Eresus research, advisory, and security news
We collect writing, advisories, and current-event analysis around AI security, the MCP ecosystem, application security, and real attack chaining here.
Featured Posts
Latest Posts
CI/CD Build Script Security: postinstall and build.rs Risks
How npm postinstall hooks, Cargo build.rs, and Maven plugins execute code during compilation — and the concrete controls to audit and harden your CI/CD pipeline.
Penetration Testing Under Turkish KVKK: Technical Measures, Board Decisions, and Evidentiary Value
Why penetration testing counts as a technical measure under KVKK Article 12 and the Personal Data Security Guide, how Turkish DPA decisions use it as evidence, and whether your pentest report would survive an audit — with real fine examples.
NIS2 Compliance and Penetration Testing: Article 21, the 24-Hour Clock, and €10M Fine Risk
Who qualifies as essential/important under NIS2, what Article 21 requires, how Implementing Regulation 2024/2690 treats security testing, the 24/72-hour reporting chain, and how non-EU suppliers should prepare.
Case Study: Lateral Movement Chain in a Kubernetes Security Review
How an over-privileged service account and a leaked GitOps credential were chained into cluster-wide compromise in a managed Kubernetes environment — validated exploitation path, remediation priority, and retest results.
DORA and Penetration Testing: Digital Operational Resilience Testing for Financial Entities
DORA Articles 24-27 explained: who falls under TLPT (threat-led penetration testing), what RTS 2025/1190 changes, the three-year testing cycle, TIBER-EU alignment, and a 12-month preparation roadmap.
PCI DSS 4.0.1 Penetration Testing: Requirement 11.4, Segmentation Testing, and the 2025 Changes
PCI DSS v4.0.1 penetration testing requirements explained: 11.4.1 methodology criteria, annual internal/external tests, segmentation validation, the March 2025 future-dated deadline, and multi-tenant service provider differences.
Case Study: AI Agent & MCP Red Team — The Prompt-to-Action Open Door
How an AI agent that reads internal documents and executes production actions was exploited through MCP tool-registration trust and missing approval gates — anonymized engagement write-up.
Case Study: Chaining BOLA and IDOR in a Fintech API Pentest
How BOLA and IDOR vulnerabilities were chained to reach cross-tenant transaction data in a multi-tenant payment platform — test approach, exploitation evidence, and remediation, anonymized.
wp2shell: Unauthenticated WordPress Core RCE via REST API Batch-Route Confusion (CVE-2026-63030 + CVE-2026-60137)
wp2shell chains a WordPress REST API batch-route confusion with a core SQL injection to reach unauthenticated remote code execution. What it is, who is affected, and how to respond.