Tempest Security Intelligence

Cyber Morning Call

Podcast de cibersegurança produzido pela Tempest com episódios diários, publicados logo pela manhã com aquilo que foi mais relevante nas últimas vinte e quatro horas em termos de novos ataques, vulnerabilidade ou ameaças. Tudo em menos de dez minutos e traduzido para uma linguagem fácil, produzido para que você possa ajustar o curso do seu dia de modo a tomar as melhores decisões de cibersegurança para sua empresa.

Author

Tempest Security Intelligence

Category

Technology

Podcast website

tempest.com.br

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

845 - Falha CVSS 10 afeta controlador de firewalls da Cisco 15.08.2025

Referências do Episódio Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability   Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

844 - PhantomCard: malware brasileiro rouba dados de cartão via NFC 14.08.2025

Referências do Episódio PhantomCard: New NFC-driven Android malware emerging in Brazil 🇧🇷 Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks From Support Ticket to Zero Day (CVE‑2025‑8355 - CVE-2025-8356) Zoom Clients for Windows - Untrusted Search Path (CVE-2025-49457) Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Nar...

843 - Patch Tuesday tem 0-day no Windows e falha crítica no FortiSIEM 13.08.2025

Referências do Episódio Microsoft's August 2025 Security Updates BadSuccessor : Abusing dMSA to Escalate Privileges in Active Directory CVE-2025-25256 - Remote unauthenticated command injection SAP Security Patch Day - August 2025 Objet: Multiples vulnérabilités dans les produits Siemens CISA Releases Seven Industrial Control Systems Advisories Security Affairs: BadCam : Linux-based Lenovo web...

842 - GPT 5 sofre jailbreak 24 após seu lançamento 12.08.2025

Referências do Episódio Tenable Jailbreaks GPT-5 , Gets It To Generate Dangerous Info Despite OpenAI’s New Safety Tech North Korean Kimsuky hackers exposed in alleged data breach Ransomware Diaries Volume 7: “I Had to Take the Guilt For Everyone” – The Kaseya Hacker Breaks His Silence Casus: Citrix kwetsbaarheid (Update 11-08-2025) Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de...

841 - Zero-day no WinRAR está sob exploração 11.08.2025

Referências do Episódio WinRAR zero-day exploited to plant malware on archive extraction WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately WinRAR 7.13 Final released CVE-2025-8088 Paper Werewolf атакует Россию с использованием уязвимости нулевого дня в WinRAR From Chrome renderer code exec to kernel with MSG_OOB Win-DoS Epidemic : A Crash Course in Abusing RPC for Wi...

840 - SonicWall bota uma pedra no assunto sobre possível zero-day 08.08.2025

Referências do Episódio Gen 7 and newer SonicWall Firewalls – SSLVPN Recent Threat Activity CVE-2024-40766 - SonicOS Improper Access Control Vulnerability Technical Advisory: SonicWall Targeted by Ransomware Group New Infection Chain   and ConfuserEx-Based Obfuscation for DarkCloud Stealer Human Risk Conference 2025 Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arr...

839 - Novo AV Killer é documentado no Brasil 07.08.2025

Referências do Episódio Driver of destruction: How a legitimate driver is being used to take down AV processes Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability - CVE-2025-53786 Microsoft Releases Guidance on High-Severity Vulnerability ( CVE-2025-53786 ) in Hybrid Exchange Deployments Exchange Server Security Changes for Hybrid Deployments Turning Camera Surveillanc...

838 - Campanha usa IA pra clonar sites do governo brasileiro 06.08.2025

Referências do Episódio GenAI Used For Phishing Websites Impersonating Brazil’s Government Android Security Bulletin —August 2025 Project AK47 : Uncovering a Link to the SharePoint Vulnerability Attacks ITW CRITICAL SECURITY BULLETIN : Trend Micro Apex One (On-Premise) Management Console Command Injection RCE Vulnerabilities Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio:...

837 - Novo backdoor pra Linux abusa de módulo PAM 05.08.2025

Referências do Episódio Webinar Tempest - Ciclo das águas: Ameaças e golpes do primeiro semestre de 2025 Plague : A Newly Discovered PAM-Based Backdoor for Linux Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

836 - Novo backdoor pra Linux abusa de módulo PAM 04.08.2025

Referências do Episódio Webinar Tempest - Ciclo das águas: Ameaças e golpes do primeiro semestre de 2025 Plague : A Newly Discovered PAM-Based Backdoor for Linux Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

835 - Rússia usa AiTM pra atacar diplomatas em Moscou 01.08.2025

Referências do Episódio Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing O que é Acesso Condicional ? Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations From Laptops to Laundromats : How DPRK IT Workers Infiltrated the Global Remote Economy Roteiro e apresentação: Carlos Cabral e Bianca Olivei...

834 - Pesquisa identifica patentes do APT Silk Typhoon 31.07.2025

Referências do Episódio China’s Covert Capabilities | Silk Spun From Hafnium Analysis of the latest Silver Fox attack campaign disguised as a Flash plugin New Lenovo UEFI firmware updates fix Secure Boot bypass flaws Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

833 - Novos ataques contra o SAP NetWeaver são documentados 30.07.2025

Referências do Episódio Auto-Color Backdoor : How Darktrace Thwarted a Stealthy Linux Intrusion CVE-2025-31324 : Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild CMC # 771 - SAP tem 0-day sob exploração Sealed Chain of Deception: Actors leveraging Node. JS to Launch JSCeal The Covert Operator's Playbook: Infiltration of Global Telecom Networks Unveiling LIMINAL PANDA : A Closer Lo...

832 - Sploitlight: falha no Spotlight do macOS permite roubar dados do Apple Intelligence 29.07.2025

Referências do Episódio Sploitlight : Analyzing a Spotlight-based macOS TCC vulnerability Revisiting UNC3886 Tactics to Defend Against Present Risk XWorm V6 : Advanced Evasion and AMSI Bypass Capabilities Revealed Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

831 - ToolShell segue rendendo assunto 25.07.2025

Referências do Episódio ToolShell, SharePoint, and the Death of the Patch Window | Team Cymru ToolShell : An all-you-can-eat buffet for threat actors ToolShell : a story of five vulnerabilities in Microsoft SharePoint Exploit module for Microsoft SharePoint ToolPane Unauthenticated RCE ( CVE-2025-53770 and CVE-2025-53771 ) #20409 Dropping Elephant APT Group Targets Turkish Defense Industry With Ne...

830 - Fire Ant: Campanha foca em ambientes VMware 24.07.2025

Referências do Episódio Fire Ant : A Deep-Dive into Hypervisor-Level Espionage Key figure behind major Russian-speaking cybercrime forum targeted in Ukraine Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

829 - China é responsável por ataques ao SharePoint, afirma a Microsoft 23.07.2025

Referências do Episódio /bin/live : Gustavo Gus Disrupting active exploitation of on-premises SharePoint vulnerabilities Cisco confirms active exploitation of ISE and ISE-PIC flaws Back to Business : Lumma Stealer Returns with Stealthier Methods Coyote in the Wild : First-Ever Malware That Abuses UI Automation Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo N...

828 - Tensão entre Irã e Israel impulsiona malware para Android 22.07.2025

Referências do Episódio Estúdio News - 19/07/2025 /bin/live : Gustavo Gus Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict Over 1,000 CrushFTP servers exposed to ongoing hijack attacks Hardcoded credentials found in HPE Aruba Instant On Wi-Fi devices After a tip, ExpressVPN updates its Windows app to strengthen protections Roteiro e apresentação: Carlos Cabral...

827 - Zero-day sob ataque no SharePoint recebe correção emergencial 21.07.2025

Referências do Episódio SharePoint 0-day uncovered ( CVE-2025-53770 ) CVE-2025-53770 : Frequently Asked Questions About Zero-Day SharePoint Vulnerability Exploitation Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability ( CVE-2025-53770 ) CVE-2025-53770 Microsoft SharePoint Server Remote Code Execution Vulnerability CVE-2025-53771 Microsoft SharePoint Server Spoofing Vulnerabili...

826 - Campanha contra Wordpress abusa do Google Tag Manager 18.07.2025

Referências do Episódio Phish and Chips : China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting  WordPress Redirect Malware Hidden in Google Tag Manager Code Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

825 - Nova campanha mira o SonicWall SMA 100 para roubar credenciais 17.07.2025

Referências do Episódio Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit New Fortinet FortiWeb hacks likely linked to public RCE exploits From a Teams Call to a Ransomware Threat: Matanbuchus 3.0 MaaS Levels Up Lookout Discovers Mobile Forensics Tooling Masisstant In...

824 - Mais um 0-day sob ataque é corrigido no Chrome 16.07.2025

Referências do Episódio Stable Channel Update for Desktop Unmasking AsyncRAT : Navigating the labyrinth of forks Konfety Returns : Classic Mobile Threat with New Evasion Techniques Hyper-volumetric DDoS attacks skyrocket: Cloudflare’s 2025 Q2 DDoS threat report A summer of security : empowering cyber defenders with AI Oracle July 2025 Critical Patch Update Addresses 165 CVEs GLOBAL GROUP : Emergin...

823 - CitrixBleed 2 vem sendo explorada desde junho, afirma pesquisador 15.07.2025

Referências do Episódio CitrixBleed 2 situation update — everybody already got owned Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

822 - FileFix: primeiros ataques reais são detectados 14.07.2025

Referências do Episódio KongTuke FileFix Leads to New Interlock RAT Variant Introducing FileFix – A New Alternative to ClickFix AttacksIntroducing FileFix – A New Alternative to ClickFix Attacks Vídeo que fiz sobre ClickFix Wing FTP Server Remote Code Execution ( CVE-2025-47812 ) Exploited in the Wild Evolving Tactics of SLOW#TEMPEST : A Deep Dive Into Advanced Malware Techniques Roteiro e apresen...

821 - ZuRu ressurge trojanizado em client SSH 11.07.2025

Referências do Episódio macOS.ZuRu Resurfaces | Modified Khepri C2 Hides Inside Doctored Termius App CVE-2025-48384 : Git vulnerable to arbitrary file write on non-Windows systems Arbitrary code execution through broken config quoting CVE-2025-48384 : Breaking Git with a carriage return and cloning RCE CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises Ro...

Listen to the Cyber Morning Call podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.