Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

November 7, 2024

[Criminal IP v1.67.1] 2024-11-07 Release Note

An update to Criminal IP v1.67.1 has been released. [Criminal IP v1.67.1] Regular Maintenance and Update Release Maintenance Period: 2024.11.07 05:00~10:00 AM (UTC) [New Changes] New API Integration – Wazuh Wazuh is an open-source platform offering unified security monitoring,…

Release Note
[Criminal IP v1.67.1] 2024-11-07 Release Note

November 1, 2024

Over 900,000 DrayTek Routers Still at Risk One Month After Critical Vulnerability Disclosure

On October 2, 2024, Forescout Research reported a significant vulnerability affecting DrayTek routers, which gained popularity as affordable VPN-enabled devices during the pandemic. When the vulnerability was initially discovered, multiple global media outlets noted that around…

Blog
Over 900,000 DrayTek Routers Still at Risk One Month After Critical Vulnerability Disclosure

October 31, 2024

Cybersecurity Awareness Month 2024: A Look Back on This Year’s Issues

Cybersecurity Awareness Month 2024 concludes today, October 31. In 2004, the United States government designated October as ‘Cybersecurity Awareness Month’ in response to growing cyber threats, aiming to promote global cybersecurity awareness and strengthen security measures.…

Blog
Cybersecurity Awareness Month 2024: A Look Back on This Year’s Issues

October 25, 2024

MeshAgent Deployed by Russia-Targeting Hacking Group ‘Awaken Likho’: Threat Hunting for Infected Servers

According to a Kaspersky report, the APT hacking group Awaken Likho launched a new attack campaign between June and August 2024, targeting Russian government agencies and industries. In this campaign, the hacking group Awaken Likho employed MeshAgent on the legitimate…

Blog
MeshAgent Deployed by Russia-Targeting Hacking Group ‘Awaken Likho’: Threat Hunting for Infected Servers

October 17, 2024

[Criminal IP v1.66.1] 2024-10-17 Release Note

An update to Criminal IP v1.66.1 has been released. [Criminal IP v1.66.1] Regular Maintenance and Update Release Maintenance Period: 2024.10.17 05:00~10:00 AM (UTC) [New Changes] Added GitHub References New repositories have been added to the Criminal IP Official GitHub list.…

Release Note
[Criminal IP v1.66.1] 2024-10-17 Release Note

October 11, 2024

CCTV Server Security: Countering CCTV Camera Exposure Threats With Threat Intelligence

The South Korean military recently withdrew around 1,300 military CCTV (Closed-Circuit Television) cameras due to potential infection with Chinese malware. Exposure of video footage in national institutions such as military facilities poses a very serious security threat that…

Blog
CCTV Server Security: Countering CCTV Camera Exposure Threats With Threat Intelligence

October 7, 2024

ClickFix: Beware of a New Threat Exploiting Copy-Paste and Fake Error Messages

The Criminal IP team recently uncovered a new attack, dubbed ClickFix, while analyzing frequent cyber threats. You may have encountered fake pop-up messages with the message, “Your iPhone has been hacked!” while browsing the internet on your mobile device. This is a form of…

Blog
ClickFix: Beware of a New Threat Exploiting Copy-Paste and Fake Error Messages

October 4, 2024

What Is Malvertising? An Analysis of the Attack: “Slack Advertisement Leading to Malware Download”

A recent Malwarebytes Labs threat report analyzed a malicious Slack advertisement, that employed a malvertising attack technique. In this article, we will examine the Slack malvertising attacks covered in the report and analyze them using the discovered indicators of compromise…

Blog
What Is Malvertising? An Analysis of the Attack: “Slack Advertisement Leading to Malware Download”

September 27, 2024

Attack Surface Management for Media Outlets: One in Four Possess CVE Vulnerabilities

This document provides a statistical analysis of the security inspection results on the attack surface management for media outlets, carried out for all media firms registered to the Publication Registration and Management System of the Ministry of Culture, Sports and Tourism…

Blog
Attack Surface Management for Media Outlets: One in Four Possess CVE Vulnerabilities

September 26, 2024

[Criminal IP v1.65.1] 2024-09-26 Release Note

An update to Criminal IP v1.65.1 has been released. [Criminal IP v1.65.1] Regular Maintenance and Update Release Note Maintenance Period: 2024.09.26 05:00~10:00 AM (UTC) [New Changes] New API Integration – IPLocation.io IPLocation.io is a free IP location lookup tool which…

Release Note
[Criminal IP v1.65.1] 2024-09-26 Release Note

September 26, 2024

CVE-2023-22527 Cryptojacking Attack Affects Over 1 Million Confluence Servers

According to a recent threat report from cybersecurity firm Trend Micro, there is a rise in cryptojacking attacks exploiting a critical vulnerability, CVE-2023-22527, in the global collaboration and documentation platform Atlassian Confluence. This vulnerability has a CVSS score…

Blog
CVE-2023-22527 Cryptojacking Attack Affects Over 1 Million Confluence Servers

September 25, 2024

How To Automate Firewall Policies to Block C2 IPs Using Criminal IP’s C2 Threat Feed

Manually configuring firewall policies without a C2 threat feed can be challenging, as it involves managing multiple rules simultaneously. Poor management can result in a pile of outdated rules, leading to indiscriminate traffic blocking and confusion about which rules should be…

Blog
How To Automate Firewall Policies to Block C2 IPs Using Criminal IP’s C2 Threat Feed

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US