Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

April 8, 2026

CVE-2026-3502: Supply Chain Attack via TrueConf Update Mechanism

In late March 2026, a zero-day vulnerability, CVE-2026-3502, was disclosed in the TrueConf Windows Client and confirmed to have been actively exploited in the wild. The vulnerability stems from a structural flaw in the update process, where integrity validation is not properly…

Notice
CVE-2026-3502: Supply Chain Attack via TrueConf Update Mechanism

April 3, 2026

CVE-2026-32746: Analysis of Pre-Authentication RCE Vulnerability in GNU InetUtils telnetd

In March 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-32746, was disclosed in the Telnet daemon (telnetd) of GNU InetUtils. The vulnerability is rated 9.8 (Critical) under the CVSS v3.1 scoring system and stems from a structural flaw that allows attackers…

Blog
CVE-2026-32746: Analysis of Pre-Authentication RCE Vulnerability in GNU InetUtils telnetd

April 3, 2026

Criminal IP Renewal & Key Feature Improvements

Maintenance Period v1.98.0: 2026.04.02 (05:00-10:00 UTC) Summary 📄 Version 1.98.0 introduces the newly redesigned Criminal IP website, along with key enhancements to the ASM experience and expanded access to cybersecurity intelligence through the CIP News feature. This update…

Notice
Criminal IP Renewal & Key Feature Improvements

April 1, 2026

Unstructured Data-Based Asset Exposure Analysis: Structuring Identifiers with Privacy Exposure Scanner

When analyzing external assets in a security environment, the focus is typically placed on elements such as open ports, running services, and known vulnerabilities. While this approach is effective for understanding the technical state of an asset, it has limitations when it…

Blog
Unstructured Data-Based Asset Exposure Analysis: Structuring Identifiers with Privacy Exposure Scanner

March 25, 2026

Wing FTP Server Vulnerability Analysis: Exposed Service Leading to an RCE Attack Chain

A recently discovered information disclosure vulnerability in Wing FTP Server (CVE-2025-47813) has been confirmed to be actively exploited in real-world attacks, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to the Known Exploited…

Blog
Wing FTP Server Vulnerability Analysis: Exposed Service Leading to an RCE Attack Chain

March 19, 2026

Event-Driven Threat Validation and Automated Blocking: An IP Risk Verification Pipeline Using Criminal IP Data

In security operations environments, many security alerts are not the beginning of an attack but rather the result of activity that has already occurred. For example, consider the following scenarios: Malware detection by an EDR Detection of a phishing site connection through…

Blog
Event-Driven Threat Validation and Automated Blocking: An IP Risk Verification Pipeline Using Criminal IP Data

March 17, 2026

Analysis of Iran-Linked APT MuddyWater Activity: Tracking Recent Campaigns and Attack Patterns

As geopolitical tensions in the Middle East continue to escalate, related activity has also increased in cyberspace. In particular, following recent military actions by the United States and Israel, movements linked to Iranian cyber operations have been observed, prompting…

Blog
Analysis of Iran-Linked APT MuddyWater Activity: Tracking Recent Campaigns and Attack Patterns

March 12, 2026

Exposed Google Cloud API Keys and the Expanding Attack Surface in AI API Environments

Thousands of exposed Google Cloud API keys have recently been discovered on the internet, raising new security concerns for cloud and AI API environments. According to cybersecurity media outlet The Hacker News, more than 2,800 Google API keys were found publicly exposed within…

Notice
Exposed Google Cloud API Keys and the Expanding Attack Surface in AI API Environments

March 9, 2026

OpenClaw Part II: 1-Click RCE and the Emerging Security Risks of AI Agents

A 1-Click Remote Code Execution (RCE) vulnerability, CVE-2026-25253, was recently disclosed in the AI agent platform OpenClaw, drawing attention from the security community. In a previous blog post, we analyzed the security risks and potential attack scenarios associated with…

Blog
OpenClaw Part II: 1-Click RCE and the Emerging Security Risks of AI Agents

March 6, 2026

Cybersecuri-Tea Time: Brewing February 2026’s Issues

By examining the major cybersecurity incidents reported in February 2026, it becomes clear that infrastructure essential to organizational operations has increasingly become a primary target for attackers. From SD-WAN devices responsible for network connectivity, to mobile…

Blog
Cybersecuri-Tea Time: Brewing February 2026’s Issues

February 27, 2026

How a Web Application Security Provider Strengthened WAAP Enforcement with Criminal IP CTIDB

As web application threats continue to evolve, security providers face growing challenges in maintaining consistent and reliable IP-based enforcement. Automated bot activity, distributed scanning infrastructure, and coordinated abuse campaigns increasingly rely on complex…

Case Studies
How a Web Application Security Provider Strengthened WAAP Enforcement with Criminal IP CTIDB

February 26, 2026

The Digital Web of “Tropa do Arranca”: Unveiling a Brazilian Phishing Kit

As cybercrime in Brazil continues to grow in sophistication, a group known as “Tropa do Arraca” has emerged as a notable threat actor. The group is reportedly involved in stealing mobile devices and then using phishing kits to extract additional digital assets from victims. In…

Blog
The Digital Web of “Tropa do Arranca”: Unveiling a Brazilian Phishing Kit

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US