Uploaded December 2025 | Updated September 2026, 1 week ago
As smart home technology becomes increasingly mainstream, the market has seen a surge in low-cost IoT devices flooding platforms like Amazon. Many of these products are backed by lesser-known manufacturers — often overseas — that prioritize rapid deployment and market share over security and long-term support. This trend has led to a growing number of insecure devices being integrated into home networks, exposing users to significant privacy and security risks.
This presentation will cover getting into IoT security research, and lead up to a discussion of new zero day vulnerabilities that have been responsibly disclosed from prior research. Additionally, the session will touch on introductory practical testing techniques that can uncover critical 0-day vulnerabilities in these devices. We’ll walk through introductory methods for analyzing firmware, hardware, and corresponding mobile applications, then bridge the gap into real-world 0-day vulnerability discovery. Additionally, the talk will cover how device-centric research can reveal API vulnerabilities which are invisible to traditional web-focused assessments.
Nicholas Cerne
Bishop Fox
Security Consultant
Nicholas Cerne is a Security Consultant at Bishop Fox, specializing in application penetration testing, hybrid application assessments, and cloud penetration testing. He also enjoys conducting IoT security research as a hobby. Nicholas holds the Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), and Security+ certifications.
He graduated with a B.S. in Cybersecurity from Virginia Tech, where he formerly served as president of the university's Cybersecurity Club.
linkedin.com/in/nick-cerne
bishopfox.com/blog/methodology-for-traeger-grill-hack (blog)
Managed by the OWASP® Foundation
owasp.org
As smart home technology becomes increasingly mainstream, the market has seen a surge in low-cost IoT devices flooding platforms like Amazon. Many of these products are backed by lesser-known manufacturers — often overseas — that prioritize rapid deployment and market share over security and long-term support. This trend has led to a growing number of insecure devices being integrated into home networks, exposing users to significant privacy and security risks.
This presentation will cover getting into IoT security research, and lead up to a discussion of new zero day vulnerabilities that have been responsibly disclosed from prior research. Additionally, the session will touch on introductory practical testing techniques that can uncover critical 0-day vulnerabilities in these devices. We’ll walk through introductory methods for analyzing firmware, hardware, and corresponding mobile applications, then bridge the gap into real-world 0-day vulnerability discovery. Additionally, the talk will cover how device-centric research can reveal API vulnerabilities which are invisible to traditional web-focused assessments.
Nicholas Cerne
Bishop Fox
Security Consultant
Nicholas Cerne is a Security Consultant at Bishop Fox, specializing in application penetration testing, hybrid application assessments, and cloud penetration testing. He also enjoys conducting IoT security research as a hobby. Nicholas holds the Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), and Security+ certifications.
He graduated with a B.S. in Cybersecurity from Virginia Tech, where he formerly served as president of the university's Cybersecurity Club.
linkedin.com/in/nick-cerne
bishopfox.com/blog/methodology-for-traeger-grill-hack (blog)
Managed by the OWASP® Foundation
owasp.org










