AI SPERA, the company behind the cyber threat intelligence platform Criminal IP, has announced AITEM (AI-Powered Threat Exposure Management), an expansion of its Attack Surface Management (ASM) offerings. AITEM aims to move beyond traditional asset discovery to provide a more comprehensive approach to understanding, prioritizing, and responding to security exposures. The platform is scheduled for a formal introduction at GovWare 2026 in Singapore.
According to AI SPERA CEO Byungtak Kang, the cybersecurity landscape requires a shift from merely identifying threats to enabling swift action. While organizations often have extensive visibility into potential risks, many struggle with effective prioritization and response, a challenge exacerbated by the increasing use of AI by attackers to accelerate vulnerability discovery and exploitation.
AITEM expands the scope of traditional ASM by integrating exposure data from various sources, including external assets, internal infrastructure, open-source intelligence (OSINT), dark web data, Shadow AI, and leaked information. It also incorporates emerging vulnerability data. The system is designed to connect fragmented security findings with the necessary context for investigation, prioritization, and response, moving beyond simple discovery and generic risk scores.
The platform leverages AI across four key stages of exposure management. In the "Detect" stage, AI SITEM connects emerging threats and vulnerabilities to specific products, services, and assets within an organization's environment. For "Investigate," it allows security teams to analyze assets, exposures, and vulnerabilities using natural language processing, consolidating relevant context. During "Prioritize," AITEM evaluates exposures based on an organization's defined risk criteria, considering real-world exploitability and attacker activity, rather than relying solely on vendor-provided risk scores. Finally, in the "Automate" stage, prioritized findings are converted into alerts, tickets, and workflow actions, which can be routed to appropriate teams to facilitate a rapid response.
Central to AITEM's functionality is Criminal IP's existing threat intelligence. This intelligence adds real-world context to exposure management by integrating data on open ports, exposed services, vulnerabilities, connected infrastructure, abuse history, scanner activity, threat attribution, and malicious infrastructure. This comprehensive data helps security teams understand not only what is exposed but also the surrounding activity and its significance.
Kang will further elaborate on AITEM's capabilities at GovWare 2026, delivering a session titled "From Visibility to Threat Hunting: A Case Study of AI-Driven Attack Surface Management." This presentation will explore how threat intelligence and attack surface visibility can enhance investigation speed and operational effectiveness, focusing on the transition from exposure discovery to understanding and action.
AI SPERA views AITEM as reflecting a broader industry trend towards integrated, AI-driven security operations, moving away from siloed security tools. The company emphasizes that the competitive edge in ASM will increasingly come from speed of operation, effective response, and organizational mobilization, with AI handling analytical tasks to allow human teams to focus on judgment, accountability, and prioritization.
Criminal IP, operated by AI SPERA, continuously scans the global internet to aggregate and contextualize threat signals across IPs, domains, URLs, and attack infrastructure. This includes malicious indicators, known vulnerabilities, exposed assets, and attacker behavior, with the goal of providing organizations with clear visibility into their cyber landscape and accelerating threat detection and response.






