• Kulkan Newsletter
  • Posts
  • From root access in a Xiaomi Smart Speaker to supply chain attacks at scale (and more)

From root access in a Xiaomi Smart Speaker to supply chain attacks at scale (and more)

The latest from Kulkan: discover the full process of getting root on an IoT device using nothing but a UART connection, and a technical deep-dive into how a single supply chain attack technique scales across tens of thousands of open source packages. Plus, the vulnerabilities, exploits, and research making noise in the offensive security world this month.

📝 Latest from Our Blog:

U-Boot as an attack surface on a Xiaomi L09G Smart Speaker

Matias Fumega documents the process of obtaining a root shell on a Xiaomi L09G smart speaker using nothing beyond a UART connection.

The article covers how Matias went from an interactive U-Boot shell to dumping and patching BL33 in Ghidra, bypassing signature verification, and booting a fully custom kernel image.

Analyzing GitHub Actions workflows at scale

Nahuel D. Sánchez analyzes vulnerable GitHub Actions workflows born out of real-world supply chain attacks.

Using TeamPCP's exploitation method as a starting point, he analyzed thousands of packages from PyPI, NPM, and Rust Crates at scale, uncovering how this attack class works and reporting several vulnerabilities along the way.

🗓️ Key Industry Events:

Leaving our mark at Black Hat & DEF CON 2026

It was an important milestone for Kulkan to show up, once again, during the most important week in the world for cybersecurity.

Nahuel D. Sánchez, Joaquin Miranda, and Lucas Lavarello connected with security leaders and practitioners throughout their week in Vegas. But the journey continues: the Kulkan team will keep heading wherever the cybersecurity community calls, always carrying the same attacker mindset that defines us.

Next stop? We won't spoil it. We can only say big things are coming.

🌐 Industry News:

What's moving the offensive security landscape?

An unauthenticated account takeover flaw in Keycloak, secret keys recovered via power LED video footage, a firmware bug that silently bypassed hardware RNG for five years, and other cybersecurity articles worth reading this month.

📝 Also From Our Blog:

Catch up on other technical blog posts; you’re still on time to read them!

A Zip encryption downgrade caused by an incorrect operator

Reversing a 433 MHz Weather Sensor: From RF Capture to Payload Forgery

Breaking Into a Govee Smart Display: From UART Shell to Device Impersonation

Any penetration test in scope?

Let's start the conversation and explore how an attacker-led approach can strengthen your defenses and support your business growth.