<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Eresus Security Research Feed</title>
    <link>https://www.eresussec.com</link>
    <atom:link href="https://www.eresussec.com/rss.xml" rel="self" type="application/rss+xml" />
    <description>Research, advisories, and offensive security writing from Eresus Security.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:22:59 GMT</lastBuildDate>
    
    <item>
      <title><![CDATA[Webhook Security Testing: Signatures, Replay, and Delivery]]></title>
      <link>https://www.eresussec.com/en/blog/webhook-security-testing-signatures-replay</link>
      <guid>https://www.eresussec.com/en/blog/webhook-security-testing-signatures-replay</guid>
      <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A practical guide to signatures, freshness, replay, idempotency, tenant isolation, queues, and callback risks in webhook integrations.]]></description>
    </item>
    <item>
      <title><![CDATA[RAG Authorization and Tenant Isolation Testing]]></title>
      <link>https://www.eresussec.com/en/blog/rag-authorization-tenant-isolation-testing</link>
      <guid>https://www.eresussec.com/en/blog/rag-authorization-tenant-isolation-testing</guid>
      <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[How to test ACL synchronization, tenant filters, cache leakage, citations, and document deletion in RAG systems.]]></description>
    </item>
    <item>
      <title><![CDATA[OAuth and OIDC Security Testing for SaaS]]></title>
      <link>https://www.eresussec.com/en/blog/oauth-oidc-security-testing-saas</link>
      <guid>https://www.eresussec.com/en/blog/oauth-oidc-security-testing-saas</guid>
      <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A hands-on review of Authorization Code, PKCE, redirects, state, nonce, token audience, account linking, and tenant membership.]]></description>
    </item>
    <item>
      <title><![CDATA[Mobile App Security: Tokens, Deep Links, and API Trust]]></title>
      <link>https://www.eresussec.com/en/blog/mobile-app-api-security-token-deep-links</link>
      <guid>https://www.eresussec.com/en/blog/mobile-app-api-security-token-deep-links</guid>
      <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A practical Android and iOS guide to token storage, deep links, device signals, and server-side authorization.]]></description>
    </item>
    <item>
      <title><![CDATA[AI Penetration Testing: How to Validate an Agent's Findings]]></title>
      <link>https://www.eresussec.com/en/blog/ai-penetration-testing-evidence</link>
      <guid>https://www.eresussec.com/en/blog/ai-penetration-testing-evidence</guid>
      <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[AI penetration testing can speed up reconnaissance, but every finding needs reproducible evidence, a verified impact path, and human review.]]></description>
    </item>
    <item>
      <title><![CDATA[AI Agent Identity Security: Trace the Path Behind Every Tool Call]]></title>
      <link>https://www.eresussec.com/en/blog/ai-agent-identity-attack-paths</link>
      <guid>https://www.eresussec.com/en/blog/ai-agent-identity-attack-paths</guid>
      <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Secure AI agents by tracing who can invoke them, which identity they use downstream, and what each tool call can reach.]]></description>
    </item>
    <item>
      <title><![CDATA[CI/CD Build Script Security: postinstall and build.rs Risks]]></title>
      <link>https://www.eresussec.com/en/blog/ci-cd-build-script-security-guide</link>
      <guid>https://www.eresussec.com/en/blog/ci-cd-build-script-security-guide</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[How npm postinstall hooks, Cargo build.rs, and Maven plugins execute code during compilation — and the concrete controls to audit and harden your CI/CD pipeline.]]></description>
    </item>
    <item>
      <title><![CDATA[ArrayRef Supply-Chain Attack: The proc-macro1 Backdoor in Rust]]></title>
      <link>https://www.eresussec.com/en/blog/arrayref-rust-supply-chain-attack-proc-macro1</link>
      <guid>https://www.eresussec.com/en/blog/arrayref-rust-supply-chain-attack-proc-macro1</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Technical breakdown of the Rust supply-chain attack on arrayref, internment, and append-only-vec: the attack chain, IOCs, and incident-response steps for teams.]]></description>
    </item>
    <item>
      <title><![CDATA[Penetration Testing Under Turkish KVKK: Technical Measures, Board Decisions, and Evidentiary Value]]></title>
      <link>https://www.eresussec.com/en/blog/kvkk-gdpr-turkey-pentest-technical-measures-guide</link>
      <guid>https://www.eresussec.com/en/blog/kvkk-gdpr-turkey-pentest-technical-measures-guide</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Why penetration testing counts as a technical measure under KVKK Article 12 and the Personal Data Security Guide, how Turkish DPA decisions use it as evidence, and whether your pentest report would survive an audit — with real fine examples.]]></description>
    </item>
    <item>
      <title><![CDATA[NIS2 Compliance and Penetration Testing: Article 21, the 24-Hour Clock, and €10M Fine Risk]]></title>
      <link>https://www.eresussec.com/en/blog/nis2-compliance-pentest-requirements</link>
      <guid>https://www.eresussec.com/en/blog/nis2-compliance-pentest-requirements</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Who qualifies as essential/important under NIS2, what Article 21 requires, how Implementing Regulation 2024/2690 treats security testing, the 24/72-hour reporting chain, and how non-EU suppliers should prepare.]]></description>
    </item>
    <item>
      <title><![CDATA[Case Study: Lateral Movement Chain in a Kubernetes Security Review]]></title>
      <link>https://www.eresussec.com/en/blog/case-study-kubernetes-cloud-review-lateral-movement</link>
      <guid>https://www.eresussec.com/en/blog/case-study-kubernetes-cloud-review-lateral-movement</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[How an over-privileged service account and a leaked GitOps credential were chained into cluster-wide compromise in a managed Kubernetes environment — validated exploitation path, remediation priority, and retest results.]]></description>
    </item>
    <item>
      <title><![CDATA[DORA and Penetration Testing: Digital Operational Resilience Testing for Financial Entities]]></title>
      <link>https://www.eresussec.com/en/blog/dora-financial-sector-digital-operational-resilience-testing</link>
      <guid>https://www.eresussec.com/en/blog/dora-financial-sector-digital-operational-resilience-testing</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[DORA Articles 24-27 explained: who falls under TLPT (threat-led penetration testing), what RTS 2025/1190 changes, the three-year testing cycle, TIBER-EU alignment, and a 12-month preparation roadmap.]]></description>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0.1 Penetration Testing: Requirement 11.4, Segmentation Testing, and the 2025 Changes]]></title>
      <link>https://www.eresussec.com/en/blog/pci-dss-4-penetration-testing-requirements</link>
      <guid>https://www.eresussec.com/en/blog/pci-dss-4-penetration-testing-requirements</guid>
      <pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[PCI DSS v4.0.1 penetration testing requirements explained: 11.4.1 methodology criteria, annual internal/external tests, segmentation validation, the March 2025 future-dated deadline, and multi-tenant service provider differences.]]></description>
    </item>
    <item>
      <title><![CDATA[Case Study: AI Agent & MCP Red Team — The Prompt-to-Action Open Door]]></title>
      <link>https://www.eresussec.com/en/blog/case-study-ai-agent-mcp-red-team-prompt-to-action</link>
      <guid>https://www.eresussec.com/en/blog/case-study-ai-agent-mcp-red-team-prompt-to-action</guid>
      <pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[How an AI agent that reads internal documents and executes production actions was exploited through MCP tool-registration trust and missing approval gates — anonymized engagement write-up.]]></description>
    </item>
    <item>
      <title><![CDATA[Case Study: Chaining BOLA and IDOR in a Fintech API Pentest]]></title>
      <link>https://www.eresussec.com/en/blog/case-study-fintech-api-pentest-bola-idor-chain</link>
      <guid>https://www.eresussec.com/en/blog/case-study-fintech-api-pentest-bola-idor-chain</guid>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[How BOLA and IDOR vulnerabilities were chained to reach cross-tenant transaction data in a multi-tenant payment platform — test approach, exploitation evidence, and remediation, anonymized.]]></description>
    </item>
    <item>
      <title><![CDATA[wp2shell: Unauthenticated WordPress Core RCE via REST API Batch-Route Confusion (CVE-2026-63030 + CVE-2026-60137)]]></title>
      <link>https://www.eresussec.com/en/blog/wp2shell-wordpress-core-rce-cve-2026-63030</link>
      <guid>https://www.eresussec.com/en/blog/wp2shell-wordpress-core-rce-cve-2026-63030</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[wp2shell chains a WordPress REST API batch-route confusion with a core SQL injection to reach unauthenticated remote code execution. What it is, who is affected, and how to respond.]]></description>
    </item>
    <item>
      <title><![CDATA[RFC 10008's New HTTP QUERY Method Is a Blind Spot for Every WAF Written Before June 2026]]></title>
      <link>https://www.eresussec.com/en/blog/rfc-10008-http-query-method-waf-bypass</link>
      <guid>https://www.eresussec.com/en/blog/rfc-10008-http-query-method-waf-bypass</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The IETF standardised a new HTTP method — QUERY — that behaves like a GET/POST hybrid. Security stacks built around GET/POST/PUT/DELETE assumptions now have a gap to close.]]></description>
    </item>
    <item>
      <title><![CDATA[CVE-2026-58420: Understanding Gitea Migration Restore Local File Inclusion]]></title>
      <link>https://www.eresussec.com/en/blog/gitea-cve-2026-58420-local-file-inclusion-en</link>
      <guid>https://www.eresussec.com/en/blog/gitea-cve-2026-58420-local-file-inclusion-en</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A practical security analysis of CVE-2026-58420 in Gitea migration restore, its operational impact, and how Eresus Guard supports evidence-first remediation.]]></description>
    </item>
    <item>
      <title><![CDATA[FreeBSD TIOCSTI: Terminal Input Injection and Local Privilege Risk]]></title>
      <link>https://www.eresussec.com/en/blog/freebsd-tiocsti-terminal-input-injection-disclosure</link>
      <guid>https://www.eresussec.com/en/blog/freebsd-tiocsti-terminal-input-injection-disclosure</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A responsible disclosure summary of FreeBSD TTY input-injection research, upstream mitigation, and verification steps for system administrators.]]></description>
    </item>
    <item>
      <title><![CDATA[Evidence-First Application Security: Turning Findings into Verifiable Decisions with Eresus Guard]]></title>
      <link>https://www.eresussec.com/en/blog/evidence-first-application-security-eresus-guard</link>
      <guid>https://www.eresussec.com/en/blog/evidence-first-application-security-eresus-guard</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[How Eresus Guard brings DAST, SAST, SCA, IaC, and secrets assessments into an evidence-first application security workflow.]]></description>
    </item>
  </channel>
</rss>