Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Denial of Wallet in LLM Applications: Detecting Resource-Draining Prompts
How attackers turn long, recursive, or tool-heavy prompts into token, GPU, and API cost spikes—and how to detect and contain the risk.
The Art of LLM Jailbreaking: Demystifying Offensive Prompt Engineering
How do Red Teamers bypass the safety filters of Large Language Models? Dive deep into the manipulative art of LLM Jailbreaking, DAN prompts, and...
Cybersecurity for SMBs: A 5-Step Defense Strategy for Growing Teams
How can Small and Medium-Sized Businesses (SMBs) protect themselves from ransomware and data breaches on a tight budget? 5 actionable security steps.
The April 2026 MCP RCE Wave
Why MCP security depends on architecture, identity, tool isolation, and registration control more than a single CVE.
How Often Should You Penetration Test? (Scrapping the Annual Audit Myth)
How frequently does your company need a penetration test? Why the traditional 'once-a-year' pentest is actively putting modern software infrastructure...
Critical Vulnerabilities in AI Frameworks (GGUF & MXNet): The Heap Overflow Threat
Model compression standards like GGUF make running LLMs easy, but are they secure? Discover how malicious model files induce memory and heap overflows...
Legacy SAST vs. AI-Powered Code Analysis: The Future of AppSec
SAST vs AI code analysis: where deterministic rules, data-flow analysis, LLM assistance, verification, false positives, and DevSecOps release gates fit together.
The Legal Mandate of Penetration Testing in GDPR and Data Privacy Compliance
Is penetration testing legally mandatory under GDPR or similar privacy laws? Discover what regulators actually demand to avoid catastrophic compliance...
AI Compliance Crisis: Navigating GDPR/KVKK in RAG Architectures
Discover the severe data privacy risks of Enterprise RAG models. Learn how to align Large Language Models with GDPR mandates like the 'Right to be...