Skip to content
Zyberum Cyber Security Firm
Menu

Insights

Security knowledge, explained by practitioners.

Regulations, techniques and lessons from the field, written by the people who test and secure these systems every day.

Case studyIoTAPI security

Case Study: Root on a Robot Vacuum, and Other People’s Cameras

We tested a camera-equipped robot vacuum: root access on the device, and cloud API flaws that opened the live camera of other users. What went wrong and why.

Sep 30, 2026 · 5 min read

Case studyIoTMQTT

Case Study: A Smart Irrigation System Anyone Could Control

We tested a smart irrigation system: a broken MQTT setup let us see and switch the devices of other customers, and locate where they are installed.

Sep 30, 2026 · 4 min read

IoTPentest

IoT Penetration Testing: What We Attack and What We Find

What an IoT pentest covers, from debug ports and firmware to radio, apps and cloud, which findings come up most often, and how to prepare your device for testing.

Sep 30, 2026 · 7 min read

NIS2Compliance

NIS2 in Germany: Who Is Affected and What to Do Now

The German NIS2 law has applied since 6 December 2025. A practical checklist: scope, registration, the ten risk measures, reporting deadlines and first steps.

Sep 30, 2026 · 7 min read

IoTCompliance

RED Cybersecurity and EN 18031: What Wireless Devices Need

Since 1 August 2025 radio equipment sold in the EU must meet the RED cybersecurity requirements. What EN 18031 demands and how it relates to the CRA.

Sep 30, 2026 · 6 min read

Secure CodingEmbedded

Secure Coding in Embedded C: Five Bugs We Keep Finding

Unchecked lengths, integer overflows, format strings, weak randomness and debug leftovers: the five bug classes we find most in firmware, and how to avoid them.

Sep 30, 2026 · 7 min read

CRACompliance

Cyber Resilience Act: What Manufacturers Must Do by 2027

A practical guide to the EU Cyber Resilience Act: scope, product classes, deadlines, reporting duties and the concrete steps manufacturers should take now.

Sep 29, 2026 · 8 min read

AutomotiveFuzzing

ECU Fuzzing Explained: Finding Bugs in UDS, DoIP and SOME/IP

How fuzz testing works for automotive ECUs, which protocols to target, how to detect crashes on real hardware and how fuzzing supports ISO/SAE 21434.

Sep 29, 2026 · 7 min read

AutomotiveISO 21434

ISO/SAE 21434 vs UN R155: How They Fit Together

UN R155 is the law, ISO/SAE 21434 is the engineering standard. Learn how CSMS, TARA and testing connect, and what suppliers need to deliver to OEMs.

Sep 29, 2026 · 7 min read

Call usBook a call

Pick a time that suits you

Open in a new tab