Podcast appearances and mentions of bianca garcia

  • 20PODCASTS
  • 728EPISODES
  • 6mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 13, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about bianca garcia

Latest podcast episodes about bianca garcia

Cyber Morning Call
1068 - Ataques contra VMware são descobertos. Brasil está entre os alvos

Cyber Morning Call

Play Episode Listen Later Aug 13, 2026 9:28


Referências do EpisódioActive exploitation of CVE-2026–59310: 361 victim IPs across 47 countriesVMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic FlawsAbuse of alternative runtime environments Deno-tes defender headachesKimwolf v7: An Evolution of the Kimwolf BotnetCATAnA: On the Dangers of SIM-Originating AT CommandsArmored Likho expands its cyber-espionage toolkitRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1067 - Zero-day afetando o Brasil é corrigido pela Microsoft

Cyber Morning Call

Play Episode Listen Later Aug 12, 2026 9:44


Referências do EpisódioZOOMSDAY - How A Security Found a Nation-State Vulnerability in Zoom in One DayAugust 2026 Security Updates Patch Tuesday - August 2026Microsoft and Adobe Patch Tuesday, August 2026 Security Update ReviewMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)Shattering the Dream – When a Job Offer Becomes a Zero-Day AttackMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysShieldBreak: New Windows Zero-Day Bypasses Microsoft's RoguePlanet PatchSAP Security Patch Day - August 2026Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service VulnerabilitySonicWall Email Security Affected By Multiple VulnerabilitiesSonicWall GMS Security Affected By Multiple VulnerabilitiesMozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private RepoRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1066 - Quadrilha de ransomware negocia sem precisar de servidor

Cyber Morning Call

Play Episode Listen Later Aug 11, 2026 7:17


Referências do EpisódioDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructureAbyssos: Technical Analysis of a New Modular RATCritical Progress LoadMaster flaw now actively exploited in attacksFollow-Up Analysis of the 29 December 2025 Energy Sector Incident Six npm Packages Use Ethereum Transactions to Retrieve Malicious PayloadsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1065 - Zero-day Em Ferramenta de BI Expõe Clientes da Fabricante de Laptops Framework

Cyber Morning Call

Play Episode Listen Later Aug 10, 2026 7:13


Referências do EpisódioMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataSecurity update available for Metabase - Please upgrade nownatjack - A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICESBring Your Own EDR: How to Turn a Commercial EDR into a Trojan HorseXSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)RovoBlast: How One Click Triggered Atlassian's AI Assistant to Leak DataSCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-FreeRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1064 - ShinyHunters: dentro da infraestrutura de phishing que mira bancos, faculdades e cripto

Cyber Morning Call

Play Episode Listen Later Aug 7, 2026 7:30


Referências do EpisódioBehind the Panels: Validating ShinyHunters Cluster A Infrastructure Through Network TelemetryWe infiltrated a criminal phishing panel: here's what we foundUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud EnvironmentsToken Jacking: Cybercriminals Could Be Stealing Your AI ResourcesZapscape KVM Flaw Lets Guest VMs Seize Host RootApple libera macOS Tahoe 26.6.1, com correções de segurançaChrome Stable Channel Update for Desktop - Thursday, August 6, 2026Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1063 - Roteadores vendidos na Amazon têm backdoor ativado de fábrica

Cyber Morning Call

Play Episode Listen Later Aug 6, 2026 5:15


Referências do EpisódioENDLESSDOORS Is Phoning Home. Pick Up.Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026Cisco IOS XE Software Security Hardening Release: August 2026OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootBreaking the PaperclipRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1062 - Worm invade cadeia de suprimentos do NPM e rouba credenciais de nuvem em mais de 2 bilhões de instalações

Cyber Morning Call

Play Episode Listen Later Aug 5, 2026 9:02


Referências do EpisódioKeyv and friends compromised in active Shai-Hulud supply chain attackkeyv and cacheable npm Package Hijacked in Supply Chain AttackAnalyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software LuresIntroducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATsInterlock ransomware gang creates volatile situationcPanel Bug Hands Database Root to Any Hosting CustomerRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1061 - Falhas no login sem senha do Google permitem assumir contas mesmo com verificação ativada

Cyber Morning Call

Play Episode Listen Later Aug 4, 2026 5:11


Referências do EpisódioPass the Passkey: A Novel Attack Surface in Passwordless AuthenticationDarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator ClusterFrom WSProxy to Root: INC ransomware and SonicWall SMA Exploit ChainRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1060 - Primeira correção não funcionou e adversários tomam controle total de servidores de gestão remota de TI

Cyber Morning Call

Play Episode Listen Later Aug 3, 2026 7:15


Referências do EpisódioN-central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577N-able Says Attackers Take Over N-central Servers After Initial Fix Proves IncompleteCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftAdobe fixed a maximum-severity vulnerability flaw in Campaign ClassicSecurity update available for Adobe Campaign Classic | APSB26-114Série de posts da Galaxy Research sobre ataque contra carteiras da ColdcardThe Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET VersionToy Ghouls' new toy: the GenieLocker ransomwareRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1059 - Amazon liga hackers norte-coreanos a ataques que atingiram bibliotecas de código usadas por milhões de programadores

Cyber Morning Call

Play Episode Listen Later Jul 31, 2026 8:47


Referências do Episódio-North Korean hackers behind major open-source supply chain attacks, Amazon says-Amazon identifies North Korean hacker group behind open-source supply chain attacks-ClickFix, EtherHiding & a DPRK Wallet Trail-Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts-(합동사이버보안권고문) 국가배후 해킹조직의 우리 국민·기업 해킹 공격 주의 권고-Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks-OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia-Investigating three real-world incidents in our cybersecurity evaluationsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1058 - Cisco confirma ataques reais explorando senha fixa em firewalls corporativos

Cyber Morning Call

Play Episode Listen Later Jul 30, 2026 8:57


Referências do EpisódioCisco Secure Firewall Management Center Software Static Credential VulnerabilityCisco warns of FMC static credential flaw exploited in zero-day attacksVMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code ExecutionInside Astaroth's New Spambot ComponentStable Channel Update for Desktop - Wednesday, July 29, 2026KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't EnoughCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Coordinated “cyberattack” on Minnesota water utilities: What you need to knowClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1057 - Falha crítica deixa roteadores vulneráveis a invasão total com um único pacote de rede

Cyber Morning Call

Play Episode Listen Later Jul 29, 2026 6:17


Referências do EpisódioCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootFast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security FindingsCritical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 NowRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1055 - Certighost: falha no AD CS deixa usuário comum se passar por controlador de domínio

Cyber Morning Call

Play Episode Listen Later Jul 27, 2026 4:58


Referências do EpisódioCertighost (CVE-2026-54121)僵尸网络新秀:Dysphoria 演进与深度技术分析Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1054 - Chaos ransomware sequestra o navegador da vítima para montar canal de C2 encoberto

Cyber Morning Call

Play Episode Listen Later Jul 24, 2026 5:52


Referências do EpisódioThe Signs Were There: What the First Autonomous Ransomware Case ConfirmsChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelCISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat ActivityTAG-195 Upgrades MaaS Ecosystem with Modular ToolsKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1053 - RefluXFS expõe mais de 16 milhões de sistemas Linux à escalada para root

Cyber Morning Call

Play Episode Listen Later Jul 23, 2026 7:07


Referências do EpisódioCVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confineRefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) JadeProx: Tracing a China-nexus Operation Through an OPSEC MistakeLampion's Portugal-focused phishing campaign delivers multistage malwareAttack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)Security Advisory – Action Required – July 2026 Security UpdateHermeticReader: The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp TakeoverRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

china portugal root linux refer sistemas milh es escalada local privilege escalation bianca garcia
Cyber Morning Call
1052 - Extorsão via BitLocker usa impressoras para entregar nota de resgate

Cyber Morning Call

Play Episode Listen Later Jul 22, 2026 6:19


Referências do EpisódioA new extortion cocktail: office printers, small ransoms, and BitLockerSolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28307)SolarWinds Serv-U Remote Code Execution Vulnerability (CVE-2026-28311)SolarWinds Serv-U Broken Access Control Vulnerability (CVE-2026-28321)Oracle Critical Patch Update Advisory - July 2026OpenAI admits it was the source of the agent swarm that attacked Hugging FacePublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1051 - Falha crítica na ServiceNow AI Platform está sob exploração ativa

Cyber Morning Call

Play Episode Listen Later Jul 21, 2026 4:12


Referências do EpisódioCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionCVE-2026-6875 - Sandbox Escape in ServiceNow AI PlatformCookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin RansomwareExploitation in the Wild of wp2shellRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1050 - SonicWall SMA: zero-days encadeados levam a acesso root

Cyber Morning Call

Play Episode Listen Later Jul 20, 2026 8:31


Referências do EpisódioProxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitationwp2shell: Pre Authentication RCE in WordPress CoreWordPress Core "wp2shell" RCE flaws get public exploits, patch nowThree Steps to the Terminal: A Siemens ROX II Zero-Day TrilogyHOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control ChannelsOpenSSL HollowByte: A DoS Hiding in 11 BytesNew North Korean campaign uses fake coding interviews to steal developer credentialsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1049 - Starland RAT: instaladores trojanizados entregam implante Python com C2 em smart contract

Cyber Morning Call

Play Episode Listen Later Jul 17, 2026 6:47


Referências do EpisódioUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignClickLock Stealer: Paste Once, Lose EverythingACR Stealer: Two observed intrusion chains amid increased threat activitySpirals: New Stealthy Ransomware Deployed Against Asian IT CompanyGoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1048 - Nightmare Eclipse publica novo zero-day no Windows

Cyber Morning Call

Play Episode Listen Later Jul 16, 2026 3:44


Referências do EpisódioChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows SystemsTuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted DevelopmentClaudeFix: Shared Claude Chats Meet ClickFixRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1047 - SonicWall detecta 0-day em ataques contra SMA1000 e Microsoft solta maior patch tuesday da história

Cyber Morning Call

Play Episode Listen Later Jul 15, 2026 6:12


Referências do EpisódioSonicWall SMA1000 Series Appliances Affected By Multiple VulnerabilitiesTwo SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin CommandsMicrosoft July 2026 Security UpdatesSAP Security Patch Day - July 2026Progress confirms ShareFile zero-day flaw behind Storage Zone shutdownRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1046 - Servidor mal configurado expõe três operações de phishing contra o Microsoft 365

Cyber Morning Call

Play Episode Listen Later Jul 14, 2026 7:35


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEOne Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing OperatorsImprove Router Hygiene to Protect Against Russian State-Sponsored TargetingCrashStealer: C++ macOS infostealer posing as crash reporterOAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1045 - Progress manda clientes desligarem servidores do ShareFile por ameaça externa

Cyber Morning Call

Play Episode Listen Later Jul 13, 2026 4:55


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEProgress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.Unfit to Boot: Breaking U-Boot's FIT Signature VerificationCritical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsOne Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law EnforcementRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1044 - Ransomware GodDamn usa driver malicioso assinado pela Microsoft para driblar antivírus

Cyber Morning Call

Play Episode Listen Later Jul 10, 2026 5:18


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORT A DE ENTRADA DO ATACANTEGodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable DefensesGigaWiper: Anatomy of a destructive backdoor assembled from multiple malwareRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1043 - Symlink falso engana assistentes de programação com IA e abre brecha para acesso remoto

Cyber Morning Call

Play Episode Listen Later Jul 9, 2026 6:26


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORT A DE ENTRADA DO ATACANTEGhostApproval: A Trust Boundary Gap in AI Coding AssistantsClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud ToolkitMicrosoft patches RoguePlanet Defender zero-day vulnerabilityHackers can use 9 of the most popular AI tools to assemble massive botnetsCoordinated npm and PyPI Campaign Typosquats Popular Secure Payment AppsSygnia Investigation Finds AI Accelerated Attack Enabled Lone Threat Actor to Rapidly Compromise Enterprise Cloud EnvironmentJuniper Security AdvisoriesPalo Alto Networks Security AdvisoriesChrome ReleasesRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1042 - UAT-7810 amplia arsenal de malware e expande ORB network

Cyber Morning Call

Play Episode Listen Later Jul 8, 2026 10:13


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORT A DE ENTRADA DO ATACANTEUAT-7810 continues building ORB networks using new malwareAn Introduction to Operational Relay Box (ORB) Networks - Unpatched, Forgotten, and ObscuredIonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File InflationThe ‘Ghost' in the Database: Recovering Active ADFS Signing Keys via Machine DPAPIOne Email Closer to the Edge: UNK_MassTraction & the Physics of ExploitationCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1041 - Backdoor é encontrado em roteadores da Tenda

Cyber Morning Call

Play Episode Listen Later Jul 7, 2026 7:31


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTETenda firmware (multiple versions) contains hidden authentication backdoorCavern Manticore: Exposing Iran-Linked Modular C2 FrameworkAdobe ColdFusion flaw CVE-2026-48282 now exploited in the wildGolpe do falso CEO: criminosos usam Microsoft Teams para enganar funcionários19-Year-Old Linux Kernel Bug Earns $80K Bounty, Grants Root in Under a Second16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1040 - Armored Likho lança BusySnake Stealer contra governo e energia e afeta o Brasil

Cyber Morning Call

Play Episode Listen Later Jul 6, 2026 4:58


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEArmored Likho digging a snake pit: inside the covert BusySnake Stealer campaignNew "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidCyber Criminal Group TeamPCPRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1039 - PamStealer: novo infostealer para macOS se disfarça de gerenciador de área de transferência

Cyber Morning Call

Play Episode Listen Later Jul 3, 2026 4:29


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEPamStealer: a Rust-based macOS infostealer that validates credentials through PAMGoogle's Continued Disruption of Malicious Residential Proxy NetworksRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

rust novo refer macos disfar gerenciador bianca garcia
Cyber Morning Call
1038 - Pesquisadores de segurança são alvo de PoCs trojanizadas que roubam credenciais e arquivos

Cyber Morning Call

Play Episode Listen Later Jul 2, 2026 5:36


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEDon't Eat The ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised ExploitsARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack TechniqueCisco Catalyst Center Arbitrary File Read VulnerabilityClamAV Vulnerabilities Affecting Cisco Products: July 2026Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation AttemptsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1037 - Phantom Squatting: ataque explora domínios que IA inventa para marcas legítimas

Cyber Morning Call

Play Episode Listen Later Jul 1, 2026 8:20


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEPhantom Squatting: AI-Hallucinated Domains as a Software Supply Chain VectorSecuring AI agents: When AI tools move from reading to actingGuardFall: a universal shell injection vulnerability in open-source AI agentsSecurity updates available for Adobe Campaign Classic | APSB26-69Security update available for Adobe ColdFusion | APSB26-68Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-ServiceNetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)Chrome Releases - Stable Channel Update for Desktop - Tuesday, June 30, 2026Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1036 - Falha CVE-2026-46817 do Oracle E-Business Suite está sendo explorada ativamente

Cyber Morning Call

Play Episode Listen Later Jun 30, 2026 4:43


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the WildChromium extension uses AI‑related branding to redirect browser searchAbout the security content of iOS 26.5.2 and iPadOS 26.5.2About the security content of macOS Tahoe 26.5.2About the security content of Safari 26.5.2A Djinn in the Machine: TaskWeaver's Node.js Intrusion ChainRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1035 - DirtyClone: novo ataque da família DirtyFrag é divulgado

Cyber Morning Call

Play Episode Listen Later Jun 29, 2026 7:33


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEDissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503)MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code ExtensionAlert Number: I-062626-PSA | 26 June 2026 - Russian Intelligence Services Continue to Target Commercial Messaging ApplicationsCL-STA-1062 Targets Southeast Asian Governments and Critical InfrastructureTONResolver RAT Abuses TON Blockchain to Target Japan's Hotel IndustryRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1034 - Turla expande arsenal de espionagem com novo backdoor

Cyber Morning Call

Play Episode Listen Later Jun 26, 2026 6:46


Referências do EpisódioMais de 430 mil firewalls corporativos são comprometidos em operação de roubo de credenciaisKazuar: Anatomy of a nation-state botnetSTOCKSTAY Another Day: The Latest Addition to Turla's Intelligence Gathering ApparatusBluekit Phishing-as-a-Service: Browser-in-the-Middle, EvolvedAISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever ReportedTuring Day 2026 | 6º ediçãoRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1033 - Mandiant expõe espionagem baseada em 0-day contra o Cisco SD-WAN

Cyber Morning Call

Play Episode Listen Later Jun 25, 2026 8:25


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN ManagerCVE-2026-20245 - Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation VulnerabilityCVE-2026-20127 - Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityCVE-2026-20182 - Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityBackdoor.Mistic: New Backdoor May be Linked to Ransomware Access BrokerStrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoaderESET takes part in Operation Endgame to disrupt Amadey and StealcStealC and Amadey: Breaking down infostealers and the cybercrime services that deliver themStealC You Later: Proofpoint and IBM X-Force Support Operation Endgame DisruptionsAmadey and StealC: Malware-as-a-Service UnavailableRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1032 - macOS.Gaslight: malware norte-coreano engana analistas

Cyber Morning Call

Play Episode Listen Later Jun 24, 2026 7:10


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the SandboxNew macOS ClickFix attack silently mounts DMGs to push infostealerCisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to RootRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1031 - WhatsApp vira vetor de malware em nova campanha que mira o Brasil

Cyber Morning Call

Play Episode Listen Later Jun 23, 2026 9:49


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06A VBScript campaign distributed through WhatsApp deploying RMM softwareFortiBleed campaign used custom FortiGate sniffer to steal credentialsFrom Langflow to Monero: Inside CVE-2026-33017 CryptominerPixelSmash – Critical FFmpeg Vulnerability Turns Media Files into WeaponsDifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ appsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1030 - usbliter8: exploit sem correção quebra a cadeia de inicialização de iPhones com chips A12 e A13

Cyber Morning Call

Play Episode Listen Later Jun 22, 2026 5:28


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06Introducing usbliter8: An A12/A13 SecureROM exploitWebinar Tempest - Superfície exposta, acesso concedido: como ativos esquecidos formam o caminho para o atacanteSalesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer DataRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1029 - F5 corrige duas falhas críticas no NGINX

Cyber Morning Call

Play Episode Listen Later Jun 19, 2026 7:09


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06K000161616: NGINX ngx_http_v3_module vulnerability CVE-2026-42530K000161584: NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability CVE-2026-42055Killing me gently: Inside Gentlemen's EDR killer frameworkLost in relocation: analysis of a new loader distributing CASTLESTEALERAutoJack: How a single page can RCE the host running your AI agent Oracle Critical Security Patch Update Advisory - June 2026PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVMRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1028 - FortiBleed expõe senhas de administrador de 75 mil firewalls Fortinet

Cyber Morning Call

Play Episode Listen Later Jun 18, 2026 7:10


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06FortiBleed — 75k Fortinet firewalls have admin passwords crackedFortiBleed Exposes Admin Passwords for 75,000 Fortinet FirewallsFortiBleed - HudsonRockClickFix Campaign Generated Via AI Delivers SmartRATFrom package to postinstall payload: Inside the Mastra npm supply chain compromiseFrom Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard HijackerMalware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader ChainRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1027 - SprySOCKS chega ao Windows: FishMonger ganha backdoor com ocultação em nível de kernel

Cyber Morning Call

Play Episode Listen Later Jun 17, 2026 8:31


Referências do Episódio/bin/live: CISOs - com Fabiana Tanaka e Denis NesiTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06FishMonger's arsenal upgraded: SprySOCKS for Windows隐形毒刺:超4000台老旧路由器遭AryStinger入侵,沦为黑客全球攻击跳板Rokarolla : Android Banker with Complete Device Takeover CapabilitiesPickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCECritical Fortinet FortiSandbox flaws now exploited in attacksChrome Releases - Tuesday, June 16, 2026GitBait: Phishing the Mexican Financial SectorRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1026 - Grupo ligado à China usou recurso do Google Workspace para roubar pesquisa médica e de defesa

Cyber Morning Call

Play Episode Listen Later Jun 16, 2026 8:16


Referências do EpisódioTURING DAY 2026 | 6ª EDIÇÃO - DIA 25/06Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense ResearchSearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration WeaponCVE-2026-42824 - M365 Copilot Information Disclosure VulnerabilityUnveiling ErrTraffic: inside a growing ClickFix malware distribution frameworkFI-2026-007 - Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityEvilTokens: A phishing attack that doesn't steal your passwordRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1025 - NarwhalRAT usa pCloud como C2 oculto para espionar vítimas

Cyber Morning Call

Play Episode Listen Later Jun 15, 2026 5:38


Referências do EpisódioMS 사칭 피싱과 Dead-drop C2 기반 APT37 NarwhalRAT 분석Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like MalwareUnauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk EnterpriseWhy Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)FBI takes down massive China-based cybercrime network that caused $1.9B in lossesIran-Linked Handala Breached a California Water Utility. It Could Have Done Worse, and It Knows That.Cyber Intel Brief: Handala Claims Breach of California Water ServiceRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

united states china refer oculto pcloud truncation bianca garcia
Cyber Morning Call
1024 - ShinyHunters explora zero-day no Oracle PeopleSoft e mira setor de educação

Cyber Morning Call

Play Episode Listen Later Jun 12, 2026 7:23


Referências do EpisódioShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitOracle Security Alert Advisory - CVE-2026-35273Oracle mitigates PeopleSoft zero-day exploited in data theft attacksVelvet Ant's Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network UndetectedInside OnyxC2: The New Stealer Targeting 210 AppsOceanLotus: From external espionage to domestic targetingArctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257From SQLi to RCE – Exploiting LangGraph's CheckpointerRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1023 - Langflow sob ataque: falha sem patch expõe 7 mil instâncias de IA a execução remota de código

Cyber Morning Call

Play Episode Listen Later Jun 11, 2026 7:10


Referências do EpisódioUnpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCEExpanded JDY IoT and SOHO botnet enables rapid vulnerability exploitationCVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integrationWho Runs the Ransomware Group ‘The Gentlemen?'GitHub to Disable npm Install Scripts by Default to Stop Supply Chain AttacksRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1022 - Microsoft tem o maior Patch Tuesday da história

Cyber Morning Call

Play Episode Listen Later Jun 10, 2026 8:52


Referências do EpisódioMSRC - June 2026 Security UpdatesCVE-2026-45586 - Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability CVE-2026-49160 - HTTP.sys Denial of Service Vulnerability CVE-2026-50507 - Windows BitLocker Security Feature Bypass VulnerabilityRoguePlanetMicrosoft Defender 'RoguePlanet' zero-day grants SYSTEM privilegesSAP Security Patch Day - June 2026ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer InstancesMore Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854CVE-2026-25089 - Second-Order OS Command Injection via JSON Input on start vnc featureRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1021 - Google corrige o quinto zero-day do Chrome explorado em ataques neste ano

Cyber Morning Call

Play Episode Listen Later Jun 9, 2026 6:39


Referências do EpisódioGoogle patches new Chrome zero-day flaw exploited in the wildChrome Releases - Stable Channel Update for Desktop - Monday, June 8, 2026Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Off By !: Exploiting a Use-after-Free in the Linux KernelShai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI WaveWhen “Hi, This Is IT” Comes Through Microsoft TeamsCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableCisco Catalyst SD-WAN Manager Authenticated Privilege Escalation VulnerabilityRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1020 - Zero-day no VSCode tem exploit publicado

Cyber Morning Call

Play Episode Listen Later Jun 3, 2026 7:25


Referências do Episódio1-Click GitHub Token Stealing via a VSCode BugError 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error PagesOperation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell BackdoorBoletim de segurança do Android: junho de 2026CISA flags two-year-old Oracle flaw as actively exploited in attacksRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1019 - Ataque de Supply Chain afeta Red Hat

Cyber Morning Call

Play Episode Listen Later Jun 2, 2026 5:40


Referências do Episódio32 Red Hat npm packages backdoored in 72 secondsMiasma: Supply Chain Attack Targeting RedHat npm PackagesMeet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised SitesCritical Windows Netlogon RCE flaw now exploited in attacksRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1018 - Palo Alto Networks: bypass de autenticação no GlobalProtect está sob exploração

Cyber Morning Call

Play Episode Listen Later Jun 1, 2026 5:09


Referências do EpisódioRapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)FSB's matryoshka #1/3 – Gamaredon's gifts that keeps unpacking – GammaPhish and GammaWormMalicious npm packages abuse dependency confusion to profile developer environmentsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia