EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Research · 107Technical Guide · 2Advisory Analysis · 5Guide · 1News · 3

Latest Posts

Agentic AI

How AI Coding Assistants Expose Secrets

Discover the critical AI Security risks associated with autonomous coding tools. Learn how Cursor, Copilot, and Claude can inadvertently leak your .env...

2026-04-27Read
Backdoor Threats

TensorFlow Custom Operator Injection (Graph Execution)

Identifies backdoor threats leveraging embedded malformed computational nodes (Custom Operators) within TensorFlow models to silently trigger execution...

2026-04-10Read
Runtime Threats

TorchScript Model Arbitrary Code Execution Detected at Model Load Time

Critical security vulnerability detailing explicit Remote Code Execution (RCE) occurrences triggered dynamically during TorchScript model initialization...

2026-04-10Read
Deserialization Threats

Python Pickle Arbitrary Code Execution Detected

Discover how Python's built-in Pickle serialization module enables severe Arbitrary Code Execution (ACE) vulnerabilities within machine learning...

2026-04-10Read
Backdoor Threats

ONNX Model Contains Embedded File Threats

AI Models can distribute additional malicious binaries hidden inside model file payloads. Eresus Sentinel detects these backdoor packages masked within...

2026-04-10Read
Runtime Threats

LiteRT FlatBuffer Metadata RCE Exploits

Identifies critical threats leveraging the custom metadata extension fields within LiteRT (.tflite) FlatBuffer archives to force path traversals and...

2026-04-10Read
Runtime Threats

Keras Model Custom Layer Detected at Model Run Time

Highlights specific Keras deployments dynamically compiling complex custom layers entirely operating outside strict deserialization bounds. Poses...

2026-04-10Read
Deserialization Threats

GGUF Model Template Containing Arbitrary Code Execution Detected

GGUF formats using raw Jinja templates without sandboxing are susceptible to arbitrary code execution attacks. Always use isolated environments for...

2026-04-10Read
Runtime Threats

Transitive Model Threat Detected with Unsafe Model Dependency

Highlighting critical interconnected runtime threats targeting definitively unsafe Artificial Intelligence components distinctly imported during ML...

2026-04-27Read