EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Latest Posts

GuideAI SecurityOWASP LLM06 Excessive Agency

Securing Agentic AI: Where MLSecOps Meets DevSecOps

How to secure agentic AI across identity, tools, memory, retrieval, model operations, CI/CD, runtime monitoring, and incident response.

2026-08-11Read
Security Advisories

Zero-Day Analysis: Authenticated SSRF in n8n-mcp (GHSA-4ggg-h7ph-26qr)

Detailed zero-day analysis of an Authenticated SSRF vulnerability in n8n-mcp (GHSA-4ggg-h7ph-26qr) exposing internal cloud infrastructure and private API endpoints through Model Context Protocol JSON-RPC reflections.

2026-04-09Read
GuideAI SecurityNIST AI Risk Management Framework

The Evolution of AI Security: Why Secure by Design Matters

A practical introduction to secure-by-design AI: lifecycle threats, model and data provenance, prompt injection, runtime controls, and measurable governance.

2026-08-11Read
Advisory

Deep Dive: Axios Supply Chain Attack Deploys Cross-Platform RAT

A comprehensive technical analysis of the recent Axios npm supply chain attack. We break down the obfuscated plain-crypto-js dependency, the exact...

2026-04-01Read
Cloud Security

Cloud Security: AWS IAM Flaws and One-Click Privilege Escalation

Why do 80% of organizations using Cloud Computing (AWS, Azure) suffer massive breaches strictly through misconfigured Identity and Access Management...

2026-04-02Read
GuideDevSecOpsAWS IAM Best Practices

What Is AWS IAM in Cloud Security?

Learn how AWS Identity and Access Management (IAM) controls access, prevents data breaches, and serves as the ultimate perimeter in modern cloud security.

2026-08-11Read
Offensive Security

Bug Bounties for AI Systems: Harnessing Crowdsourced Security for LLMs

Discover why traditional Bug Bounty programs fail for Generative AI, and how enterprises can launch crowdsourced vulnerability disclosure programs to...

2026-04-14Read
DevSecOps

How to Build Fully Autonomous and Secure CI/CD Pipelines

Discover the DevSecOps secrets and strategies for building autonomous, highly observable, and inherently secure CI/CD pipelines for modern engineering...

2026-04-27Read
Guide

Black Box, White Box vs Grey Box Penetration Testing: Which Should You Choose?

Understand the key differences between Black Box, White Box, and Grey Box penetration testing to select the right cybersecurity approach for your business.

2026-04-06Read