Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

January 10, 2026

Global OSINT Analysis of Exposed Critical Digital Assets: Redis, phpMyAdmin, Dev, and More

This article is based on an analysis shared by the Twitter-based threat intelligence specialist, Clandestine. As cyber threats continue to grow more sophisticated in today’s digital landscape, an increasing number of critical digital assets are becoming externally exposed and…

Blog
Global OSINT Analysis of Exposed Critical Digital Assets: Redis, phpMyAdmin, Dev, and More

January 6, 2026

MongoBleed (CVE-2025-14847): Critical Memory Leak in MongoDB and ASM-Based Mitigation

Reminiscent of the infamous Heartbleed, a critical vulnerability in MongoDB, codenamed “MongoBleed” appeared in late December and allows unauthenticated remote attackers to leak sensitive data directly from a server’s heap memory. With a CVSS score of 8.7, MongoBleed has rapidly…

Blog
MongoBleed (CVE-2025-14847): Critical Memory Leak in MongoDB and ASM-Based Mitigation

January 2, 2026

Remote Code Execution Vulnerability in the n8n Workflow Automation Platform (CVE-2025-68613)

In the second half of 2025, a critical remote code execution vulnerability, CVE-2025-68613, was disclosed in the open-source workflow automation platform n8n.The vulnerability was assigned a CVSS score of 9.9 (Critical) and involves a structural flaw in the expression evaluation…

Blog
Remote Code Execution Vulnerability in the n8n Workflow Automation Platform (CVE-2025-68613)

December 27, 2025

FortiCloud SSO Authentication Bypass (CVE-2025-59718/CVE-2025-59719): Highlight the Need For Attack Surface-Driven Defense

On December 9, 2025, Fortinet released a critical security advisory regarding two authentication bypass vulnerabilities, CVE-2025-59718 and CVE-2025-59719, affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. These flaws allow unauthenticated attackers to gain…

Blog
FortiCloud SSO Authentication Bypass (CVE-2025-59718/CVE-2025-59719): Highlight the Need For Attack Surface-Driven Defense

December 23, 2025

React2Shell Vulnerability Analysis: Identifying RSC Exposure Through Domain-Level Tech Stack Analysis

The React Server Components (RSC) vulnerability CVE-2025-55182, commonly known as React2Shell, was disclosed in December 2025 and has rapidly impacted web services worldwide, emerging as one of the most critical web vulnerabilities of the year. This vulnerability is not limited…

Blog
React2Shell Vulnerability Analysis: Identifying RSC Exposure Through Domain-Level Tech Stack Analysis

December 20, 2025

Palo Alto Networks Cortex XSOAR and Criminal IP Threat Intelligence Integration: Automated Security Platform and Threat Defense Solution

Criminal IP has established an integration with global cybersecurity leader Palo Alto Networks, connecting its AI-driven threat intelligence platform directly with the Cortex XSOAR. Through this integration, Criminal IP’s advanced threat intelligence and automated attack surface…

Notice
Palo Alto Networks Cortex XSOAR and Criminal IP Threat Intelligence Integration: Automated Security Platform and Threat Defense Solution

December 16, 2025

Strengthening State-Level Threat Intelligence Operations with Criminal IP TI

A public sector organization in Germany responsible for safeguarding critical digital services sought a more effective approach to identifying and analyzing external cyber threats. As its digital footprint expanded, security teams faced growing challenges in separating…

Case Studies
Strengthening State-Level Threat Intelligence Operations with Criminal IP TI

December 16, 2025

How a U.S. Federal Agency Strengthened Its Cyber Defense with Criminal IP Threat Intelligence

A U.S. federal agency responsible for safeguarding pension data was looking for a more reliable way to understand and respond to external threats. As its digital footprint grew, so did the volume of alerts and the difficulty of determining which indicators required immediate…

Case Studies
How a U.S. Federal Agency Strengthened Its Cyber Defense with Criminal IP Threat Intelligence

December 15, 2025

Asahi GHD Ransomware Incident: VPN Exploitation Case and ASM-Based Prevention Strategies

In late September 2025, Asahi Group Holdings experienced a major cyber incident that disrupted order and shipping systems across its nationwide operations in Japan. The investigation later confirmed that Qilin, a Russia-based ransomware group, carried out the attack.The…

Blog
Asahi GHD Ransomware Incident: VPN Exploitation Case and ASM-Based Prevention Strategies

December 10, 2025

Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide

In December 2025, CVE-2025-55182 (React2Shell), a vulnerability in React Server Components (RSC) that enables remote code execution (RCE), was publicly disclosed. Shortly after publication, multiple security vendors reported scanning activity and suspected exploitation attempts,…

Blog
Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide

December 5, 2025

Calendar Invitation Phishing? The Reality Behind the Surge of ICS File Attacks and How to Defend Against Them

Attackers have recently begun actively exploiting ICS (calendar invitation) files instead of traditional email-based phishing. Because an ICS file is a simple text-based calendar file, many security systems classify it as low-risk. Moreover, Outlook and Google Calendar…

Blog
Calendar Invitation Phishing? The Reality Behind the Surge of ICS File Attacks and How to Defend Against Them

November 28, 2025

[Criminal IP v1.92.0] 2025-11-27 Release Note

An update to Criminal IP v1.92.0 has been released. [Criminal IP v1.92.0] Regular Maintenance and Update Release Note Maintenance Period: 2025.11.27 05:00~10:00 AM (UTC) [New Changes] Malicious IP Information Lookup API Updated (v2) The existing /v1/feature/ip/malicious-info API…

Release Note
[Criminal IP v1.92.0] 2025-11-27 Release Note

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US