EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Latest Posts

Methodology

What is Agentic Cybersecurity? Are AI Agents Replacing Pentesters?

Discover the differences between Agentic Security architecture and manual penetration testing, and explore the future of AI in offensive cybersecurity.

2026-04-27Read
GuideAI GovernanceNIST AI Risk Management Framework

What Is AI Data Governance and Why Is It So Hard to Implement?

AI data governance guide for LLM and RAG systems: semantic DLP, tenant-aware retrieval, purpose-based access, provenance, deletion, and auditability.

2026-08-11Read
GuideAI SecurityOWASP Top 10 for LLM Applications

How AI Coding Assistants Expose Secrets

AI coding assistant security guide for Cursor, Copilot, and Claude: secret leakage, workspace indexing, prompt injection, terminal tools, OAuth scopes, and enterprise controls.

2026-08-11Read
Red Team

Setting up an Active Directory Pentest Lab in Seconds with AI (Cursor)

For cyber security experts and internal Red Teams: How to set up a fully comprehensive, vulnerable Active Directory test environment with a single click...

2026-04-27Read
ResearchCloud SecurityKubeflow Central Dashboard and Profiles documentation

Kubeflow Dashboard Security: Authentication, Notebook Isolation and Cloud Metadata Risk

How to assess Kubeflow dashboard exposure, OIDC, profiles, notebook permissions, network isolation, audit logs, and cloud metadata access without assuming every deployment is vulnerable.

2026-08-11Read
AdvisoryAI Supply ChainOWASP Path Traversal Guidance & Eresus AI Security Research

PAIT-ARV-100: Archive Slip Vulnerabilities in Machine-Learning Model Packaging

Comprehensive guide on Zip Slip and Tar Slip path traversal in AI model archives, detailing how malicious archive entries escape extraction sandboxes and execute code on inference servers.

2026-08-11Read
GuideAI SecurityOWASP Top 10 for LLM Applications

Beyond Jailbreaks: Contextual Red Teaming for Agentic AI

Why standalone jailbreak tests miss agent risk, and how to test indirect prompt injection, retrieval boundaries, tool permissions, and recovery in multi-step systems.

2026-08-11Read