Check Point and academic researchers discovered critical vulnerabilities in smart bulbs including Philips Hue and TP-Link Tapo models that enable attackers to inject malware into home networks through buffer overflows and credential theft. Millions of IoT devices are publicly exposed on Shodan, and attackers exploit known CVEs at scale; users should update firmware, isolate smart bulbs on separate networks, and replace devices with unpatched vulnerabilities.