Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Transitive Model Threat Detected with A Suspicious Model Dependency
Discover why transitive model threats and suspicious artificial intelligence dependencies put your AI supply chain at risk. Learn how Eresus Sentinel...
TensorFlow SavedModel Contains Suspicious Operator Execution at Model Run Time
Highlights complex execution parameters inside TensorFlow evaluations avoiding explicit malware categorization yet successfully performing extremely...
TensorFlow SavedModel Contains Unsafe Operator Execution at Model Run Time
Critical execution vulnerability identifying specifically unsafe logical operators strictly executing natively during standard TensorFlow prediction...
TensorFlow SavedModel Execution Environment Extrapolation (RCE)
A runtime execution vulnerability capitalizing on inherent structural logic within the standardized TensorFlow SavedModel infrastructure, permitting...
TorchScript Model Arbitrary Code Execution Suspected at Model Load Time
Highlights suspicious computational graph behavior evaluating directly indicative of load-time remote code execution attempts within AI infrastructure....
PyTorch Model Arbitrary Code Execution Suspected at Model Load Time
PyTorch serialized objects detected with high-risk structural manipulation pointing towards concealed runtime commands.
PyTorch Subverted Loading Mechanism Triggering ACE
Identifies hostile payloads manipulating the core PyTorch `torch.load()` functionality to bypass security parameters and execute unauthorized OS commands.
File Corruption & Ransomware via Serialization Opcodes
Catastrophic cybersecurity alert indicating an ML artifact executes destructive local operations mimicking Ransomware upon load.
Environmental Data Exfiltration Initiated via Model Execution
Critical security threat characterizing an ML serialization object stealthily extracting operational secrets and API keys to third-party endpoints.