Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Technical Analysis of Fortinet CVE-2026-35616: Actively Exploited API Vulnerability
FortiClient EMS CVE-2026-35616 analysis: affected versions, improper access control, active-exploitation response, patch validation, isolation, logging, and credential rotation.
API Security in Fintech Applications: Why WAFs Are Never Enough
Today, the digital lifeblood connecting banking software, crypto wallets, open banking integrations, and payment gateways is the API (Application...
How to Build a Production-Grade gRPC Service in Go: A Step-by-Step Guide
Learn how to write a gRPC service in Go from scratch: Protobuf definitions, Unary/Streaming RPCs, PostgreSQL with GORM, Auth Interceptors, Rate...
Critical Authentication Bypass via JWT Signature Verification Disabled in yargi-mcp
Critical authentication bypass vulnerability (CVE pending) in yargi-mcp OAuth endpoint allowing full system access due to disabled JWT signature...
The Hidden Cyber Risks of Integrating AI in E-Commerce and Enterprise Systems
E-commerce AI security risks: prompt injection, RAG data leakage, tool abuse, refund manipulation, session security, and cost controls for shopping assistants.
What is DevSecOps? Automating Security with the 'Shift-Left' Approach
Understand the core principles of DevSecOps and Shift-Left security. Learn how to automate security checks directly into your software development...
Tools and Technologies for Secure-by-Design AI Systems
A practical map of the scanners, provenance controls, evaluation suites, runtime protections, and observability needed to secure AI systems from build to production.
The Rise of Corporate Deepfakes and Vishing: AI-Powered Social Engineering
Discover how threat actors use Deepfakes and Voice Phishing (Vishing) for multi-million dollar corporate heists, and how to defend your enterprise.
The Rise of the Certified AI Security Professional (CAISP): Reimagining Enterprise Pentesting
Traditional penetration testing cannot protect Machine Learning models. Learn why the Certified AI Security Professional (CAISP) is crucial for securing...