EresusSecurity
Research & Intelligence

Eresus research, advisory, and security news

We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.

Guide · 27News · 4Case Study · 3Research · 84Technical Guide · 2Advisory Analysis · 5Advisory · 2

Featured Posts

Latest Posts

GuideSoftware Supply Chain

CI/CD Build Script Security: postinstall and build.rs Risks

How npm postinstall hooks, Cargo build.rs, and Maven plugins execute code during compilation — and the concrete controls to audit and harden your CI/CD pipeline.

2026-08-26Read
GuideCompliance

Penetration Testing Under Turkish KVKK: Technical Measures, Board Decisions, and Evidentiary Value

Why penetration testing counts as a technical measure under KVKK Article 12 and the Personal Data Security Guide, how Turkish DPA decisions use it as evidence, and whether your pentest report would survive an audit — with real fine examples.

2026-08-25Read
GuideCompliance

NIS2 Compliance and Penetration Testing: Article 21, the 24-Hour Clock, and €10M Fine Risk

Who qualifies as essential/important under NIS2, what Article 21 requires, how Implementing Regulation 2024/2690 treats security testing, the 24/72-hour reporting chain, and how non-EU suppliers should prepare.

2026-08-24Read
Case StudyCloud Security

Case Study: Lateral Movement Chain in a Kubernetes Security Review

How an over-privileged service account and a leaked GitOps credential were chained into cluster-wide compromise in a managed Kubernetes environment — validated exploitation path, remediation priority, and retest results.

2026-08-24Read
GuideCompliance

DORA and Penetration Testing: Digital Operational Resilience Testing for Financial Entities

DORA Articles 24-27 explained: who falls under TLPT (threat-led penetration testing), what RTS 2025/1190 changes, the three-year testing cycle, TIBER-EU alignment, and a 12-month preparation roadmap.

2026-08-23Read
GuideCompliance

PCI DSS 4.0.1 Penetration Testing: Requirement 11.4, Segmentation Testing, and the 2025 Changes

PCI DSS v4.0.1 penetration testing requirements explained: 11.4.1 methodology criteria, annual internal/external tests, segmentation validation, the March 2025 future-dated deadline, and multi-tenant service provider differences.

2026-08-22Read
Case StudyAI Security

Case Study: AI Agent & MCP Red Team — The Prompt-to-Action Open Door

How an AI agent that reads internal documents and executes production actions was exploited through MCP tool-registration trust and missing approval gates — anonymized engagement write-up.

2026-08-22Read
Case StudyFintech

Case Study: Chaining BOLA and IDOR in a Fintech API Pentest

How BOLA and IDOR vulnerabilities were chained to reach cross-tenant transaction data in a multi-tenant payment platform — test approach, exploitation evidence, and remediation, anonymized.

2026-08-21Read
Vulnerability Analysis

wp2shell: Unauthenticated WordPress Core RCE via REST API Batch-Route Confusion (CVE-2026-63030 + CVE-2026-60137)

wp2shell chains a WordPress REST API batch-route confusion with a core SQL injection to reach unauthenticated remote code execution. What it is, who is affected, and how to respond.

2026-07-20Read