Business Customer Reports
Experienced any inconvenience?
Let us know right away.
All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.
November 21, 2025
A newly identified path traversal vulnerability in Fortinet FortiWeb allows attackers to bypass authentication and ultimately gain administrator privileges on vulnerable systems. This zero-day vulnerability (CVE-2025-64446) has been actively exploited since early October 2025.…

November 18, 2025
To provide more professional and comprehensive cybersecurity insights, the Criminal IP Technical Blog has been newly integrated into the Knowledge Hub.Users can now access a wide range of Attack Surface Management (ASM) and Threat Intelligence (TI) content — including reports,…

November 13, 2025
An update and maintenance to Criminal IP v1.91.0 has been released. [Criminal IP v1.91.0] Regular Maintenance and Update Release Note Maintenance and Update Period: 2025.11.13 05:00~10:00 AM (UTC) [New Changes] Criminal IP Technical Blog Integrated into the Knowledge Hub To…
![[Criminal IP v1.91.0] 2025-11-13 Release Note](/_next/image?url=https%3A%2F%2Fi0.wp.com%2Fblog.criminalip.io%2Fwp-content%2Fuploads%2F2025%2F11%2Freleasenote_1910_eng-1.png%3Ffit%3D1096%252C620%26ssl%3D1&w=3840&q=75)
November 13, 2025
On November 1, 2025, the Australian Signals Directorate (ASD) warned that activity involving the installation of a malicious implant called BadCandy has again been observed exploiting the old but critical Cisco IOS XE Web UI vulnerability, CVE-2023-20198. Exploiting this flaw…

November 7, 2025
In early November 2025, researchers disclosed a severe unauthenticated remote code execution vulnerability in Ubiquiti’s UniFi OS ecosystem. Tracked as CVE-2025-52665, the flaw originates in the input handling of the backup orchestration endpoint (/api/ucore/backup/export).…

November 6, 2025
On October 14, 2025, Microsoft disclosed a WSUS RCE vulnerability, CVE-2025-59287 (CVSS 9.8). This vulnerability is exploitable without authentication and proof-of-concept code has been published, enabling active exploitation by attackers. Microsoft released an initial fix in…

October 31, 2025
Recently, a total of three critical security vulnerabilities were announced in Apache Tomcat. In particular, CVE-2025-55752 is a vulnerability that allows authentication bypass and remote code execution (RCE) via HTTP PUT requests, posing an immediate threat to production…

October 29, 2025
The RediShell RCE vulnerability, a critical cumulative flaw in Redis’s Lua scripting engine, was publicly disclosed in early October 2025. CVE-2025-49844 — dubbed “RediShell” by Wiz — is a use-after-free vulnerability that can escape the Lua sandbox and enable host-level remote…

October 23, 2025
Oracle headquarters generated with NanoBanana CVE-2025-61884 has been disclosed for Oracle E-Business Suite (EBS). The affected component, Oracle Configurator Runtime UI, can be exploited via an unauthenticated HTTP request prior to login. Successful exploitation may allow…

October 21, 2025
Recently, multiple reports in South Korea have exposed a series of kidnapping and detention cases in Cambodia disguised as “high-paying job offers.” Several media investigations revealed websites operated by Cambodia-based criminal organizations that facilitate illegal job…

October 16, 2025
SonicWall has confirmed that firewall configuration data for all customers using its cloud backup service was exfiltrated by threat actors.Contrary to its initial statement that “only some users were affected,” SonicWall now acknowledges that attackers stole the firewall…
![[Urgent] SonicWall Cloud Backup Breach: Full Firewall Configs Stolen; Immediate Checks Needed for 390K+ Firewalls](/_next/image?url=https%3A%2F%2Fi0.wp.com%2Fblog.criminalip.io%2Fwp-content%2Fuploads%2F2025%2F10%2Fcybersecurity_report_251015_eng.png%3Ffit%3D1096%252C620%26ssl%3D1&w=3840&q=75)
October 14, 2025
Multiple hacking groups have been repeatedly using SonicWall SSL VPN devices as an intrusion vector, and the security community continues to report cases where accounts protected by OTP-based multi-factor authentication (MFA) were nonetheless logged into successfully — raising…

Business Customer Reports
Experienced any inconvenience?
Let us know right away.
Join AI SPERA
Be part of the AI SPERA journey.