EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Latest Posts

ResearchAI SecurityMeta Llama 4 Model Card

Llama 4 Security Assessment: Scout vs. Maverick Deployment Risks

How to assess Llama 4 Scout and Maverick in a real application: model safeguards, prompt injection, output validation, local deployment, and supply-chain controls.

2026-08-11Read
ResearchAI InfrastructureGitLab Advisory Database: GHSA-4ggg-h7ph-26qr

Zero-Day Analysis: Authenticated SSRF in n8n-mcp (GHSA-4ggg-h7ph-26qr)

Technical analysis of GHSA-4ggg-h7ph-26qr, an authenticated SSRF in n8n-mcp multi-tenant HTTP deployments, with exposure checks, patching, egress controls, and response steps.

2026-08-11Read
Security

Mythos, Machine-Speed Exploitation, and the Growing Importance of Identity Attack Paths

When Anthropic announced Mythos and the associated rollout plan, it sparked an immediate wave of discussion across the cybersecurity community about machine-speed compromise.

2026-04-09Read
Deserialization Threats

Machine Learning Archive Zip Slip (Path Traversal) Threat

Identifies severe path traversal vulnerabilities (Zip Slip) occurring during the automated extraction of compressed machine learning model packages.

2026-04-27Read
AI Security

OWASP Top 10 for LLMs: The Definitive Guide to AI Vulnerabilities

Explore the official OWASP Top 10 for Large Language Models (LLMs). From Prompt Injection to Supply Chain Attacks, learn how to secure your enterprise...

2026-04-14Read
Advisory

The Overlooked Attack Surface: Hunting 0-Days in AI Model Files

When discussing cybersecurity in Artificial Intelligence, everyone fixates on API security, prompt injections, and web vulnerabilities. Meanwhile, ...

2026-04-01Read
Offensive Security

LLM and RAG Data Poisoning: Infiltrating Autonomous AI Models

How do threat actors execute Indirect Prompt Injections and Data Poisoning in Retrieval-Augmented Generation (RAG) architectures?

2026-04-06Read
ResearchAI SecurityMITRE ATLAS

AI Risk Report: Fast-Growing Threats in AI Runtime

AI runtime security research covering model supply chain, unsafe loading, parser risk, prompt injection, tool abuse, resource exhaustion, and recovery controls.

2026-08-11Read
GuideAI SecurityOWASP Top 10 for LLM Applications

Artificial Intelligence (LLM) Manipulations: Prompt Injection and RAG Poisoning

Prompt injection and RAG poisoning guide: direct and indirect attacks, retrieval authorization, data provenance, tool boundaries, safe testing, and runtime controls.

2026-08-11Read