Criminal IP Pushes Attack Surface Management Past Pure Visibility
Criminal IP, the cyber threat intelligence platform operated by South Korean security firm AI SPERA, has introduced AITEM (AI-Powered Threat Exposure Management), a framework the company is positioning as the next evolution of Attack Surface Management (ASM). The announcement, carried by BleepingComputer and syndicated via GlobeNewswire on October 10, 2026, argues that traditional ASM tools — which focus on discovering internet-facing assets such as servers, domains, IP addresses, and admin panels — no longer go far enough, because visibility without a path to investigation, prioritization, and response leaves security teams unable to keep pace with attackers.
Product Details
| Attribute | Value |
|---|---|
| Vendor | Criminal IP (operated by AI SPERA) |
| Framework name | AITEM — AI-Powered Threat Exposure Management |
| Category | Attack Surface Management / Threat Exposure Management |
| Core capability | AI-driven pipeline connecting exposure discovery to investigation, risk prioritization, and automated response |
| Framework debut | First conceptually introduced at Infosecurity Europe 2026 (June 2026) |
| Current announcement | Formal introduction tied to GovWare 2026, Singapore (October 13–15, 2026) |
| Executive | Byungtak Kang, CEO, AI SPERA |
| Pricing / availability | Not disclosed in the announcement |
What Criminal IP Is Announcing
AITEM is not, by Criminal IP's own framing, a shipped product name so much as an architectural vision for where its existing Criminal IP ASM offering is headed — and a label for a security-operations problem the company says the market has not solved. Traditional ASM tools excel at inventorying what an organization exposes to the internet, but they typically stop there, handing analysts a list of assets and generic vendor risk scores with little context on which exposures actually matter. Criminal IP argues that gap has widened as AI lowers the barrier for attackers: automated scanning, published proof-of-concept exploit code, and AI-assisted vulnerability discovery now let threat actors identify and weaponize exposed assets faster than most defenders can triage them.
To close that gap, AITEM applies AI across four stages. Detect connects newly disclosed threats and vulnerabilities to the specific products, services, and assets that actually exist in an organization's environment, rather than surfacing generic CVE feeds. Investigate lets security teams query assets, exposures, and findings using natural language, pulling relevant context — open ports, exposed services, connected infrastructure, abuse history, scanner activity, and threat attribution — into one place instead of forcing analysts to pivot across separate tools. Prioritize scores exposure against organization-defined risk criteria combined with real-world exploitability and observed attacker activity, moving past the generic severity ratings that dominate most vendor risk scores. Automate then converts prioritized findings into alerts, tickets, and workflow actions routed to the appropriate team, aiming to shorten the path from detection to remediation.
Beyond external asset inventory, Criminal IP says AITEM's scope extends to open-source intelligence, dark web data, internal infrastructure, leaked-data monitoring, and Shadow AI detection — flagging unsanctioned AI tool usage (via firewall log analysis and domain intelligence) as a growing, often-overlooked piece of an organization's attack surface. The framework is built on top of Criminal IP's existing threat intelligence corpus, which continuously scans the internet to aggregate signals across IPs, domains, URLs, and attack infrastructure.
AI SPERA CEO Byungtak Kang is scheduled to present the framework's practical application at GovWare 2026 in Singapore (part of Singapore International Cyber Week) in a session titled "From Visibility to Threat Hunting: A Case Study of AI-Driven Attack Surface Management," positioning the company's message around moving security teams from passive visibility to active threat hunting. The announcement does not disclose pricing, a general-availability date, or named customers for AITEM-branded capabilities.
Why This Matters
- ASM is consolidating with threat exposure management. Criminal IP's pitch reflects a broader market shift — vendors across the ASM space are folding asset discovery into wider "exposure management" platforms that also pull in dark web monitoring, OSINT, and vulnerability intelligence, rather than selling discovery as a standalone product.
- Alert fatigue, not visibility, is the stated target. The framing — detect, investigate, prioritize, automate — is a direct response to security teams drowning in undifferentiated findings; the value proposition hinges on cutting the noise between "we found something exposed" and "here's what to do about it."
- Shadow AI is becoming a named attack-surface category. Treating unsanctioned employee use of AI tools as part of the discoverable attack surface, alongside traditional assets, signals that ASM vendors expect enterprises to start budgeting for AI-usage visibility specifically.
- This is a vision announcement, not a product launch. AITEM is explicitly described as a framework guiding where Criminal IP's ASM product is being built toward, not a newly shipped, independently priced offering — buyers evaluating it should ask for concrete feature availability and timelines rather than assuming it is generally available today.
- Security teams evaluating ASM vendors should weigh integration depth over marketing framing. The capabilities Criminal IP describes — natural-language investigation, exploitability-aware prioritization, automated ticketing — are increasingly table stakes across the ASM/exposure-management category; buyers should press any vendor (including Criminal IP) for independent validation of detection coverage and false-positive rates rather than relying on announcement copy alone.