Breaking Into a Govee Smart Display: From UART Shell to Device ImpersonationHi! I’m Matias Fumega, security consultant at Kulkan Security. This post covers my research on the Govee H8630 smart display. Starting from…Mar 26Mar 26
See no Evil(ginx) / Detecting and stopping AitM phishing threatsHi! I’m Matias Forti, technical lead at Kulkan Security. In this post, we’ll dive into some research focused on Evilginx, a popular reverse…Feb 9Feb 9
Published inArtificial Intelligence in Plain EnglishHow to Run Cisco’s Foundation-sec-8B-Reasoning in Ollama (DIY Guide!)Cisco’s new model release extends their previous 8B model with structured reasoning capabilities. This allows it to generate explicit…Feb 3Feb 3
Published inCyber Security Write-upsMxCheckSec: Validate SPF, DKIM, DMARC, and more.Introducing MxCheckSec for SPF, DKIM and DMARC validation, and more.Jan 28Jan 28
Gitxray v1.0.20: Inferring Timezones for Contributors, Commit Pattern Analysis, and more.Our latest version for Gitxray is out and already updated in PyPI. Several new features and association checks included that can help with…Jan 9Jan 9
A Hands-On Introduction to Polyglot FilesThe goal of this post is to explore the nature of polyglot files and the scenarios where they are most effective for discovering…Dec 18, 2025Dec 18, 2025
Published inCyber Security Write-upsAssessing the Attack Surface of Remote MCP ServersHello! I’m Matias Forti, technical lead here at Kulkan Security. As the AI landscape continues to evolve I’ve been really interested in…Nov 3, 2025Nov 3, 2025
Client-Side Path Traversal: Exploiting CSRF in Header-based auth scenariosHello! Lucas Cebrero here, Security Consultant at Kulkan. As part of an internal training activity I’ve been working on a small lab to…Oct 14, 2025Oct 14, 2025
Solving YWH Dojo #43 — Custom CCTV Firmware ChallengeHello everyone! Octavio Gorrini here, security consultant at Kulkan. As a way to continue learning I like to play CTFs, participate in…Sep 24, 2025Sep 24, 2025
In4m: Keeping up with the Latest Infosec NewsAt Kulkan, we believe it’s essential to stay continuously informed about the latest security threats that could impact both our customers…Sep 1, 2025Sep 1, 2025