EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Research · 107Technical Guide · 2Advisory Analysis · 5Guide · 1News · 3

Latest Posts

Deserialization Threats

Joblib Model Suspicious Code Execution Detected at Model Load Time

Identifies suspicious execution sequences during a Joblib model load indicating potentially obstructed deserialization threats.

2026-04-27Read
Deserialization Threats

Joblib / Scikit-Learn Arbitrary Code Execution (ACE)

Identifies insecure object deserialization attacks utilizing the popular Scikit-Learn Joblib persistency library, granting attackers remote execution...

2026-04-27Read
Deserialization Threats

GGUF Metadata Parsing Flaws (Llama.cpp Buffer Overflows)

Identifies highly critical buffer overflow attacks manipulating the internal metadata and vocabulary tensors of GGUF files to exploit C++ parsers like...

2026-04-27Read
Deserialization Threats

Extraction-Triggered Environment Override (Path Overwriting)

An advanced attack where a malicious model archive weaponizes extraction processes to overwrite critical environment-level objects, seizing control of...

2026-04-27Read
Deserialization Threats

Execution of Arbitrary Code via Model Config Architecture Targets

Identifying advanced threats where malicious executables are obfuscated as configuration objects inside an ML model archive, triggering Remote Code...

2026-04-27Read
Deserialization Threats

Machine Learning Archive Zip Slip (Path Traversal) Threat

Identifies severe path traversal vulnerabilities (Zip Slip) occurring during the automated extraction of compressed machine learning model packages.

2026-04-27Read
Vulnerability Analysis

Zero-Day Analysis: Authenticated SSRF in n8n-mcp (GHSA-4ggg-h7ph-26qr)

Yiğit İbrahim Sağlam discovered a critical Authenticated SSRF vulnerability in n8n-mcp. Learn how the x-n8n-url header was exploited to access...

2026-04-09Read
Security

Mythos, Machine-Speed Exploitation, and the Growing Importance of Identity Attack Paths

When Anthropic announced Mythos and the associated rollout plan, it sparked an immediate wave of discussion across the cybersecurity community about machine-speed compromise.

2026-04-09Read
Security Advisories

Zero-Day Analysis: Authenticated SSRF in n8n-mcp (GHSA-4ggg-h7ph-26qr)

Zero-Day Analysis: Authenticated SSRF vulnerability in n8n-mcp (GHSA-4ggg-h7ph-26qr) allowing attackers to query internal endpoints and exfiltrate cloud...

2026-04-09Read