Real vulnerabilities, not scanner output
A scanner spits out hundreds of findings with no context. I show you what can actually be exploited, and how to fix it.
Pentester · Security auditor
I'm Jakub Lipiec, a penetration tester and security auditor. I test hardware and software - from embedded circuits, through connected and industrial devices, to automotive systems. I also run training and workshops for technical teams.
Experience
Employment, independent work and industry bodies. The full story is on the about page.
Focus
I don't do everything for everyone. The specialisation is narrow on purpose - that's why I know where these systems actually break.
Hardware and firmware analysis: debug interfaces, memory, radio communication, over-the-air updates. I look at the device from the angle its maker usually doesn't.
Learn moreHands-on sessions for technical teams: IoT security, modern attack techniques, Red Team and Blue Team exercises. No slides without substance.
Learn moreIn-vehicle systems, communication buses and telematics modules. Experience built on automotive projects at Bosch Poland.
Learn moreHow it looks
An illustration of how I work. The actual steps depend on what I'm given and what the agreed scope covers.
$ recon --hardware[*] Debug interface exposed on pads TP4-TP7[*] Memory: SPI NOR, 8 MB, read protection not enabled$ firmware extract && analyze[!] API key stored in plaintext in the configuration[!] OTA update accepted without signature verification$ report --format pdf --cvss 3.1[+] Report ready: 2 critical, 5 high, each with remediation steps
Every finding comes with proof of exploitation, a CVSS 3.1 rating and a concrete fix. Without the first you can't tell if it's real; without the third you can't tell what to do about it.
Why me
A scanner spits out hundreds of findings with no context. I show you what can actually be exploited, and how to fix it.
Most testers stop at the application layer. I go down to the board: chips, interfaces, firmware.
I speak and teach for a living, so the report also lands with management - in language that translates into decisions.
Alerts
The CISA catalog collects vulnerabilities known to have been actually used in attacks - not the ones that could theoretically cause harm. It holds 1 656 entries today and only ever grows; 172 were added in 2026 alone. The four newest are below.
Updated:
Tell me briefly what it is and where you are in the process. I'll tell you whether and how I can help - no strings attached.