Marcin Motwicki
„Security is a process, not a one-off product.”
Day to day, I break security in a controlled way to help companies build stronger, attack-resistant systems. I have over 7 years of experience in the offensive security industry. In that time I have delivered more than 350 projects, from audits for small startups, through medical facilities, to the complex environments of large corporations. In over 70 of them I served as the technical lead.
What drives me is clarity. The art is not capturing the flag, writing an exploit or bragging about yet another CVE number. The real value lies in translating convoluted technical jargon into the language of business and risk management. I help managers and boards understand real threats and implement solutions that actually work.
Certifications
Areas of expertise
Career path
Getting started in Offensive Security
A fascination with reverse engineering and building aimbots / wallhacks for FPS games, first steps in memory analysis, function hooking and bypassing anti-cheat protections.
First encounters with cybersecurity
Attending meetups introducing students to the world of cybersecurity, organized by the John Paul II Catholic University of Lublin (KUL).
Courses, certificates and a first talk
Completing the first professional cybersecurity courses and trainings. Giving a talk at the Lublin University of Technology for World Password Day.
A career in Offensive Security
Joining Smarttech247 as a Junior Pentester. Delivering the first network and infrastructure audits.
OSCP certificate & first CVE
Independently running tests for global clients. Earning the elite OSCP certificate. Publishing a first CVE.
Network and web application expert
Earning OSWP and BSCP certifications. Starting independent research (bug hunting).
Team Lead, OSWE & 0-day discoveries
Promotion to team lead. Earning the advanced OSWE certificate. Reporting critical vulnerabilities in CVAT. Completing Sector7 and MalDev Academy courses.
ISO 27001 Auditor & IASE
Extending competencies with certified ISO 27001 auditing. Completing the IASE (iOS Application Security Engineer) course by Securing. Growing PWNONE as a brand.
Growing PWNONE
Delivering comprehensive security audits, industry talks (incl. LLM/AI security) and popularizing knowledge.
Published CVE
Independent software security research that resulted in official security bulletins.
PHP Object Injection in WordPress Cooked Pro (10,000+ active installs)
Reflected XSS in Computer Vision Annotation Tool (CVAT)
Double IDOR in CVAT webhooks, data theft and DoS risk
Broken Access Control (IDOR) in CVAT, ACL bypass via HTTP method change
Capture The Flag (CTF)
I regularly compete in CTF events, taking top places at Break the Syntax CTF, TyphoonCon and NahamCon, among others.
Industry talks
I speak at conferences and meetups, sharing knowledge about LLM/AI security and popularizing cybersecurity.
Articles Marcina
Practical knowledge from the front lines of offensive cybersecurity.
How I Impersonated an Interia Administrator. An Analysis of an SPF Bypass / DMARC Misconfiguration
During routine research we came across a serious flaw in the SPF configuration of Interia.pl that made it possible to send forged emails bypassing sender verification.
How to Secure an API Against Attacks? A Practical Guide
In the age of microservices, the API is the backbone of modern software. Learn the key practices for protecting programming interfaces against attacks.
Anatomy of a Breach: A Ransomware Attack on the Polish Healthcare Sector
A detailed analysis of a real ransomware incident that paralyzed a hospital network. From the initial access vector to full remediation — step by step.
NIS2 in Practice: What You Must Implement by October 2026
The NIS2 Directive places new obligations on operators of essential services. See which requirements you must meet and how to prepare for them.
Change One HTTP Method and... You Walk Right In. A Classic IDOR in CVAT (CVE-2024-47172)
Changing the HTTP method from GET to PATCH was enough to bypass access control in the popular CVAT tool. A classic IDOR vulnerability with the official identifier CVE-2024-47172.
When an int Becomes a Malicious Script. Reflected XSS in CVAT (CVE-2024-47064)
A lack of input type validation and output encoding allowed injecting malicious JavaScript into the victim’s browser. Reflected XSS in CVAT scored CVSS 8.1 (High).
Let's talk about your security
Looking for an experienced pentester, an auditor, or someone who can explain clearly and simply where the critical flaws lurk in your environment? Write to me.
