EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Advisory Analysis · 3Guide · 1News · 3Research · 100

Latest Posts

Runtime Threats

TorchScript Model Arbitrary Code Execution Detected at Model Load Time

Critical security vulnerability detailing explicit Remote Code Execution (RCE) occurrences triggered dynamically during TorchScript model initialization...

2026-04-10Read
Deserialization Threats

Python Pickle Arbitrary Code Execution Detected

Discover how Python's built-in Pickle serialization module enables severe Arbitrary Code Execution (ACE) vulnerabilities within machine learning...

2026-04-10Read
Backdoor Threats

ONNX Model Contains Embedded File Threats

AI Models can distribute additional malicious binaries hidden inside model file payloads. Eresus Sentinel detects these backdoor packages masked within...

2026-04-10Read
Runtime Threats

LiteRT FlatBuffer Metadata RCE Exploits

Identifies critical threats leveraging the custom metadata extension fields within LiteRT (.tflite) FlatBuffer archives to force path traversals and...

2026-04-10Read
Runtime Threats

Keras Model Custom Layer Detected at Model Run Time

Highlights specific Keras deployments dynamically compiling complex custom layers entirely operating outside strict deserialization bounds. Poses...

2026-04-10Read
Deserialization Threats

GGUF Model Template Containing Arbitrary Code Execution Detected

GGUF formats using raw Jinja templates without sandboxing are susceptible to arbitrary code execution attacks. Always use isolated environments for...

2026-04-10Read
Runtime Threats

Transitive Model Threat Detected with Unsafe Model Dependency

Highlighting critical interconnected runtime threats targeting definitively unsafe Artificial Intelligence components distinctly imported during ML...

2026-04-27Read
Runtime Threats

Transitive Model Threat Detected with A Suspicious Model Dependency

Discover why transitive model threats and suspicious artificial intelligence dependencies put your AI supply chain at risk. Learn how Eresus Sentinel...

2026-04-27Read
Runtime Threats

TensorFlow SavedModel Contains Suspicious Operator Execution at Model Run Time

Highlights complex execution parameters inside TensorFlow evaluations avoiding explicit malware categorization yet successfully performing extremely...

2026-04-27Read