EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Research · 107Technical Guide · 2Advisory Analysis · 5Guide · 1News · 3

Latest Posts

Vulnerability Analysis

Technical Analysis of Fortinet CVE-2026-35616: Actively Exploited API Vulnerability

A deep dive into the critical CVSS 9.1 improper access control vulnerability (CVE-2026-35616) in FortiClient EMS, its exploitation landscape, and...

2026-04-07Read
DevSecOps

How to Build a Production-Grade gRPC Service in Go: A Step-by-Step Guide

Learn how to write a gRPC service in Go from scratch: Protobuf definitions, Unary/Streaming RPCs, PostgreSQL with GORM, Auth Interceptors, Rate...

2026-04-07Read
DevSecOps

Legacy SAST vs. AI-Powered Code Analysis: The Future of AppSec

Why are traditional Static Analysis (SAST) tools slowing down development teams? Learn how AI-powered autonomous agents are redefining application...

2026-04-06Read
Guide

Cybersecurity for SMBs: A 5-Step Defense Strategy for Growing Teams

How can Small and Medium-Sized Businesses (SMBs) protect themselves from ransomware and data breaches on a tight budget? 5 actionable security steps.

2026-04-06Read
DevSecOps

The Alphabet of AppSec: Understanding the Difference Between SAST, DAST, and IAST

Confused by AppSec acronyms? Discover the core differences between SAST, DAST, and IAST to understand which testing methodology best secures your...

2026-04-06Read
Offensive Security

LLM and RAG Data Poisoning: Infiltrating Autonomous AI Models

How do threat actors execute Indirect Prompt Injections and Data Poisoning in Retrieval-Augmented Generation (RAG) architectures?

2026-04-06Read
Methodology

How Often Should You Penetration Test? (Scrapping the Annual Audit Myth)

How frequently does your company need a penetration test? Why the traditional 'once-a-year' pentest is actively putting modern software infrastructure...

2026-04-06Read
Guide

Black Box, White Box vs Grey Box Penetration Testing: Which Should You Choose?

Understand the key differences between Black Box, White Box, and Grey Box penetration testing to select the right cybersecurity approach for your business.

2026-04-06Read
Offensive Security

The Depths of BOLA and IDOR: Exploiting REST and GraphQL APIs

What is BOLA (Broken Object Level Authorization)? Discover how threat actors exploit access control logic in APIs and how autonomous agents eradicate them.

2026-04-27Read