EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Research · 107Technical Guide · 2Advisory Analysis · 5Guide · 1News · 3

Latest Posts

Cloud Security

Cloud Security: AWS IAM Flaws and One-Click Privilege Escalation

Why do 80% of organizations using Cloud Computing (AWS, Azure) suffer massive breaches strictly through misconfigured Identity and Access Management...

2026-04-02Read
Backend Security

Authentication in AI Applications: LLM Sessions and Data Privacy

Vulnerable JWT management and Context Hijacking attacks in Chatbots, RAG architectures, and AI assistants. Learn how to architect robust Authentication...

2026-04-27Read
Deep-Dive

The Simplest Bug is the Deadliest: Remote Code Execution (RCE) via Pickle in Machine Learning

Sometimes the simplest bugs are the most dangerous—especially when they’ve been hiding in plain sight. In the world of Machine Learning (ML), data ...

2026-04-01Read
Advisory

New Perseus Android Banking Malware Monitors Notes Apps for Sensitive Data

A novel Android banking malware dubbed 'Perseus' exploits accessibility services via phishing apps to monitor device screens, harvest sensitive data...

2026-04-01Read
Advisory

The Overlooked Attack Surface: Hunting 0-Days in AI Model Files

When discussing cybersecurity in Artificial Intelligence, everyone fixates on API security, prompt injections, and web vulnerabilities. Meanwhile, ...

2026-04-01Read
AI Security

Artificial Intelligence (LLM) Manipulations: Prompt Injection and RAG Poisoning

How does the shiny new ChatGPT clone your company launched fall straight into the hands of cyber attackers? An anatomical breakdown of Direct and...

2026-04-01Read
AI Security

Critical Vulnerabilities in AI Frameworks (GGUF & MXNet): The Heap Overflow Threat

Model compression standards like GGUF make running LLMs easy, but are they secure? Discover how malicious model files induce memory and heap overflows...

2026-04-01Read
Case Study

API Security in Fintech Applications: Why WAFs Are Never Enough

Today, the digital lifeblood connecting banking software, crypto wallets, open banking integrations, and payment gateways is the API (Application...

2026-04-01Read
Research

The Hidden Cyber Risks of Integrating AI in E-Commerce and Enterprise Systems

Artificial Intelligence is no longer just a futuristic concept; it’s the technology engine driving personalized shopping, automating inventory mana...

2026-04-01Read