Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Automated Vulnerability Scanning vs. Manual Penetration Testing: Which Do You Need?
When deciding on cybersecurity investments, IT teams and boards often have the same debate: 'Instead of spending thousands of dollars on manual p...
The Depths of BOLA and IDOR: Exploiting REST and GraphQL APIs
What is BOLA (Broken Object Level Authorization)? Discover how threat actors exploit access control logic in APIs and how autonomous agents eradicate them.
AI Supply Chain Attacks: The Hidden Trojans Inside Open-Source LLMs
AI supply-chain security guide covering untrusted model files, Pickle and deserialization risk, model provenance, Safetensors, GGUF, sandboxing, and MLOps controls.
AI Safety vs. AI Security
Discover the critical distinctions between AI Safety (protecting humans from AI) and AI Security (protecting AI from malicious threat actors and hackers).
AI-Orchestrated Cyber Espionage: The Dawn of Autonomous APT Campaigns
Discover how Advanced Persistent Threats (APTs) weaponize Generative AI and autonomous agents to conduct hyper-scalable, undetectable cyber espionage...
GitOps Security in ArgoCD Architecture: How to Protect Your K8s Clusters
ArgoCD and GitOps architectures rely on a Single Source of Truth. Learn how attackers exploit supply chain vulnerabilities and the detailed guidelines...
Apple Warns: Older iPhones Vulnerable to Coruna & DarkSword Exploit Kits
Apple has issued a critical warning regarding unpatched, older iOS devices being actively targeted by Coruna and DarkSword exploit kits through drive-by...
Authentication in AI Applications: LLM Sessions and Data Privacy
AI application authentication guide covering JWT validation, session binding, thread ID access, tenant isolation, RAG authorization, and agent tool permissions.
AI Agent Traps: Web Attacks Against Agents
How hidden web content, poisoned context, and tool access can manipulate autonomous AI agents in real enterprise workflows.