Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

May 13, 2026

CVE-2026-3854: GitHub RCE Vulnerability Triggered by a Single git push

On March 4, 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-3854, affecting both GitHub Enterprise Server and GitHub.com was reported through GitHub’s bug bounty program. Upon receiving the report, GitHub deployed a fix for GitHub.com within two hours and…

Notice
CVE-2026-3854: GitHub RCE Vulnerability Triggered by a Single git push

May 11, 2026

CVE-2026-42208: LiteLLM SQL Injection Vulnerability Targeting AI Gateways

On April 24, 2026, the critical SQL injection vulnerability CVE-2026-42208 affecting the open-source AI gateway LiteLLM was disclosed in the GitHub Advisory Database. Just 36 hours and 7 minutes after disclosure, real-world exploitation was already observed. Rated CVSS 9.3…

Notice
CVE-2026-42208: LiteLLM SQL Injection Vulnerability Targeting AI Gateways

May 4, 2026

Persistent Threats Beyond Patching: Analysis of the FIRESTARTER Backdoor Targeting Cisco ASA

In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre (NCSC) released a joint advisory on a newly identified backdoor named “FIRESTARTER,” deployed by the state-linked APT group UAT-4356 targeting Cisco…

Notice
Persistent Threats Beyond Patching: Analysis of the FIRESTARTER Backdoor Targeting Cisco ASA

May 1, 2026

Criminal IP Integration with Securonix ThreatQ Platform

Criminal IP, a cyber threat intelligence platform, has been integrated with Securonix’s threat intelligence operations platform, ThreatQ. ThreatQ is a Threat Intelligence Platform (TIP) that centralizes, aggregates, and prioritizes threat data from multiple sources, serving as a…

Notice
Criminal IP Integration with Securonix ThreatQ Platform

April 27, 2026

nginx-ui MCPwn (CVE-2026-33032) Analysis: Nginx Server Compromise via Missing MCP Authentication

In March 2026, a critical authentication bypass vulnerability, CVE-2026-33032, was disclosed in the open-source Nginx management tool nginx-ui. Nicknamed “MCPwn,” this vulnerability received a CVSS v3.1 score of 9.8 (Critical) and has been confirmed to be actively exploited in…

Notice
nginx-ui MCPwn (CVE-2026-33032) Analysis: Nginx Server Compromise via Missing MCP Authentication

April 27, 2026

Analyzing Phishing Infrastructure and Attack Patterns Using Daily Malicious Phishing Data

Phishing remains one of the most persistent and practical cybersecurity threats today. Attackers no longer rely on a single infrastructure; instead, they continuously rotate domains, platforms, and content to evade detection. So what does real-world phishing infrastructure…

Blog
Analyzing Phishing Infrastructure and Attack Patterns Using Daily Malicious Phishing Data

April 22, 2026

CVE-2026-35616: Exploitation Trends and Exposure Analysis of Fortinet FortiClient EMS

In April 2026, active exploitation of a newly disclosed vulnerability in Fortinet FortiClient EMS, tracked as CVE-2026-35616, was observed in the wild. This vulnerability originates from flaws in the request handling logic of the EMS server and may lead to remote code execution…

Notice
CVE-2026-35616: Exploitation Trends and Exposure Analysis of Fortinet FortiClient EMS

April 17, 2026

Introducing the New Phishing Scan Mode

Maintenance Period v1.99.0: 2026.04.16 (05:00-10:00 UTC) Summary 📃 Version 1.99.0 introduces the new Phishing Scan mode for URL/Domain scanning, providing users with a dedicated detection capability to identify phishing sites and fraudulent web pages. This update expands…

Notice
Introducing the New Phishing Scan Mode

April 17, 2026

CVE-2026-34197: Apache ActiveMQ RCE Vulnerability Analysis

In April 2026, a remote code execution (RCE) vulnerability, CVE-2026-34197, was disclosed in Apache ActiveMQ Classic, remaining undiscovered for over 13 years. Rated 8.8 (High) under CVSS v3.1, this vulnerability stems from a complex interaction between the Jolokia management…

Notice
CVE-2026-34197: Apache ActiveMQ RCE Vulnerability Analysis

April 13, 2026

Analyzing a FIFA-Themed Phishing Campaign: Tracking Suspicious 2026 World Cup-Related Domains and Infrastructure

International sporting events are highly effective social engineering lures for attackers. In particular, globally recognized events such as the FIFA World Cup are repeatedly abused in phishing campaigns impersonating ticket purchases, official reservations, and event…

Blog
Analyzing a FIFA-Themed Phishing Campaign: Tracking Suspicious 2026 World Cup-Related Domains and Infrastructure

April 8, 2026

CVE-2026-3502: Supply Chain Attack via TrueConf Update Mechanism

In late March 2026, a zero-day vulnerability, CVE-2026-3502, was disclosed in the TrueConf Windows Client and confirmed to have been actively exploited in the wild. The vulnerability stems from a structural flaw in the update process, where integrity validation is not properly…

Notice
CVE-2026-3502: Supply Chain Attack via TrueConf Update Mechanism

April 3, 2026

CVE-2026-32746: Analysis of Pre-Authentication RCE Vulnerability in GNU InetUtils telnetd

In March 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-32746, was disclosed in the Telnet daemon (telnetd) of GNU InetUtils. The vulnerability is rated 9.8 (Critical) under the CVSS v3.1 scoring system and stems from a structural flaw that allows attackers…

Notice
CVE-2026-32746: Analysis of Pre-Authentication RCE Vulnerability in GNU InetUtils telnetd

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US