EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Research · 107Technical Guide · 2Advisory Analysis · 5Guide · 1News · 3

Latest Posts

Advisory

Deep Dive: Axios Supply Chain Attack Deploys Cross-Platform RAT

A comprehensive technical analysis of the recent Axios npm supply chain attack. We break down the obfuscated plain-crypto-js dependency, the exact...

2026-04-01Read
DevSecOps

How to Build Fully Autonomous and Secure CI/CD Pipelines

Discover the DevSecOps secrets and strategies for building autonomous, highly observable, and inherently secure CI/CD pipelines for modern engineering...

2026-04-27Read
Methodology

Automated Vulnerability Scanning vs. Manual Penetration Testing: Which Do You Need?

When deciding on cybersecurity investments, IT teams and boards often have the same debate: 'Instead of spending thousands of dollars on manual p...

2026-04-27Read
DevSecOps

GitOps Security in ArgoCD Architecture: How to Protect Your K8s Clusters

ArgoCD and GitOps architectures rely on a Single Source of Truth. Learn how attackers exploit supply chain vulnerabilities and the detailed guidelines...

2026-04-27Read
Advisory

Apple Warns: Older iPhones Vulnerable to Coruna & DarkSword Exploit Kits

Apple has issued a critical warning regarding unpatched, older iOS devices being actively targeted by Coruna and DarkSword exploit kits through drive-by...

2026-04-27Read
Red Team

Setting up an Active Directory Pentest Lab in Seconds with AI (Cursor)

For cyber security experts and internal Red Teams: How to set up a fully comprehensive, vulnerable Active Directory test environment with a single click...

2026-04-27Read
AppSec

The Limitations of WAF: Why Firewalls Alone Can't Prevent Hacks

Your company relies on a pricey WAF (Web Application Firewall) to block threats. But why is a WAF completely blind to logical flaws? Discover how manual...

2026-03-31Read
Cloud Security

Kubernetes (K8s) Penetration Testing Playbook: The Black Box Approach

How do cyber attackers breach your Kubernetes (K8s) clusters from the outside without prior knowledge? An in-depth look into Black Box Kubernetes...

2026-03-31Read
Research

The Overlooked Threat in AI Models: Keras & Pickle File Vulnerabilities

While everyone focuses on prompt injection, the biggest threat lies in the background: AI model files (Keras, Pickle) executing malicious code. Learn...

2026-03-31Read