Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Securing Agentic AI: Where MLSecOps Meets DevSecOps
How to secure agentic AI across identity, tools, memory, retrieval, model operations, CI/CD, runtime monitoring, and incident response.
Zero-Day Analysis: Authenticated SSRF in n8n-mcp (GHSA-4ggg-h7ph-26qr)
Detailed zero-day analysis of an Authenticated SSRF vulnerability in n8n-mcp (GHSA-4ggg-h7ph-26qr) exposing internal cloud infrastructure and private API endpoints through Model Context Protocol JSON-RPC reflections.
The Evolution of AI Security: Why Secure by Design Matters
A practical introduction to secure-by-design AI: lifecycle threats, model and data provenance, prompt injection, runtime controls, and measurable governance.
Deep Dive: Axios Supply Chain Attack Deploys Cross-Platform RAT
A comprehensive technical analysis of the recent Axios npm supply chain attack. We break down the obfuscated plain-crypto-js dependency, the exact...
Cloud Security: AWS IAM Flaws and One-Click Privilege Escalation
Why do 80% of organizations using Cloud Computing (AWS, Azure) suffer massive breaches strictly through misconfigured Identity and Access Management...
What Is AWS IAM in Cloud Security?
Learn how AWS Identity and Access Management (IAM) controls access, prevents data breaches, and serves as the ultimate perimeter in modern cloud security.
Bug Bounties for AI Systems: Harnessing Crowdsourced Security for LLMs
Discover why traditional Bug Bounty programs fail for Generative AI, and how enterprises can launch crowdsourced vulnerability disclosure programs to...
How to Build Fully Autonomous and Secure CI/CD Pipelines
Discover the DevSecOps secrets and strategies for building autonomous, highly observable, and inherently secure CI/CD pipelines for modern engineering...
Black Box, White Box vs Grey Box Penetration Testing: Which Should You Choose?
Understand the key differences between Black Box, White Box, and Grey Box penetration testing to select the right cybersecurity approach for your business.