Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

October 8, 2026

One Favicon Hash to a Carding C2: Dissecting “Olho de Deus”

One favicon hash in Criminal IP Asset Search led to two Contabo VPS nodes running a Brazilian operator console called Olho de Deus (“Eye of God”). Static analysis of its React frontend shows what it really is: a card track-data C2 with a general-purpose Windows RAT bolted on.…

Blog
One Favicon Hash to a Carding C2: Dissecting “Olho de Deus”

October 7, 2026

Criminal IP Scheduled Maintenance and Service Unavailability Notice (October 20)

Hello from Criminal IP. Infrastructure maintenance and database server maintenance are scheduled to ensure service stability. Please review the schedule and service availability details below and plan accordingly. Maintenance Schedule Time ZoneDateMaintenance WindowUTCOctober…

Release Note
Criminal IP Scheduled Maintenance and Service Unavailability Notice (October 20)

October 7, 2026

Kiteworks’ Shutdown Advisory: Analyzing Internet-Exposed Infrastructure

Kiteworks is a secure data exchange platform that helps enterprises and government agencies share and transfer sensitive files and data. It brings together file sharing, managed file transfer (MFT), email, web forms, and other data exchange channels to manage access permissions…

Blog
Kiteworks’ Shutdown Advisory: Analyzing Internet-Exposed Infrastructure

October 6, 2026

Privacy Policy Update (Effective October 13, 2026)

Criminal IP’s Privacy Policy will be revised effective October 13, 2026.This revision aims to clearly inform users about the disclosure of personal information to a third party and its transfer overseas as part of the G2 review submission process. Key Changes (v1.4) Third-Party…

Release Note
Privacy Policy Update (Effective October 13, 2026)

October 2, 2026

Asset Search & AI Overview Enhancements

This update introduces improvements to Asset Search, including more flexible search conditions, an updated keyword and filter interface, and enhancements to AI Overview. Maintenance Schedule v1.106.0: 2026.10.01 (05:00-10:00 UTC) Overview 📃 Asset Search in Criminal IP has been…

Release Note
Asset Search & AI Overview Enhancements

September 28, 2026

Strengthening External Threat Investigation Across Singapore’s Digital Environment

A government organization supporting a national digital ecosystem uses Criminal IP Threat Intelligence to investigate suspicious external infrastructure and gain broader context around IPs and domains. By looking beyond individual indicators, analysts can better understand the…

Case Studies
Strengthening External Threat Investigation Across Singapore’s Digital Environment

September 28, 2026

ScreenConnect Vulnerability CVE-2026-84869: Exploiting Active Remote Sessions

ConnectWise ScreenConnect is a remote management solution used by enterprises and managed service providers (MSPs) to access PCs and servers for technical support and system administration. Its remote sessions support capabilities such as file transfer and command execution,…

Blog
ScreenConnect Vulnerability CVE-2026-84869: Exploiting Active Remote Sessions

September 22, 2026

MikroTik RouterOS “MikroTrick” Attack Chain (CVE-2026-67276 · CVE-2026-86060) Analysis

In September 2026, an attack chain combining two vulnerabilities in MikroTik RouterOS, which is widely deployed at network edges, was found to be actively exploited in the wild, allowing attackers to fully compromise affected devices without authentication. Among six…

Blog
MikroTik RouterOS “MikroTrick” Attack Chain (CVE-2026-67276 · CVE-2026-86060) Analysis

September 17, 2026

Beyond the Login Event: Threat Intelligence for Digital Identity Services

A digital identity and trust services provider uses Criminal IP Threat Intelligence to gain additional context when investigating suspicious access activity across its digital services. By looking beyond individual login or access events, security teams can better understand the…

Case Studies
Beyond the Login Event: Threat Intelligence for Digital Identity Services

September 15, 2026

SonicWall SMA1000 Pre-Authentication SSRF and Command Injection Chain: Analysis of CVE-2026-83548 and CVE-2026-83549

On September 1, 2026, two zero-day vulnerabilities under active exploitation, CVE-2026-83548 and CVE-2026-83549, were disclosed in the SonicWall SMA1000 series of remote access gateways and SSL-VPN appliances. Each vulnerability poses a serious risk on its own, but the…

Blog
SonicWall SMA1000 Pre-Authentication SSRF and Command Injection Chain: Analysis of CVE-2026-83548 and CVE-2026-83549

September 7, 2026

Analysis of the JFrog Artifactory Authentication Bypass Vulnerability CVE-2026-82329

On August 28, 2026, a critical vulnerability, CVE-2026-82329, was disclosed in JFrog Artifactory, a repository solution that manages the full lifecycle of software artifacts. The vulnerability allows attackers to bypass authentication and obtain administrator privileges. It is…

Blog
Analysis of the JFrog Artifactory Authentication Bypass Vulnerability CVE-2026-82329

September 4, 2026

Domain Phishing Scan AI Analysis Multilingual Support

This update adds multilingual support for AI analysis results in Criminal IP Domain Phishing Scan, allowing users to view analysis explanations in five supported languages based on their language settings. Maintenance Schedule v1.105.0: 2026.09.03 (05:00-10:00 UTC) Overview 📃…

Release Note
Domain Phishing Scan AI Analysis Multilingual Support

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US