large-Scale Extortion Operation of Cloud Environments - https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/   Ransomware attackers introduce new EDR killer to their arsenal - https://news.sophos.com/en-us/2024/08/14/edr-kill-shifter/   A Deep Dive into a New ValleyRAT Campaign Targeting Chinese Speakers - https://w...

605 - Quadrilha FIN7 tem infra revelada 15.08.2024

[Referências do Episódio] FIN7: The Truth Doesn't Need to be so STARK - https://www.team-cymru.com/post/fin7-the-truth-doesn-t-need-to-be-so-stark   WHD 12.8.3 Hotfix 1 - https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1   Cryptocurrency Lures and Pupy RAT: Analysing the UTG-Q-010 Campaign - https://cyble.com/blog/analysing-the-utg-q-010-campaign/   EastWind campaign:...

604 - Microsoft corrige 9 zero-days, ataques afetam 6. 14.08.2024

[Referências do Episódio] Microsoft August 2024 Patch Tuesday fixes 9 zero-days, 6 exploited - https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2024-patch-tuesday-fixes-9-zero-days-6-exploited/   SAP Security Patch Day – August 2024 - https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2024.html   Security Advisory: Ivanti Virtual Traffic Manager (vTM )...

603 - Falha zero-click no Outlook é dissecada 13.08.2024

[Referências do Episódio] Technical Analysis: CVE-2024-30103 - https://blog.morphisec.com/cve-2024-30103-technical-analysis   FreeBSD Releases Urgent Patch for High-Severity OpenSSH Vulnerability - https://thehackernews.com/2024/08/freebsd-releases-urgent-patch-for-high.html   FBI disrupts the Dispossessor ransomware operation, seizes servers - https://www.bleepingcomputer.com/news/security/fbi-di...

602 - Golpes contra call centers resultam em fraudes 12.08.2024

[Referências do Episódio] Ligação a cobrar: como criminosos estão atacando atendentes de call centers usando engenharia social - https://sidechannel.blog/ligacao-a-cobrar-como-criminosos-estao-atacando-atendentes-de-call-centers/   QuickShell: Sharing Is Caring about an RCE Attack Chain on Quick Share - https://www.safebreach.com/blog/rce-attack-chain-on-quick-share   Researchers Uncover 10 Flaws...

601 - 0.0.0.0 Day flaw, Earth Baku e PoC público pra vuln crítica no Cisco SSM ON-PREM 09.08.2024

[Referências do Episódio] 0.0.0.0 Day: Exploiting Localhost APIs From the Browser - https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser   A Dive into Earth Baku’s Latest Campaign - https://www.trendmicro.com/en_us/research/24/h/earth-baku-latest-campaign.html   CVE-2024-20419 - Cisco Smart Software Manager On-Prem Password Change Vulnerability - https://sec.cloud...

... e chegamos aos 600 episódios 08.08.2024

[Referências do Episódio] Windows Downdate: Downgrade Attacks Using Windows Updates - https://www.blackhat.com/us-24/briefings/schedule/index.html#windows-downdate-downgrade-attacks-using-windows-updates-38963   Windows Update downgrade attack "unpatches" fully-updated systems - https://www.bleepingcomputer.com/news/microsoft/windows-update-downgrade-attack-unpatches-fully-updated-system...

Cyber Morning Call - #599 - 07/08/2024 07.08.2024

[Referências do Episódio] External Technical Root Cause Analysis — Channel File 291 - https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf   France's Grand Palais discloses cyberattack during Olympic games - https://www.bleepingcomputer.com/news/security/frances-grand-palais-discloses-cyberattack-during-olympic-games/   Turning the...

Cyber Morning Call - #598 - 06/08/2024 06.08.2024

[Referências do Episódio] SonicWall Discovers Second Critical Apache OFBiz Zero-Day Vulnerability: Details and analysis on CVE-2024-38856, a pre-auth RCE in Apache OFBiz . - https://blog.sonicwall.com/en-us/2024/08/sonicwall-discovers-second-critical-apache-ofbiz-zero-day-vulnerability/ Dismantling Smart App Control - https://www.elastic.co/security-labs/dismantling-smart-app-control   Gh0st RAT:...

Cyber Morning Call - #597 - 05/08/2024 05.08.2024

[Referências do Episódio] StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms - https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/   Panamorfi: A New Discord DDoS Campaign - https://www.aquasec.com/blog/panamorfi-a-new-discord-ddos-campaign/   SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cac...

Cyber Morning Call - #596 - 02/08/2024 02.08.2024

[Referências do Episódio] Quartet of Trouble: XWorm, AsyncRAT, VenomRAT, and PureLogs Stealer Leverage TryCloudflare - https://www.esentire.com/blog/quartet-of-trouble-xworm-asyncrat-venomrat-and-purelogs-stealer-leverage-trycloudflare   Threat Actor Abuses Cloudflare Tunnels to Deliver RATs - https://www.proofpoint.com/us/blog/threat-insight/threat-actor-abuses-cloudflare-tunnels-deliver-rats   ...

Listen to the Cyber Morning Call podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.