Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Latest Posts
Llama 4 Security Assessment: Scout vs. Maverick Deployment Risks
How to assess Llama 4 Scout and Maverick in a real application: model safeguards, prompt injection, output validation, local deployment, and supply-chain controls.
Zero-Day Analysis: Authenticated SSRF in n8n-mcp (GHSA-4ggg-h7ph-26qr)
Technical analysis of GHSA-4ggg-h7ph-26qr, an authenticated SSRF in n8n-mcp multi-tenant HTTP deployments, with exposure checks, patching, egress controls, and response steps.
Mythos, Machine-Speed Exploitation, and the Growing Importance of Identity Attack Paths
When Anthropic announced Mythos and the associated rollout plan, it sparked an immediate wave of discussion across the cybersecurity community about machine-speed compromise.
Machine Learning Archive Zip Slip (Path Traversal) Threat
Identifies severe path traversal vulnerabilities (Zip Slip) occurring during the automated extraction of compressed machine learning model packages.
OWASP Top 10 for LLMs: The Definitive Guide to AI Vulnerabilities
Explore the official OWASP Top 10 for Large Language Models (LLMs). From Prompt Injection to Supply Chain Attacks, learn how to secure your enterprise...
The Overlooked Attack Surface: Hunting 0-Days in AI Model Files
When discussing cybersecurity in Artificial Intelligence, everyone fixates on API security, prompt injections, and web vulnerabilities. Meanwhile, ...
LLM and RAG Data Poisoning: Infiltrating Autonomous AI Models
How do threat actors execute Indirect Prompt Injections and Data Poisoning in Retrieval-Augmented Generation (RAG) architectures?
AI Risk Report: Fast-Growing Threats in AI Runtime
AI runtime security research covering model supply chain, unsafe loading, parser risk, prompt injection, tool abuse, resource exhaustion, and recovery controls.
Artificial Intelligence (LLM) Manipulations: Prompt Injection and RAG Poisoning
Prompt injection and RAG poisoning guide: direct and indirect attacks, retrieval authorization, data provenance, tool boundaries, safe testing, and runtime controls.