Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

August 5, 2026

Arbitrary File Read via Image Upload: An Analysis of Ruby on Rails CVE-2026-66066

In July 2026, a critical vulnerability, CVE-2026-66066, was disclosed in Ruby on Rails Active Storage, affecting applications that allow untrusted users to upload images. Rated CVSS 9.5 (Critical), the vulnerability enables attackers to read arbitrary files accessible to the…

Blog
Arbitrary File Read via Image Upload: An Analysis of Ruby on Rails CVE-2026-66066

August 3, 2026

TeamCity On-Premises CVE-2026-63077: Unauthenticated Server Compromise Vulnerability Analysis

On July 27, 2026, JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution (RCE) vulnerability affecting TeamCity On-Premises, its CI/CD server solution. The vulnerability has been assigned a CVSS v3.1 score of 9.8 (Critical) and is caused by an…

Blog
TeamCity On-Premises CVE-2026-63077: Unauthenticated Server Compromise Vulnerability Analysis

July 29, 2026

TI Feed Feature Release

Maintenance Schedule v1.100.1: 2026.07.27 (05:00-10:00 UTC) Overview 📃 This update introduces TI Feed, a new feature that provides threat IP data collected and analyzed by Criminal IP as a subscription-based feed. Enterprise TI plan customers can view their TI License key on…

Release Note
TI Feed Feature Release

July 29, 2026

Steam Forum ClickFix Attack: Analyzing XMRig Distribution Infrastructure with Criminal IP

A ClickFix attack was recently identified on Steam discussion forums, where malicious PowerShell commands were disguised as solutions to gaming and PC-related issues. According to a BleepingComputer report published on July 25, 2026, the attacker used randomly created Steam…

Blog
Steam Forum ClickFix Attack: Analyzing XMRig Distribution Infrastructure with Criminal IP

July 22, 2026

Criminal IP Achieves Highest-Level PCI DSS Certification for Fourth Consecutive Year

Criminal IP has renewed its certification for Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 at the highest level, Level 1. With this renewal, Criminal IP has maintained the highest level of PCI DSS certification for four consecutive years. Criminal IP Achieves…

Notice
Criminal IP Achieves Highest-Level PCI DSS Certification for Fourth Consecutive Year

July 22, 2026

RabbitMQ OAuth Secret Exposure Vulnerabilities: An Analysis of CVE-2026-57219 and CVE-2026-57221

In July 2026, two access control vulnerabilities were disclosed in the open-source message broker RabbitMQ. The more severe issue, CVE-2026-57219 (CVSS 8.7), allows an unauthenticated attacker to retrieve RabbitMQ’s OAuth client secret with a single HTTP request and exchange it…

Blog
RabbitMQ OAuth Secret Exposure Vulnerabilities: An Analysis of CVE-2026-57219 and CVE-2026-57221

July 16, 2026

Internet-Exposed Cisco IOS Management Interfaces: Why Legacy Network Devices Remain Attractive Targets

Recently, the CISA and the NSA warned that Russian state-sponsored threat actors continue to target vulnerable or misconfigured network routers. In their joint cybersecurity advisory, they specifically highlighted CVE-2008-4128, a long-standing vulnerability in the Cisco IOS…

Blog
Internet-Exposed Cisco IOS Management Interfaces: Why Legacy Network Devices Remain Attractive Targets

July 15, 2026

Internet-Exposed Swagger UI: What API Documentation Reveals to Attackers

As generative AI, SaaS platforms, mobile applications, and cloud services continue to expand, core business functions are becoming increasingly API-driven. Behind the interfaces of modern web applications, APIs handle a wide range of functions, including user authentication,…

Notice
Internet-Exposed Swagger UI: What API Documentation Reveals to Attackers

July 10, 2026

Criminal IP Threat Intelligence Integration with the Torq AI SOC Platform

Criminal IP has partnered with Torq, an AI SOC platform company for autonomous security operations, and has integrated with the Torq AI SOC Platform. Torq is an agentic security operations platform that helps security teams automatically triage, investigate, and respond to large…

Notice
Criminal IP Threat Intelligence Integration with the Torq AI SOC Platform

July 8, 2026

Tracking Exposed AI API Tokens: How OpenAI and Anthropic Keys Surface Publicly

As organizations increasingly integrate artificial intelligence into their services, API tokens issued by providers such as OpenAI and Anthropic have become critical credentials for application operations. However, API tokens intended exclusively for server-side use are…

Notice
Tracking Exposed AI API Tokens: How OpenAI and Anthropic Keys Surface Publicly

July 6, 2026

Discovering Internet-Exposed AI Gateways: How Can New AI Attack Surfaces Be Identified?

As generative AI services rapidly expand, the number of AI Gateways that connect and manage various LLMs, including Claude, OpenAI, and Gemini, within a single environment is also increasing. AI Gateways may be deployed by enterprises to manage multiple AI APIs in an integrated…

Blog
Discovering Internet-Exposed AI Gateways: How Can New AI Attack Surfaces Be Identified?

July 1, 2026

Tracking the Storm-2561 Fake VPN Campaign: How Malicious Domains Are Reused After an Attack Ends

In March 2026, Microsoft disclosed the Storm-2561 campaign, which used SEO poisoning to distribute fake enterprise VPN clients. The attackers exposed domains impersonating VPN products from legitimate security companies, including Fortinet, Ivanti, Cisco, Sophos, and SonicWall,…

Notice
Tracking the Storm-2561 Fake VPN Campaign: How Malicious Domains Are Reused After an Attack Ends

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US