ROBERT KRUCZEK
Robert Kruczek

Robert "ProXy" Kruczek

Offensive Security & Research

Independent Security Researcher • Exploit Dev • Red Teaming

About Me

I am a Cybersecurity Consultant, Mentor, and Ethical Hacker (known in the infosec community as ProXy) at Securitum - Poland's leading cybersecurity firm - and a contributor to sekurak.pl, the country's largest infosec portal. With over 10 years of experience in vulnerability research and penetration testing.

Operating under the ProXy alias, I discovered and reported 53 CVEs and I am an active Bug Bounty hunter (Hall of Fame at OLX, reports for BlaBlaCar, OVH, and ERCOM).

53 CVEs Found
DPO Qualified
10+ Years Exp
HoF/BB BlaBlaCar / OVH / OLX
Book

Author of "Socjotechnika w praktyce"

"Triki i kruczki hackowania ludzi."

Practical guide on the psychology of hacking.

Learn more →

Publications

Who Are Ethical Hackers? - Polskie Radio 24

My radio interview where we break down the mindset and true role of ethical hackers in modern cybersecurity. We discuss how our motivations differ from black hats, focusing on securing infrastructure rather than chasing money or fame.

Read on Polskie Radio 24 →

The Legacy of VB6 and the ClientSide Auth Bypass

A technical breakdown of a security audit on a legacy VB6 application. It demonstrates how relying on a direct database connection and client-side authentication allows an attacker to completely bypass the login mechanism via binary patching.

Read on Securitum →

PAD CMS – Security Advisory and Critical Flaws Analysis

A technical advisory and vulnerability analysis of PAD CMS. This research led to the discovery of critical flaws, including Remote Code Execution (RCE), affecting multiple public institution websites.

Read on Safety Online →

Malware via RDP – Russian APT29 Campaign

Analysis of a new data exfiltration technique from Windows systems using RDP features, discovered in a campaign linked to the Russian APT29 group.

Read on Sekurak →

GitHub as an Attack Tool – APT Group Campaign

A technical look into how North Korean APT groups leverage fake job offers and GitHub repositories to distribute sophisticated malware to security researchers.

Read on Sekurak →

Phishing Under the Lens – Analysis of Cybercriminal Tactics

A comprehensive analysis of modern phishing techniques, psychological triggers used by attackers, and technical methods to bypass traditional email security filters.

Read on Sekurak →

ChatGPT as an (Un)safe Auditor's Assistant

A fascinating case study where ChatGPT generated a security tool containing a critical vulnerability, potentially allowing an attacker to compromise the pentester's own machine.

Read on Sekurak →

Unveiling Hidden Data: A Log Files Security Breach

Technical research on how improperly secured log files can become a goldmine for attackers, leading to the exposure of sensitive session tokens, credentials, and system architecture details.

Read on Securitum →

Public Speaking

MSHP - Web App Pentesting in 40 Minutes! CyberGov - 3587166b-d057-474b-b0ab-944da98fb28c MSHP - How Do Hackers Work? SHP Gliwice - Secure File Upload MSHP - How We Hacked Half of Poland in One Evening
Annual

Cyberstarter & DOSA - Recurring Expert, Challenge Creator, and Speaker at Sekurak.Academy events

Ongoing

Corporate Training - Specialized Social Engineering & Awareness workshops for private clients

Various

Guest appearances at industry meetups, panels, and closed-door security workshops

CVE Research

Open API Database →
CVE-2025-26855 CVSS 10
SQL Injection in Articles Calendar for Joomla
CVE-2025-26854 CVSS 10
SQL Injection in Articles Good Search for Joomla
CVE-2025-7065 CVSS 10
Remote Code Execution via Unrestricted File Upload in PAD CMS
CVE-2025-7063 CVSS 10
Remote Code Execution via Unrestricted File Upload in PAD CMS
CVE-2025-67649 CVSS 9.3
Unauthenticated SQL Injection in PHP Jabbers – Car Rental Script
CVE-2026-5482 CVSS 9.3
Remote Code Execution via Unrestricted File Upload in Responsive FileManager
CVE-2025-4568 CVSS 9.3
Blind SQL Injection in 'changes__reference_id' parameter in 2ClickPortal CMS
CVE-2025-7385 CVSS 9.3
SQL Injection in 'search[query]' parameter in GOV CMS
CVE-2025-30085 CVSS 9.2
Remote Code Execution in RSForm!Pro for Joomla
CVE-2025-3895 CVSS 9.1
Weak password reset tokens in MegaBIP CMS
CVE-2025-54117 CVSS 9.1
Stored XSS in dashboard text editor in NamelessMC
CVE-2026-46593 CVSS 8.6
Authenticated SQL Injection in PHP Poll Script
CVE-2025-67650 CVSS 8.6
Authenticated SQL Injection in PHP Jabbers scripts
CVE-2025-49485 CVSS 8.6
SQL Injection in Balbooa Forms for Joomla
CVE-2025-49468 CVSS 8.6
SQL Injection in No Boss Calendar for Joomla
CVE-2025-27753 CVSS 8.6
SQL Injection in RSMediaGallery for Joomla
CVE-2025-49486 CVSS 8.6
Stored XSS in Balbooa Gallery for Joomla
CVE-2025-3893 CVSS 8.6
SQL Injection in justification module in MegaBIP CMS
CVE-2025-32465 CVSS 8.5
Stored XSS in RSTickets! for Joomla
CVE-2026-40551 CVSS 8.4
Use of Client-Side Authentication in mpGabinet
CVE-2025-27445 CVSS 8.2
Path Traversal in RSFirewall for Joomla
CVE-2025-53923 CVSS 8.2
Reflected XSS in admin panel in emlog CMS
CVE-2025-22205 CVSS 7.5
Path Traversal in Admiror Gallery for Joomla
CVE-2025-54421 CVSS 7.2
Stored XSS in SEO component in NamelessMC
CVE-2025-67651 CVSS 6.9
CSRF in PHP Jabbers scripts
CVE-2026-40550 CVSS 6.9
Execution with Unnecessary Privileges in mpGabinet
CVE-2025-50057 CVSS 6.9
DoS in RSFiles! for Joomla
CVE-2025-53924 CVSS 6.9
Stored XSS in links functionality in emlog CMS
CVE-2025-32466 CVSS 6.7
SQL Injection in RSMediaGallery! for Joomla
CVE-2025-30084 CVSS 6.7
Stored XSS in RSMail! for Joomla
CVE-2025-27754 CVSS 6.5
Stored XSS in RSBlog for Joomla
CVE-2024-2122 CVSS 6.4
Stored XSS in FooGallery #2 for WordPress
CVE-2025-53926 CVSS 6.1
Reflected XSS in error messages in emlog CMS
CVE-2026-54611 CVSS 5.5
Remote Code Execution in package installe in iCMS2
CVE-2025-6815 CVSS 5.5
Authenticated Stored XSS in LatePoint for WordPress
CVE-2025-53925 CVSS 5.4
Stored XSS in upload functionality in emlog CMS
CVE-2024-2081 CVSS 5.4
Stored XSS in FooGallery for WordPress
CVE-2025-54118 CVSS 5.3
Sensitive information disclosure in member list component in NamelessMC
CVE-2025-50126 CVSS 5.3
Stored XSS in RSBlog! for Joomla
CVE-2026-46594 CVSS 5.1
Reflected XSS in PHP Poll Script - PHP Jabbers
CVE-2025-4379 CVSS 5.1
Reflected XSS in 'szukaj' parameter in DobryCMS
CVE-2025-50056 CVSS 5.1
Reflected XSS in RSMail! for Joomla
CVE-2025-50058 CVSS 5.1
Stored XSS in RSDirectory! for Joomla
CVE-2025-54174 CVSS 5.1
CSRF in Quick.CMS
CVE-2025-7761 CVSS 5.1
Reflected XSS in LepszyBIP CMS
CVE-2025-52994 CVSS 4.9
Remote Code Execution in phpThumb
CVE-2025-7518 CVSS 4.9
Path Traversal in RSFirewall! plugin for WordPress
CVE-2025-27444 CVSS 4.8
Reflected XSS in RSForm!Pro for Joomla
CVE-2025-3894 CVSS 4.8
Stored XSS in text editor in MegaBIP CMS
CVE-2025-54172 CVSS 4.8
Stored XSS in Quick.CMS
CVE-2026-40552 CVSS 4.7
RCE in mpGabinet
CVE-2025-59055 CVSS 4.7
SSRF in InstantCMS
CVE-2025-54175 CVSS 4.6
Reflected XSS in Quick.CMS

Career Path

2026 - PRESENT

Academic Lecturer

University of Economics in Katowice

Conducting academic classes and sharing practical knowledge in the field of cybersecurity and offensive security with students.

2016 - PRESENT

Senior Security Consultant

Securitum

Advanced penetration testing, IT security consulting, and Red Teaming operations. Started as a Consultant (2016), promoted to Senior.

2015 - PRESENT

Owner & Researcher

Safety-Online.pl

Independent security research and tool development. Active Bug Bounty hunter (findings for OLX, OVH, Qwant, Ercom...).

2015

Senior IT Specialist

ING Services Polska

Performed network and application security testing strictly for the banking sector.

2014 - 2015

Programmer

x-kom

Refactoring core PHP engines for one of the largest e-commerce platforms in Poland.

2013 - 2014

Web Developer & Auditor

Agencja WMC

Designed secure web applications and conducted web security audits.

2011 - 2013

Full Stack Dev

Freelance

Focused on software engineering and infrastructure management.

Let's work together

For commercial inquiries (pentests, audits), please contact me via Securitum.
For research, speaking engagements, or training – feel free to reach out directly - ProXy.

ENCRYPT YOUR MESSAGE
-----BEGIN PGP PUBLIC KEY BLOCK----- xjMEaAKVsBYJKwYBBAHaRw8BAQdAIh3aICafTxALxd5J8GM39KnK4PFgvfE+vW5M f9sN+HjNMFJvYmVydCBLcnVjemVrIDxrcnVjemVrLnJvYmVydEBzYWZldHktb25s aW5lLnBsPsKPBBMWCAA3FiEEx3O8/j9EmahYYiwtJ+hKoIkuE/QFAmgClbAFCQlm AYACGwMECwkIBwUVCAkKCwUWAgMBAAAKCRAn6EqgiS4T9OABAQD/hTRenSkXnjWL W5MnwlwoXab+8F6snuOXdOQUXTS8kgD/S+X8gIa65M6H0CcDwZdQTL0zAkX3p7rg ExMcDQsL7AHOOARoApWwEgorBgEEAZdVAQUBAQdAYGkMRICAOo/dYDlFOOhiiVAo lo8CMR19dW2CPnkRXhkDAQgHwn4EGBYIACYWIQTHc7z+P0SZqFhiLC0n6EqgiS4T 9AUCaAKVsAUJCWYBgAIbDAAKCRAn6EqgiS4T9NsqAP44VRZf4fYlnRpWzBVsm4cJ e3VGuuE1WuBq5xmRqQevEAD/f8RDIV+uIK0kQID+CJYIDnQvmRieZEwmnd3bdCps 7gg= =4otu -----END PGP PUBLIC KEY BLOCK-----