EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Latest Posts

ResearchEnterprise SecurityNVD CVE-2026-35616

Technical Analysis of Fortinet CVE-2026-35616: Actively Exploited API Vulnerability

FortiClient EMS CVE-2026-35616 analysis: affected versions, improper access control, active-exploitation response, patch validation, isolation, logging, and credential rotation.

2026-08-11Read
GuideFintech SecurityOWASP API Security Top 10

API Security in Fintech Applications: Why WAFs Are Never Enough

Today, the digital lifeblood connecting banking software, crypto wallets, open banking integrations, and payment gateways is the API (Application...

2026-08-11Read
DevSecOps

How to Build a Production-Grade gRPC Service in Go: A Step-by-Step Guide

Learn how to write a gRPC service in Go from scratch: Protobuf definitions, Unary/Streaming RPCs, PostgreSQL with GORM, Auth Interceptors, Rate...

2026-04-07Read
Security Advisories

Critical Authentication Bypass via JWT Signature Verification Disabled in yargi-mcp

Critical authentication bypass vulnerability (CVE pending) in yargi-mcp OAuth endpoint allowing full system access due to disabled JWT signature...

2026-04-04Read
GuideAI SecurityOWASP Top 10 for LLM Applications

The Hidden Cyber Risks of Integrating AI in E-Commerce and Enterprise Systems

E-commerce AI security risks: prompt injection, RAG data leakage, tool abuse, refund manipulation, session security, and cost controls for shopping assistants.

2026-08-11Read
Methodology

What is DevSecOps? Automating Security with the 'Shift-Left' Approach

Understand the core principles of DevSecOps and Shift-Left security. Learn how to automate security checks directly into your software development...

2026-04-05Read
GuideAI SecurityNIST AI Risk Management Framework

Tools and Technologies for Secure-by-Design AI Systems

A practical map of the scanners, provenance controls, evaluation suites, runtime protections, and observability needed to secure AI systems from build to production.

2026-08-11Read
Threat Intelligence

The Rise of Corporate Deepfakes and Vishing: AI-Powered Social Engineering

Discover how threat actors use Deepfakes and Voice Phishing (Vishing) for multi-million dollar corporate heists, and how to defend your enterprise.

2026-04-14Read
Red Teaming

The Rise of the Certified AI Security Professional (CAISP): Reimagining Enterprise Pentesting

Traditional penetration testing cannot protect Machine Learning models. Learn why the Certified AI Security Professional (CAISP) is crucial for securing...

2026-04-14Read