"Seeing a threat and responding to it are completely different challenges," said Byungtak Kang, CEO of AI SPERA. That line frames Criminal IP's new pitch for AITEM, an AI-powered expansion of attack surface management the company is presenting as it participates in GovWare 2026 in Singapore.
Byungtak Kang: shifting ASM from visibility to action
AI SPERA's CEO lays out a simple contention: discovery of internet-facing assets alone no longer meets defenders' needs. "Building a safer cyber world requires a shift from visibility to action," Kang said, arguing that organisations have unprecedented visibility but still struggle to prioritise and act on the risks that visibility reveals. He warns that as AI lowers the bar for attackers, defenders' critical gap is not discovery but speed of response.
AITEM's four-stage model: Detect, Investigate, Prioritize, Automate
Criminal IP introduces AITEM — AI-Powered Threat Exposure Management — as what it calls the next evolution of Attack Surface Management (ASM). AITEM applies AI across four explicit stages of exposure management:
- Detect — connect emerging threats and vulnerabilities to products, services, and assets that actually exist within an organisation's environment.
- Investigate — allow security teams to investigate assets, exposures, vulnerabilities, and security findings using natural language while bringing relevant context together in one place.
- Prioritize — evaluate exposure using organisation-defined risk criteria together with real-world exploitability and attacker activity, instead of relying only on generic vendor risk scores.
- Automate — turn prioritized findings into alerts, tickets, and workflow actions that can be routed to the appropriate teams to move critical exposures toward response.
The model is presented as a movement from mere inventory toward a lifecycle that closes the loop between detection and response.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildThreat intelligence at the core of Criminal IP's approach
Criminal IP positions threat intelligence as the differentiator for AITEM. The platform aggregates signals from continuous global internet scanning and layers them with context: open ports, exposed services, vulnerabilities, connected infrastructure, abuse history, scanner activity, threat attribution, and malicious infrastructure. The company says that combining these signals helps teams understand not just what is exposed, but "what is happening around that exposure and why it matters."
GovWare 2026: a case study on AI-driven attack surface management
At GovWare 2026, CEO Byungtak Kang will deliver a session titled "From Visibility to Threat Hunting: A Case Study of AI-Driven Attack Surface Management." According to Criminal IP, the presentation will draw from real-world examples to explore how threat intelligence and attack surface visibility can support faster investigation and more effective security operations, and to examine the shift from discovering exposure to understanding and acting on it.
The company ties AITEM's launch into a broader industry movement it sees emerging in 2026. At RSAC 2026, Criminal IP notes, themes such as agentic AI, AI SOC, and Shadow AI became prominent, and leading vendors moved toward more integrated, AI-driven security operations. In that context, Kang says, "The competition in ASM is no longer about who finds the most assets. It will be about who can operate faster, respond more effectively, and mobilize the organisation."
What this means for security teams, procurement leaders, and threat actors
- Security teams and technologists — AITEM is pitched to let analysts use natural language investigation and consolidated context to reduce noise and focus on exposures with real-world exploitability. The platform's built-in prioritisation and automation steps are intended to shift effort from repetitive analysis to human judgment, accountability, and prioritisation.
- Procurement leaders and affected enterprises — Criminal IP is proposing a move away from generic vendor risk scores toward organisation-defined criteria combined with attacker activity. Procurement and operations leaders will be asked to evaluate tools on their ability to connect discovery to response workflows and to integrate threat intelligence across external and internal signals.
- Adversaries and threat actors — The company explicitly warns that automated scanning, published proof-of-concept exploit code, and AI-assisted vulnerability discovery accelerate attackers' targeting, increasing the importance of defenders' response speed and contextual prioritisation.
Criminal IP frames AITEM as an answer to a narrow but urgent problem: visibility without action leaves organisations exposed. The product roadmap centres threat intelligence and AI as enablers to triage, contextualise, and automate response, while preserving human roles in judgment and escalation. Whether that approach shortens the gap from detection to response in practice will be tested in the field and onstage at GovWare 2026.
Original story: https://www.bleepingcomputer.com/news/security/criminal-ip-introduces-aitem-as-the-next-evolution-of-attack-surface-management/




