I am a Cybersecurity Consultant, Mentor, and Ethical Hacker (known in the infosec community as ProXy) at Securitum - Poland's leading cybersecurity firm - and a contributor to sekurak.pl, the country's largest infosec portal.
With over 10 years of experience in vulnerability research and penetration testing.
Operating under the ProXy alias, I discovered and reported 53 CVEs and I am an active Bug Bounty hunter (Hall of Fame at OLX, reports for BlaBlaCar, OVH, and ERCOM).
Born in 1991 in Katowice, I’ve always been driven by curiosity—breaking down toys to see how they worked. My programming journey began at age 8, leading to commercial projects by 16. My passion for Offensive Security sparked early, experimenting with game server mechanics and exploit development.
Currently, I balance offensive work with extensive education, serving as an Academic Lecturer at the University of Economics in Katowice. I am also a regular speaker at DOSA (Sekurak.Academy Open Days) and the nationwide Cyberstarter initiative.
Beyond public speaking, I conduct specialized Social Engineering trainings for corporate clients and serve as a Trainer for the Websecurity Master program.
Beyond the terminal, the person behind the ProXy handle is an avid League of Legends player, an equestrian, and a volunteer for an exotic animal rescue organization.
My radio interview where we break down the mindset and true role of ethical hackers in modern cybersecurity. We discuss how our motivations differ from black hats, focusing on securing infrastructure rather than chasing money or fame.
A technical breakdown of a security audit on a legacy VB6 application. It demonstrates how relying on a direct database connection and client-side authentication allows an attacker to completely bypass the login mechanism via binary patching.
PAD CMS – Security Advisory and Critical Flaws Analysis
A technical advisory and vulnerability analysis of PAD CMS. This research led to the discovery of critical flaws, including Remote Code Execution (RCE), affecting multiple public institution websites.
A technical look into how North Korean APT groups leverage fake job offers and GitHub repositories to distribute sophisticated malware to security researchers.
Phishing Under the Lens – Analysis of Cybercriminal Tactics
A comprehensive analysis of modern phishing techniques, psychological triggers used by attackers, and technical methods to bypass traditional email security filters.
A fascinating case study where ChatGPT generated a security tool containing a critical vulnerability, potentially allowing an attacker to compromise the pentester's own machine.
Unveiling Hidden Data: A Log Files Security Breach
Technical research on how improperly secured log files can become a goldmine for attackers, leading to the exposure of sensitive session tokens, credentials, and system architecture details.
Conducting academic classes and sharing practical knowledge in the field of cybersecurity and offensive security with students.
2016 - PRESENT
Senior Security Consultant
Securitum
Advanced penetration testing, IT security consulting, and Red Teaming operations.
Started as a Consultant (2016), promoted to Senior.
2015 - PRESENT
Owner & Researcher
Safety-Online.pl
Independent security research and tool development. Active Bug Bounty hunter
(findings for OLX, OVH, Qwant, Ercom...).
2015
Senior IT Specialist
ING Services Polska
Performed network and application security testing strictly for the banking sector.
2014 - 2015
Programmer
x-kom
Refactoring core PHP engines for one of the largest e-commerce platforms in Poland.
2013 - 2014
Web Developer & Auditor
Agencja WMC
Designed secure web applications and conducted web security audits.
2011 - 2013
Full Stack Dev
Freelance
Focused on software engineering and infrastructure management.
Let's work together
For commercial inquiries (pentests, audits), please contact me via Securitum.
For research, speaking engagements, or training – feel free to reach out directly - ProXy.