EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Latest Posts

Advisory

Breaking MCP Authentication: How a Single Line of Code Exposes an Entire Legal Database

Eresus Security discovers a critical authentication bypass in yargi-mcp, a popular open-source MCP server for Turkish legal databases. A single...

2026-04-04Read
Security Advisories

Critical RCE Vulnerability in Legacy Enterprise Gateway

Critical Remote Code Execution (RCE) vulnerability in legacy enterprise API gateway architectures allowing unauthenticated root access via command injection in header logging.

2026-03-15Read
GuideAI SecurityOWASP Top 10 for LLM Applications

What is a Vector Database? Its Role in AI and LLM Security

Vector database security guide for AI and RAG: embeddings, metadata filters, tenant isolation, data poisoning, retrieval authorization, deletion, and audit logs.

2026-08-11Read
Adversarial ML

What is AI Security? A Complete Enterprise Blueprint for Securing Machine Learning Ecosystems

A deep dive into the complex world of AI Security. Understand the mechanics behind data poisoning, adversarial ML evasion, and prompt injection attacks...

2026-04-14Read
NewsCloud SecurityVercel April 2026 Security Bulletin

Vercel, Context.ai, and AI SaaS Security

Eresus analyzes the April 20, 2026 Vercel incident linked to Context.ai and explains why OAuth-connected AI tools now belong in the core SaaS attack surface.

2026-08-11Read
AI Security

Structuring and Securing AI Microservices in Python (FastAPI)

Why must you transition from monolithic setups to a microservices architecture when exposing AI models to the public? Designing attack-resistant Python...

2026-04-02Read
DevSecOps

The Alphabet of AppSec: Understanding the Difference Between SAST, DAST, and IAST

Confused by AppSec acronyms? Discover the core differences between SAST, DAST, and IAST to understand which testing methodology best secures your...

2026-04-06Read
Backend Security

Why Should We Use Rust for AI-Powered Backend Systems?

When AI assistants are writing half your code, how do you ensure system security? Discover the superiority of the Rust language and its Memory Safety...

2026-04-02Read
Guide

Penetration Testing Pricing in 2026: Cost Factors & Budget Guide

A comprehensive 2026 guide to penetration testing costs. Learn exactly how pricing is determined for web, mobile, and network security assessments.

2026-04-05Read