Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Forgotten Secrets in the Frontend: What Hackers Extract from JavaScript Files
API keys, passwords, and AWS credentials left behind in compiled client-side JavaScript files (React, Vue) are prime targets for cyber attackers. Learn...
The Silent Assassin of Modern APIs: BOLA / IDOR Vulnerabilities and Their Impact
Why does the undisputed leader of the OWASP API Top 10, Broken Object Level Authorization (BOLA/IDOR), constantly evade WAF and DAST scanners? Defending...
ERESUS-ADV-2026-002: Server-Side Request Forgery (SSRF) via Cloud Metadata Endpoints
Analysis of widespread SSRF vulnerabilities in cloud environments (AWS, GCP, Azure) exposing critical metadata endpoints and credentials.
Critical RCE Vulnerability in Legacy Enterprise Gateway
Critical Remote Code Execution (RCE) vulnerability in a legacy enterprise API gateway allowing unauthenticated root access.
Hacking Humans: Social Engineering and the Psychology
Social engineering engagements are the most exciting and heart pumping. It doesn’t begin at the badge reader or the front desk. The access occurs when someone makes a decision.
Automated Red Teaming Scans of Agentic Workflows Using Eresus Sentinel
We are thrilled to announce the integration of Eresus Sentinel with Enterprise Agents, a groundbreaking step in securing LLM application deployments.
Strengthening AI Security with Eresus Security Defense Services
As organizations rapidly adopt generative AI, they face a new frontier of security challenges that traditional testing approaches simply cannot address.
Llama 4 Series Vulnerability Assessment: Scout vs. Maverick
Meta has launched the Llama 4 family, featuring models built on a mixture-of-experts (MoE) architecture. Here is our vulnerability assessment.
AI Risk Report: Fast-Growing Threats in AI Runtime
A comprehensive look into the fast-growing vulnerabilities affecting AI systems in runtime environments, featuring Eresus Sentinel.