How a broken auto-updater left my blog open to a WordPress core RCE (wp2shell, CVE-2026-63030) and the boring IP rule that saved it anyway.
The patch that couldn’t install: a WordPress core exploit created an admin on this blog


How a broken auto-updater left my blog open to a WordPress core RCE (wp2shell, CVE-2026-63030) and the boring IP rule that saved it anyway.
Reminder: the "S" in IoT stands for Security
I need a node.js guru volunteer to work with me on creating basic PKI PoC that provisions #ESP32 devices with client certificates; node-forge looks right for the purpose. I have the complete solution architecture figured, just need a node.js guru that can code it for free π Couple volunteers already, thanks @eliofilipe and @MrQinEL ;β¦

Sharing some thoughts on using mTLS (mutual TLS authentication) to secure IoT solutions in a blog post: https://harizanov.com/2019/06/using-mtls-to-secure-iot-solutions/

Notes on securing IoT devices with mutual TLS (mTLS) β what it adds over one-way SSL and how I apply it in my own projects.
Got featured on @hackaday .. again π https://x.com/hackaday/status/976639868263542785

Adding AI object detection to my plain IP security cameras β how accessible AI has become for DIY IoT projects.
New post: High security keyfob project http://harizanov.com/?p=4362

Building a high security key fob around Atmel’s ATSHA204 β because rolling code fobs turn out to be quite hackable.
I will be doing a tech session on "#Security, Big Data and other challenges to the #IoT" at @ISTA_Conference 2017 https://www.istacon.org/Sessions/Session/12DCE70C-7085-4499-87DC-6D2954571FD5

Some thoughts on IoT security: billions of records in transit daily, and most of the sensors sending them were never designed to be safe.

Second attempt at decoding the Paradox alarm keypad bus β reading alarm state, PIRs and door/window sensors for home automation use.
Tapping into my Paradox home security system to read armed/disarmed state and zone statuses β free presence data for home automation.