Research and guides
Long-form guides and research on video-infrastructure security: protocols, firmware, exposure, vulnerability management and hardening.
-
Camera firmware and the patching problem
Camera firmware is versioned by silicon, delivered by hand and signed only above a floor — what that means for choosing a build and keeping an estate on it.
-
Where camera segmentation goes wrong
Camera VLANs fail at the rule set more often than at the drawing. Vendor documentation shows the four places it happens, and what to write instead.
-
Common camera ports and protocols
The ports cameras and VMS servers actually listen on, the shipped enabled-or-disabled state each vendor documents, and the numbers nobody has confirmed.
-
End-of-life cameras and cyber risk
What an end-of-support commitment actually covers, whose clock it runs from, and which camera makers publish no lifecycle policy we could retrieve.
-
How cameras end up on the internet
Every published count of internet-exposed cameras counts devices answering at a routable address, which is not the same population as the reachable one.
-
What Mirai did to the camera industry
Cameras and DVRs are named in the Mirai charging documents. What three plea agreements admit, what researchers only estimated, and what nobody ever verified.
-
Procurement rules that now govern surveillance equipment
What Section 889, the FCC authorisation rules and their enforcement, the Entity List, UK PSTI and the EU Cyber Resilience Act actually require, and from when.
-
Which video vendors publish security advisories
CNA status, advisory locations and disclosure policy across thirteen video-security vendors, checked against the CVE Program's own roster on 5 September 2026.