• Kulkan Newsletter
  • Posts
  • Smart home devices are more vulnerable than you think (and we proved it again!)

Smart home devices are more vulnerable than you think (and we proved it again!)

The latest from Kulkan: how a commercial weather station's RF protocol was decoded, and how tampered data was successfully injected and read by the station. We also bring updates of our latest K-Talk session, cybersecurity articles worth reading, the parallels between pentesting and the World Cup, and more.

📝 Latest from Our Blog:

Reversing a 433 MHz Weather Sensor: From RF Capture to Payload Forgery

Following the Govee Smart Display research, Matias Fumega reversed a 433 MHz Weather Sensor and injected custom data into it.

Want to see how with an SDR (and a bit of patience bruteforcing the Device ID) you can essentially inject arbitrary readings into the display?

🎙️ K-Talks:

A space to learn, share, and sharpen the tools and methodologies behind every assessment!

In our latest K-Talk session, Francisco Tierno (Manager at Kulkan) presented a custom Burp Suite extension he developed that uses LLMs to support the analysis of application logic.

Then, Lucas Cebrero (Security Consultant) broke down CVE-2025-55182 (React2Shell), the critical RCE in the React ecosystem, tracing it back to the Flight Protocol behind React Server Components and sharing a Next.js checklist to catch this class of issues early.

🌐 Industry News:

Want to stay on top of what's moving in the industry?

A one-click GitHub OAuth attack, an npm supply chain hit on Grafana Labs, NVIDIA's new AI security scanner, and other cybersecurity stories that caught our attention this month.

💡 Security Highlights:

What Does Offensive Security Have to Do With the World Cup?

We joined the World Cup fever the Kulkan way; because while soccer may not be our main expertise, we definitely know how to win the penetration testing match:

The match that really matters: are you ready to face your adversaries?

Pentesting is like training against your toughest rival; studying the field, exposing your weaknesses, and proving which ones a real rival (or attacker) can actually exploit…

Some vulnerabilities can only be found by the opponent who knows you best

In pentesting, like in soccer, there's no single "winning methodology" for every match: it's about understanding the specific business use cases to find how they can be compromised from within their own logic…

📝 Also From Our Blog:

Catch up on other technical blog posts; you’re still on time to read them!

Breaking Into a Govee Smart Display: From UART Shell to Device Impersonation

By Matias Fumega

See no Evil(ginx) / Detecting and stopping AitM phishing threats

By Matias Forti

MxCheckSec: Validate SPF, DKIM, DMARC, and more

By Serafin Cepeda

Ready to strengthen your security posture?

If you’re planning upcoming penetration testing initiatives, let’s start the conversation and explore how our attacker-led approach can help secure your business and support its growth.