Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
LiteRT FlatBuffer Metadata RCE Exploits
Identifies critical threats leveraging the custom metadata extension fields within LiteRT (.tflite) FlatBuffer archives to force path traversals and...
Joblib Model Suspicious Code Execution Detected at Model Load Time
Identifies suspicious execution sequences during a Joblib model load indicating potentially obfuscated deserialization threats and runtime hooks.
PAIT-GGUF-101: Arbitrary Code Execution via Unsandboxed Jinja2 Chat Templates in GGUF Models
Detailed analysis of Server-Side Template Injection (SSTI) in GGUF LLM formats, explaining how malicious Jinja2 chat templates execute remote shell commands upon model load.
GGUF Metadata Parsing Flaws (Llama.cpp Buffer Overflows)
Identifies highly critical buffer overflow attacks manipulating the internal metadata and vocabulary tensors of GGUF files to exploit C++ parsers like...
Automated Red Teaming for Agentic AI Workflows: What to Test and What to Measure
A practical framework for testing prompt injection, tool abuse, data exposure, excessive agency, and recovery in enterprise agent workflows.
Extraction-Triggered Environment Override (Path Overwriting)
An advanced attack where a malicious model archive weaponizes extraction processes to overwrite critical environment-level objects, seizing control of...
AI Security Testing for GenAI Applications: From Prompt Tests to Runtime Controls
A practical guide to assessing GenAI applications, agent permissions, RAG data flows, prompt injection, output handling, and runtime evidence.
Execution of Arbitrary Code via Model Config Architecture Targets
Identifying advanced threats where malicious executables are obfuscated as configuration objects inside an ML model archive, triggering Remote Code...
Joblib / Scikit-Learn Arbitrary Code Execution (ACE)
Identifies insecure object deserialization attacks utilizing the popular Scikit-Learn Joblib persistency library, granting attackers remote execution...