Criminal IP introduces AITEM, an AI-driven evolution of attack surface management (ASM).
AITEM ties exposure findings to investigation, prioritization and automated actions, not just asset lists.
CEO Byungtak Kang says the goal is faster, real-time defense rather than static visibility.
Quick read · 1 min
Criminal IP, via AI SPERA, is launching AITEM, an AI-driven upgrade to attack surface management. It combines asset exposure data with threat context and automated actions to help security teams move from discovery to response faster. The approach covers external assets, OSINT, dark web signals, and internal infrastructure, aiming to reduce risk by prioritizing real threats and automating common responses. GovWare 2026 will showcase a case study illustrating how a real-world security team used AI-powered exposure management to speed up investigations and responses.
For everyday users, this could mean fewer exposed services in the wild and quicker fixes when problems are found, which translates to less chance of disruptions from cyberattacks. GovWare 2026 will showcase a case study illustrating how a real-world security team used AI-powered exposure management to speed up investigations and responses.
Detect: link threats to actual assets
Investigate: understand exposures with context
Automate: turn findings into actions
Criminal IP, a threat intelligence platform operated by AI SPERA, is presenting a new take on attack surface management with AITEM. Marketed as the next step beyond traditional ASM, AITEM blends AI-powered exposure discovery with context and automated workflows to help security teams move from spotting problems to actively solving them. The company will showcase the approach at GovWare 2026 in Singapore, including a case study on turning visibility into proactive threat hunting.
Traditional ASM focuses on cataloging internet-exposed assets. AITEM broadens that focus by combining external assets, OSINT, dark web data, internal infrastructure, and emerging risks like Shadow AI and leaked data. The aim is to give defenders a clearer, more actionable picture of what matters, not just what is exposed.
At the core of AITEM is AI that helps security teams prioritize risks and automate responses. As AI lowers the barrier for attackers to locate exposed assets, defenders need faster, smarter tools to respond. AITEM connects discovery results with investigation context, priorities based on real-world exploitability, and automated workflow actions that can trigger alerts or tickets to the right teams.
Criminal IP frames AITEM as more than a new tool; it’s a shift in how teams manage exposure. The four stages it covers are Detect, Investigate, Prioritize, and Automate. In Detect, it links emerging threats to actual assets in an organization. In Investigate, it uses natural language to help security staff understand exposures in one place. In Prioritize, it weighs risk against real attacker activity, not just generic scores. In Automate, it translates top risks into actionable steps for teams.
01
What AITEM is and why it matters
AITEM is pitched as an evolution of ASM that connects exposure discovery with threat context and response, rather than stopping at asset lists or risk scores. It leverages Criminal IP’s threat intelligence to place exposures in a broader picture, showing what’s connected, what’s vulnerable, and how attackers might exploit it in real time.
02
Where it fits among modern security tools
The security field has been moving toward integrated, AI-powered operations. AITEM mirrors discussions about moving from standalone tools to systems that combine data, context, and automated actions quickly. Conversations at events like RSAC 2026 highlight the demand for tools that help teams act fast rather than just observe risks.
03
What this means for everyday organizations
For most readers, you’ll likely never see AITEM by name in your daily tools. What matters is the potential impact: faster identification of real, exploitable exposures and quicker, more precise responses. That could mean shorter times that a misconfigured service or vulnerable asset stays exposed, reducing breach risk and possibly lowering incident-response costs.
04
What happens next
GovWare 2026 will feature a case study on how AI-powered exposure management supports faster investigation and more effective security operations. If AITEM gains traction, expect more vendors to blend exposure discovery with context and automated workflows rather than relying on discovery alone.
AITEM stands for AI-Powered Threat Exposure Management, an approach to attack surface management that links exposure discovery with investigation, prioritization and automated response.
When is it being shown?
It will be discussed at GovWare 2026 in Singapore, including a session by AI SPERA’s CEO.
Why should security teams care?
Because attackers can find exposed assets faster than ever, tools that speed up detection-to-response help reduce risk and downtime.
A Ukrainian drone strike damaged a huge Yandex data center in Kaluga, knocking several modules offline and signaling renewed pressure on Russia’s cloud backbone.
4 min read
We use cookies to understand how readers use Talk With Tech, so we can make it better. Is that OK? Privacy policy
The Daily Brief
Today's biggest tech stories, in 5 minutes
Every morning, the news that matters from AI, phones, apps and the people shaping tech. Explained in plain English. Free.
One email a day. No spam, unsubscribe anytime. Privacy policy