Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

November 21, 2025

Fortinet FortiWeb Authentication Bypass Zero-Day (CVE-2025-64446): Exposure Analysis & Mitigation Guide

A newly identified path traversal vulnerability in Fortinet FortiWeb allows attackers to bypass authentication and ultimately gain administrator privileges on vulnerable systems. This zero-day vulnerability (CVE-2025-64446) has been actively exploited since early October 2025.…

Blog
Fortinet FortiWeb Authentication Bypass Zero-Day (CVE-2025-64446): Exposure Analysis & Mitigation Guide

November 18, 2025

Criminal IP Technical Blog Integrated into the Knowledge Hub

To provide more professional and comprehensive cybersecurity insights, the Criminal IP Technical Blog has been newly integrated into the Knowledge Hub.Users can now access a wide range of Attack Surface Management (ASM) and Threat Intelligence (TI) content — including reports,…

Notice
Criminal IP Technical Blog Integrated into the Knowledge Hub

November 13, 2025

[Criminal IP v1.91.0] 2025-11-13 Release Note

An update and maintenance to Criminal IP v1.91.0 has been released. [Criminal IP v1.91.0] Regular Maintenance and Update Release Note Maintenance and Update Period: 2025.11.13 05:00~10:00 AM (UTC) [New Changes] Criminal IP Technical Blog Integrated into the Knowledge Hub To…

Release Note
[Criminal IP v1.91.0] 2025-11-13 Release Note

November 13, 2025

BadCandy Threat — Cisco IOS XE Web UI Vulnerability (CVE-2023-20198): Status and Response Guide

On November 1, 2025, the Australian Signals Directorate (ASD) warned that activity involving the installation of a malicious implant called BadCandy has again been observed exploiting the old but critical Cisco IOS XE Web UI vulnerability, CVE-2023-20198. Exploiting this flaw…

Blog
BadCandy Threat — Cisco IOS XE Web UI Vulnerability (CVE-2023-20198): Status and Response Guide

November 7, 2025

UniFi OS RCE Alert: Unauthenticated Backup API Enables Remote Code Execution (CVE-2025-52665)

In early November 2025, researchers disclosed a severe unauthenticated remote code execution vulnerability in Ubiquiti’s UniFi OS ecosystem. Tracked as CVE-2025-52665, the flaw originates in the input handling of the backup orchestration endpoint (/api/ucore/backup/export).…

Blog
UniFi OS RCE Alert: Unauthenticated Backup API Enables Remote Code Execution (CVE-2025-52665)

November 6, 2025

WSUS RCE (CVE-2025-59287): 4,616 Exposed Instances Remain Unpatched

On October 14, 2025, Microsoft disclosed a WSUS RCE vulnerability, CVE-2025-59287 (CVSS 9.8). This vulnerability is exploitable without authentication and proof-of-concept code has been published, enabling active exploitation by attackers. Microsoft released an initial fix in…

Blog
WSUS RCE (CVE-2025-59287): 4,616 Exposed Instances Remain Unpatched

October 31, 2025

Three Critical Apache Tomcat Vulnerabilities — Over 540K Exposed Instances Need Immediate Inspection (CVE-2025-55752, CVE-2025-55754, CVE-2025-61795)

Recently, a total of three critical security vulnerabilities were announced in Apache Tomcat. In particular, CVE-2025-55752 is a vulnerability that allows authentication bypass and remote code execution (RCE) via HTTP PUT requests, posing an immediate threat to production…

Blog
Three Critical Apache Tomcat Vulnerabilities — Over 540K Exposed Instances Need Immediate Inspection (CVE-2025-55752, CVE-2025-55754, CVE-2025-61795)

October 29, 2025

RediShell RCE Alert: Over 8,000 Redis Instances — Immediate Update Recommended

The RediShell RCE vulnerability, a critical cumulative flaw in Redis’s Lua scripting engine, was publicly disclosed in early October 2025. CVE-2025-49844 — dubbed “RediShell” by Wiz — is a use-after-free vulnerability that can escape the Lua sandbox and enable host-level remote…

Blog
RediShell RCE Alert: Over 8,000 Redis Instances — Immediate Update Recommended

October 23, 2025

Oracle EBS CVE-2025-61884: Runtime UI Exposes Configuration Data

Oracle headquarters generated with NanoBanana CVE-2025-61884 has been disclosed for Oracle E-Business Suite (EBS). The affected component, Oracle Configurator Runtime UI, can be exploited via an unauthenticated HTTP request prior to login. Successful exploitation may allow…

Blog
Oracle EBS CVE-2025-61884: Runtime UI Exposes Configuration Data

October 21, 2025

Tracing the Hidden Servers of “Hades Cafe”: Site Exploited as a Criminal Channel in Cambodia

Recently, multiple reports in South Korea have exposed a series of kidnapping and detention cases in Cambodia disguised as “high-paying job offers.” Several media investigations revealed websites operated by Cambodia-based criminal organizations that facilitate illegal job…

Blog
Tracing the Hidden Servers of “Hades Cafe”: Site Exploited as a Criminal Channel in Cambodia

October 16, 2025

[Urgent] SonicWall Cloud Backup Breach: Full Firewall Configs Stolen; Immediate Checks Needed for 390K+ Firewalls

SonicWall has confirmed that firewall configuration data for all customers using its cloud backup service was exfiltrated by threat actors.Contrary to its initial statement that “only some users were affected,” SonicWall now acknowledges that attackers stole the firewall…

Blog
[Urgent] SonicWall Cloud Backup Breach: Full Firewall Configs Stolen; Immediate Checks Needed for 390K+ Firewalls

October 14, 2025

Urgent: 3,894 SonicWall SSL VPNs Vulnerable to OVERSTEP and MFA Bypass

Multiple hacking groups have been repeatedly using SonicWall SSL VPN devices as an intrusion vector, and the security community continues to report cases where accounts protected by OTP-based multi-factor authentication (MFA) were nonetheless logged into successfully — raising…

Blog
Urgent: 3,894 SonicWall SSL VPNs Vulnerable to OVERSTEP and MFA Bypass

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US