Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

July 24, 2024

Kimsuky Hackers Create Phishing Site Mimicking Korea University: Are They Targeting Entire Research Institutions?

The North Korean hacking group Kimsuky has sparked controversy by reportedly developing a phishing site disguised as the Korea University portal. Upon investigation, this phishing site was found to be an exact replica of the actual Korea University portal page (original site:…

Blog
Kimsuky Hackers Create Phishing Site Mimicking Korea University: Are They Targeting Entire Research Institutions?

July 22, 2024

Unmasking the IP Addresses of the Illegal Webtoon Site ‘Newtoki’ Hidden by Cloudflare

The rapidly growing webtoon market in Korea is plagued by copyright issues due to the proliferation of illegal webtoon sites. Even when discovered and shut down, these sites quickly reappear under new domains, often hosted overseas to evade law enforcement. Screen of the illegal…

Blog
Unmasking the IP Addresses of the Illegal Webtoon Site ‘Newtoki’ Hidden by Cloudflare

July 18, 2024

Brickstream’s ‘Authentication-Less’ People Counting System Leaves Camera and Settings Pages Unprotected

The use of people counting systems for business and marketing purposes is increasing across various industries. One such product is Teledyne FLIR’s Brickstream 3D Gen 2, which tracks customer movements by measuring traffic volume, visitor flow, dwell time, etc., and provides…

Blog
Brickstream’s ‘Authentication-Less’ People Counting System Leaves Camera and Settings Pages Unprotected

July 15, 2024

Open-Source Supply Chain Attacks: Case Studies of Malicious NuGet and npm Packages

Recently, supply chain attacks through malicious packages hidden in open-source repositories have become a significant issue in the cybersecurity industry. The open nature of these repositories, allowing anyone to freely distribute and install packages, makes them an attractive…

Blog
Open-Source Supply Chain Attacks: Case Studies of Malicious NuGet and npm Packages

July 11, 2024

[Criminal IP v1.60.1] 2024-07-11 Release Note

An update to Criminal IP v1.60.1 has been released. [Criminal IP v1.60.1] Regular Maintenance and Update Release Note Maintenance Period : 2024.07.11 05:00~10:00 AM (UTC) [New Changes] New API Integration – Hybrid Analysis Hybrid Analysis is a leading automated malware analysis…

Release Note
[Criminal IP v1.60.1] 2024-07-11 Release Note

July 10, 2024

[Fraud Detection Statistics] When Is Online Fraud Most Prevalent During the Day?

This FDS case study aims to analyze fraud detection statistics based on real FDS data and determine when online fraud is most likely to occur. Thieves in Broad Daylight? Illustration of a thief active at nigh When you search for images of thieves on the internet, you often see…

Blog
[Fraud Detection Statistics] When Is Online Fraud Most Prevalent During the Day?

July 5, 2024

Privacy Breach: ID and Personal Information Exposed in KYC Systems

What is KYC? Recently, KYC (Know Your Customer) has become a mandatory requirement not only in the financial sector but also for cryptocurrency exchanges. KYC is a procedure for verifying the identity of customers to confirm that they are indeed the owners of their accounts.…

Blog
Privacy Breach: ID and Personal Information Exposed in KYC Systems

July 4, 2024

Polyfill Supply Chain Attack: Malicious Code Injected Into More Than 100,000 Domains

Polyfill is an open-source library that supports older browsers, and Polyfill.js is an open-source JavaScript source used by more than 100,000 sites worldwide. Recently, the domains using Polyfill.js were identified to have been exposed to malware attacks. This article will…

Blog
Polyfill Supply Chain Attack: Malicious Code Injected Into More Than 100,000 Domains

July 2, 2024

regreSSHion (CVE-2024-6387): Critical RCE Vulnerability Exposes 9.78 Million OpenSSH Servers, “Urgent Action Required”

A critical RCE vulnerability in OpenSSH, known as ‘regreSSHion (CVE-2024-6387)’, has been discovered, prompting the global security industry to stay alert and emphasize the need for analysis and response to potential attacks. This vulnerability is known to affect OpenSSH servers…

Blog
regreSSHion (CVE-2024-6387): Critical RCE Vulnerability Exposes 9.78 Million OpenSSH Servers, “Urgent Action Required”

June 26, 2024

Introducing Criminal IP FDS | AI Payment Fraud Detection and Credential Stuffing Prevention Solution

Criminal IP FDS is an AI-based solution to counter payment fraud and credential stuffing attacks. This on-premise product is integrated with a CTI-based database to identify bypass IP addresses like VPN, Tor, Proxy, and Hosting to protect your business against threats. Visit…

Videos
Introducing Criminal IP FDS | AI Payment Fraud Detection and Credential Stuffing Prevention Solution

June 20, 2024

The Growing Threat of Illegal Chinese OTT Platforms to Personal Data Security

Recently, there has been a surge in incidents involving the leakage of sensitive personal information through illegal OTT (Over-The-Top) services operated in China. These leaks can lead to various crimes, including voice phishing, financial fraud, sexual crimes, cyberbullying,…

Blog
The Growing Threat of Illegal Chinese OTT Platforms to Personal Data Security

June 14, 2024

[Criminal IP v1.58.1] 2024-06-13 Release Note

An update to Criminal IP v1.58.1 has been released. [Criminal IP v1.58.1] Regular Maintenance and Update Release Note Maintenance Period: 2024.06.13 05:00~10:00 AM (UTC) [New Changes] Added /v1/domain/lite/reports Open API A new Open API has now been added to retrieve Domain…

Release Note
[Criminal IP v1.58.1] 2024-06-13 Release Note

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US