EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Latest Posts

GuideAI SecurityOWASP Top 10 for LLM Applications

Denial of Wallet in LLM Applications: Detecting Resource-Draining Prompts

How attackers turn long, recursive, or tool-heavy prompts into token, GPU, and API cost spikes—and how to detect and contain the risk.

2026-08-11Read
Red Teaming

The Art of LLM Jailbreaking: Demystifying Offensive Prompt Engineering

How do Red Teamers bypass the safety filters of Large Language Models? Dive deep into the manipulative art of LLM Jailbreaking, DAN prompts, and...

2026-04-14Read
Guide

Cybersecurity for SMBs: A 5-Step Defense Strategy for Growing Teams

How can Small and Medium-Sized Businesses (SMBs) protect themselves from ransomware and data breaches on a tight budget? 5 actionable security steps.

2026-04-06Read
NewsAI Infrastructure

The April 2026 MCP RCE Wave

Why MCP security depends on architecture, identity, tool isolation, and registration control more than a single CVE.

2026-04-22Read
GuideMethodologyNIST Cybersecurity Framework 2.0

How Often Should You Penetration Test? (Scrapping the Annual Audit Myth)

How frequently does your company need a penetration test? Why the traditional 'once-a-year' pentest is actively putting modern software infrastructure...

2026-08-11Read
AI Security

Critical Vulnerabilities in AI Frameworks (GGUF & MXNet): The Heap Overflow Threat

Model compression standards like GGUF make running LLMs easy, but are they secure? Discover how malicious model files induce memory and heap overflows...

2026-04-01Read
GuideDevSecOpsNIST Secure Software Development Framework

Legacy SAST vs. AI-Powered Code Analysis: The Future of AppSec

SAST vs AI code analysis: where deterministic rules, data-flow analysis, LLM assistance, verification, false positives, and DevSecOps release gates fit together.

2026-08-11Read
Guide

The Legal Mandate of Penetration Testing in GDPR and Data Privacy Compliance

Is penetration testing legally mandatory under GDPR or similar privacy laws? Discover what regulators actually demand to avoid catastrophic compliance...

2026-04-05Read
AI Security

AI Compliance Crisis: Navigating GDPR/KVKK in RAG Architectures

Discover the severe data privacy risks of Enterprise RAG models. Learn how to align Large Language Models with GDPR mandates like the 'Right to be...

2026-04-14Read