Criminal IP Threat Intelligence Reports

Criminal IP The latest news and developments for Cyber Threat Intelligence Reports.

CIP Blog Criminal IP Blog · The latest news and developments for Criminal IP. Cyber Threat Intelligence Reports.

  • Internet-Exposed Cisco IOS Management Interfaces: Why Legacy Network Devices Remain Attractive Targets
    by Criminal IP on July 16, 2026 at 5:36 am

    Recently, the CISA and the NSA warned that Russian state-sponsored threat actors continue to target vulnerable or misconfigured network routers. In their joint cybersecurity advisory, they specifically highlighted CVE-2008-4128, a long-standing vulnerability in the Cisco IOS HTTP management feature, emphasizing that legacy network devices that are no longer supported or have not received security updates remain viable targets for real-world attacks.  Routers and […] The post Internet-Exposed Cisco IOS Management Interfaces: Why Legacy Network Devices Remain Attractive Targets appeared first on CIP Blog.

  • Internet-Exposed Swagger UI: What API Documentation Reveals to Attackers
    by Criminal IP on July 15, 2026 at 12:00 am

    As generative AI, SaaS platforms, mobile applications, and cloud services continue to expand, core business functions are becoming increasingly API-driven. Behind the interfaces of modern web applications, APIs handle a wide range of functions, including user authentication, payment processing, data retrieval, file uploads, and administrative operations. Swagger UI and OpenAPI documentation are widely used to […] The post Internet-Exposed Swagger UI: What API Documentation Reveals to Attackers appeared first on CIP Blog.

  • Criminal IP Threat Intelligence Integration with the Torq AI SOC Platform
    by Criminal IP on July 10, 2026 at 8:00 am

    Criminal IP has partnered with Torq, an AI SOC platform company for autonomous security operations, and has integrated with the Torq AI SOC Platform. Torq is an agentic security operations platform that helps security teams automatically triage, investigate, and respond to large volumes of security events. Through this integration, the Torq AI SOC Platform can […] The post Criminal IP Threat Intelligence Integration with the Torq AI SOC Platform appeared first on CIP Blog.

  • Tracking Exposed AI API Tokens: How OpenAI and Anthropic Keys Surface Publicly
    by Criminal IP on July 8, 2026 at 12:00 am

    As organizations increasingly integrate artificial intelligence into their services, API tokens issued by providers such as OpenAI and Anthropic have become critical credentials for application operations. However, API tokens intended exclusively for server-side use are sometimes exposed through web pages, environment files, debugging interfaces, and client-side application code. In June 2026, Criminal IP Asset Search was […] The post Tracking Exposed AI API Tokens: How OpenAI and Anthropic Keys Surface Publicly appeared first on CIP Blog.

  • Discovering Internet-Exposed AI Gateways: How Can New AI Attack Surfaces Be Identified?
    by Criminal IP on July 6, 2026 at 12:00 am

    As generative AI services rapidly expand, the number of AI Gateways that connect and manage various LLMs, including Claude, OpenAI, and Gemini, within a single environment is also increasing. AI Gateways may be deployed by enterprises to manage multiple AI APIs in an integrated manner. They may also operate as API Relay or Proxy Servers […] The post Discovering Internet-Exposed AI Gateways: How Can New AI Attack Surfaces Be Identified? appeared first on CIP Blog.

  • Tracking the Storm-2561 Fake VPN Campaign: How Malicious Domains Are Reused After an Attack Ends
    by Criminal IP on July 1, 2026 at 2:06 am

    In March 2026, Microsoft disclosed the Storm-2561 campaign, which used SEO poisoning to distribute fake enterprise VPN clients. The attackers exposed domains impersonating VPN products from legitimate security companies, including Fortinet, Ivanti, Cisco, Sophos, and SonicWall, at the top of search results. When users downloaded and executed VPN installation files from these websites, an interface similar to […] The post Tracking the Storm-2561 Fake VPN Campaign: How Malicious Domains Are Reused After an Attack Ends appeared first on CIP Blog.

  • Criminal IP Threat Intelligence Integration with OpenCTI
    by Criminal IP on June 30, 2026 at 12:00 am

    Criminal IP is now integrated with OpenCTI by Filigran, an open-source cyber threat intelligence platform. OpenCTI uses a graph-based model to structure, store, and analyze cyber threat data. It connects indicators, vulnerabilities, threat actors, attack campaigns, and other threat information within a unified knowledge base, supporting investigation, collaboration, and intelligence sharing. Through this integration, IP […] The post Criminal IP Threat Intelligence Integration with OpenCTI appeared first on CIP Blog.

  • Managing the External Attack Surface with ASM and DNS Records
    by Criminal IP on June 25, 2026 at 3:57 am

    DNS Record-Based External Attack Surface Management The IT assets maintained in an organization’s internal inventory may not fully match the assets that are actually exposed to the internet. Cloud instances, abandoned subdomains, systems created by external partners, shared hosting environments, and misconfigured DNS records can all remain part of the external attack surface without the […] The post Managing the External Attack Surface with ASM and DNS Records appeared first on CIP Blog.

  • FortiBleed Campaign Analysis: Why Internet-Exposed FortiGate Devices Become the Starting Point for Credential Theft
    by Criminal IP on June 23, 2026 at 6:25 am

    In June 2026, the FortiBleed campaign came to light after a dataset containing a large volume of login information associated with Fortinet FortiGate and SSL VPN devices was exposed publicly. The leaked data reportedly included credentials that could be used to access actual devices, including usernames, email addresses, and plaintext passwords. FortiGate is a security […] The post FortiBleed Campaign Analysis: Why Internet-Exposed FortiGate Devices Become the Starting Point for Credential Theft appeared first on CIP Blog.

  • CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Vulnerability and Externally Exposed VPN Assets
    by Criminal IP on June 22, 2026 at 3:31 am

    On May 13, 2026, Palo Alto Networks disclosed CVE-2026-0257, an authentication bypass vulnerability affecting PAN-OS GlobalProtect Portal and Gateway components. Just four days after disclosure, active exploitation attempts were already being observed in the wild. Following the public release of a proof-of-concept (PoC) exploit on May 29, attacks rapidly escalated. On the same day, the vulnerability was […] The post CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Vulnerability and Externally Exposed VPN Assets appeared first on CIP Blog.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.