Peeling Back the Plastic: Finding 0-Days in IoT Devices @OWASPGLOBAL
Peeling Back the Plastic: Finding 0-Days in IoT Devices  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
As smart home technology becomes increasingly mainstream, the market has seen a surge in low-cost IoT devices flooding platforms like Amazon. Many of these products are backed by lesser-known manufacturers — often overseas — that prioritize rapid deployment and market share over security and long-term support. This trend has led to a growing number of insecure devices being integrated into home networks, exposing users to significant privacy and security risks.

This presentation will cover getting into IoT security research, and lead up to a discussion of new zero day vulnerabilities that have been responsibly disclosed from prior research. Additionally, the session will touch on introductory practical testing techniques that can uncover critical 0-day vulnerabilities in these devices. We’ll walk through introductory methods for analyzing firmware, hardware, and corresponding mobile applications, then bridge the gap into real-world 0-day vulnerability discovery. Additionally, the talk will cover how device-centric research can reveal API vulnerabilities which are invisible to traditional web-focused assessments.

Nicholas Cerne
Bishop Fox
Security Consultant

Nicholas Cerne is a Security Consultant at Bishop Fox, specializing in application penetration testing, hybrid application assessments, and cloud penetration testing. He also enjoys conducting IoT security research as a hobby. Nicholas holds the Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), and Security+ certifications.

He graduated with a B.S. in Cybersecurity from Virginia Tech, where he formerly served as president of the university's Cybersecurity Club.
linkedin.com/in/nick-cerne
bishopfox.com/blog/methodology-for-traeger-grill-hack (blog)

Managed by the OWASP® Foundation
owasp.org
Peeling Back the Plastic: Finding 0-Days in IoT Devices202006 June 2020 Global Board MeetingBeyond the Checklist: Adversary Simulation for Proactive Insecure Design Discovery track 2German OWASP Day HighlightThreat Modeling in the Age of AI - Susanna CoxTwo Paths to Security Upskilling: Startup and EnterpriseTransparency Exchange API: How Do You Find the SBOM for a Smart Light Bulb?OWASP Top 10 Risks for Open Source Software - George Apostolopoulos“The Developer First Security Mindset”   Making Security a Product Feature, Not a BlockerEveryone Can Play! Building CTFs for Non-Security FolksLLMs in AppSec: Why They Still Need a ChaperoneAI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir Sadon
OWASP Foundation |

Peeling Back the Plastic: Finding 0-Days in IoT Devices

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER