Marcin Motwicki - CEO of PWNONE
CEO
CEO & Co-founder, PWNONE
7+ years in offensive security
350+ delivered projects
4 published CVEs
8 elite certifications
9 articles in the Knowledge Base
CEO & Co-founder of PWNONE

Marcin Motwicki

„Security is a process, not a one-off product.”

Day to day, I break security in a controlled way to help companies build stronger, attack-resistant systems. I have over 7 years of experience in the offensive security industry. In that time I have delivered more than 350 projects, from audits for small startups, through medical facilities, to the complex environments of large corporations. In over 70 of them I served as the technical lead.

What drives me is clarity. The art is not capturing the flag, writing an exploit or bragging about yet another CVE number. The real value lies in translating convoluted technical jargon into the language of business and risk management. I help managers and boards understand real threats and implement solutions that actually work.

Certifications

2025
ISO 27001
Lead Auditor
2025
iASE
iOS Application Security Engineer (Securing)
2024
OSWE
Offensive Security Web Expert
2024
MalDev Academy
Malware Development Academy
2024
Sector7
Sector7 Red Team Training
2023
BSCP
Burp Suite Certified Practitioner
2023
OSWP
Offensive Security Wireless Professional
2022
OSCP
Offensive Security Certified Professional

Areas of expertise

Web and mobile application penetration testing (SAST/DAST)
Active Directory environments and internal networks
Wireless network audits (Enterprise, Evil Twin, WPA2)
Open-source intelligence (OSINT) and Dark Web research
Social engineering (phishing, vishing)
Physical security testing (tailgating, lock picking, USB drops)

Career path

2018

Getting started in Offensive Security

A fascination with reverse engineering and building aimbots / wallhacks for FPS games, first steps in memory analysis, function hooking and bypassing anti-cheat protections.

2019

First encounters with cybersecurity

Attending meetups introducing students to the world of cybersecurity, organized by the John Paul II Catholic University of Lublin (KUL).

2020

Courses, certificates and a first talk

Completing the first professional cybersecurity courses and trainings. Giving a talk at the Lublin University of Technology for World Password Day.

2021

A career in Offensive Security

Joining Smarttech247 as a Junior Pentester. Delivering the first network and infrastructure audits.

2022

OSCP certificate & first CVE

Independently running tests for global clients. Earning the elite OSCP certificate. Publishing a first CVE.

2023

Network and web application expert

Earning OSWP and BSCP certifications. Starting independent research (bug hunting).

2024

Team Lead, OSWE & 0-day discoveries

Promotion to team lead. Earning the advanced OSWE certificate. Reporting critical vulnerabilities in CVAT. Completing Sector7 and MalDev Academy courses.

2025

ISO 27001 Auditor & IASE

Extending competencies with certified ISO 27001 auditing. Completing the IASE (iOS Application Security Engineer) course by Securing. Growing PWNONE as a brand.

2026

Growing PWNONE

Delivering comprehensive security audits, industry talks (incl. LLM/AI security) and popularizing knowledge.

Bug Hunting & Responsible Disclosure

Published CVE

Independent software security research that resulted in official security bulletins.

CVE-2022-3900
CriticalCVSS 9.8

PHP Object Injection in WordPress Cooked Pro (10,000+ active installs)

CVE-2024-47064
HighCVSS 8.1

Reflected XSS in Computer Vision Annotation Tool (CVAT)

CVE-2024-45393
MediumCVSS 6.4

Double IDOR in CVAT webhooks, data theft and DoS risk

CVE-2024-47172
MediumCVSS 5.4

Broken Access Control (IDOR) in CVAT, ACL bypass via HTTP method change

Capture The Flag (CTF)

I regularly compete in CTF events, taking top places at Break the Syntax CTF, TyphoonCon and NahamCon, among others.

Industry talks

I speak at conferences and meetups, sharing knowledge about LLM/AI security and popularizing cybersecurity.

Articles Marcina

Practical knowledge from the front lines of offensive cybersecurity.

All articles
Zero-Day 15 min read

How I Impersonated an Interia Administrator. An Analysis of an SPF Bypass / DMARC Misconfiguration

During routine research we came across a serious flaw in the SPF configuration of Interia.pl that made it possible to send forged emails bypassing sender verification.

March 11, 2026Read
Defense Guides 12 min read

How to Secure an API Against Attacks? A Practical Guide

In the age of microservices, the API is the backbone of modern software. Learn the key practices for protecting programming interfaces against attacks.

February 15, 2026Read
Breach Analyses 18 min read

Anatomy of a Breach: A Ransomware Attack on the Polish Healthcare Sector

A detailed analysis of a real ransomware incident that paralyzed a hospital network. From the initial access vector to full remediation — step by step.

March 8, 2026Read
Regulations & Compliance 10 min read

NIS2 in Practice: What You Must Implement by October 2026

The NIS2 Directive places new obligations on operators of essential services. See which requirements you must meet and how to prepare for them.

January 5, 2026Read
Zero-Day 10 min read

Change One HTTP Method and... You Walk Right In. A Classic IDOR in CVAT (CVE-2024-47172)

Changing the HTTP method from GET to PATCH was enough to bypass access control in the popular CVAT tool. A classic IDOR vulnerability with the official identifier CVE-2024-47172.

March 17, 2026Read
Zero-Day 8 min read

When an int Becomes a Malicious Script. Reflected XSS in CVAT (CVE-2024-47064)

A lack of input type validation and output encoding allowed injecting malicious JavaScript into the victim’s browser. Reflected XSS in CVAT scored CVSS 8.1 (High).

March 17, 2026Read

Let's talk about your security

Looking for an experienced pentester, an auditor, or someone who can explain clearly and simply where the critical flaws lurk in your environment? Write to me.