- Kulkan Newsletter
- Posts
- What's moving the offensive security landscape?
What's moving the offensive security landscape?
The latest from Kulkan: we joined Ekoparty Miami as official sponsors, delivering two technical talks during the conference! Plus, a roundup of the cybersecurity stories that caught our attention this month, and the latest technical research and tools from our blog worth reading.
🗓️ Key Industry Events:
Kulkan at Ekoparty Miami!
We closed out an incredible week in Miami, as official sponsors of Ekoparty's U.S. debut: two technical talks, key industry connections, and offensive security conversations that mattered!

Our team took the stage to show what an attacker mindset really looks like in practice: Matias Fumega presented his research on hardware hacking, showing how two real targets were compromised from scratch, while our CEO Lucas Lavarello shared how a single misplaced operator silently broke encryption in a Python library recommended by frontier LLMs.
🌐 Industry News:
Want to stay on top of what's moving in the industry?From a critical RCE in GitHub's internal infrastructure to a social engineering attack hijacking DNS records (and many others), here's our latest selection of cybersecurity articles that caught our attention. | ![]() |
📝 Latest from Our Blog:
![]() | Breaking Into a Govee Smart DisplayMatias Fumega dives into research on the Govee H8630 smart display, starting from initial UART access and ends at full device impersonation, finding and reporting cool bugs along the way. |
![]() | See no Evil(ginx) / Detecting and stopping AitM phishing threatsIn this research, Matias Forti dives into Evilginx, a popular reverse proxy phishing toolkit, focusing on how these attacks work and how these campaigns can be detected and disrupted in the wild. |
![]() | MxCheckSec: Validate SPF, DKIM, DMARC, and moreSerafin Cepeda introduces MxCheckSec, a tool designed to simplify the validation of SPF, DKIM, and DMARC records to ensure a secure email setup. |
Ready to strengthen your security posture?
If you’re planning upcoming penetration testing initiatives, let’s start the conversation and explore how our attacker-led approach can help secure your business and support its growth.



