Pentester · Security auditor

I find the flaws in your devices before someone else does

I'm Jakub Lipiec, a penetration tester and security auditor. I test hardware and software - from embedded circuits, through connected and industrial devices, to automotive systems. I also run training and workshops for technical teams.

Experience

Where I work and contribute

Employment, independent work and industry bodies. The full story is on the about page.

How it looks

A typical device assessment

An illustration of how I work. The actual steps depend on what I'm given and what the agreed scope covers.

$ recon --hardware
[*] Debug interface exposed on pads TP4-TP7
[*] Memory: SPI NOR, 8 MB, read protection not enabled
$ firmware extract && analyze
[!] API key stored in plaintext in the configuration
[!] OTA update accepted without signature verification
$ report --format pdf --cvss 3.1
[+] Report ready: 2 critical, 5 high, each with remediation steps

Every finding comes with proof of exploitation, a CVSS 3.1 rating and a concrete fix. Without the first you can't tell if it's real; without the third you can't tell what to do about it.

Why me

What you get beyond the report

Real vulnerabilities, not scanner output

A scanner spits out hundreds of findings with no context. I show you what can actually be exploited, and how to fix it.

Hardware fluency

Most testers stop at the application layer. I go down to the board: chips, interfaces, firmware.

I can explain it

I speak and teach for a living, so the report also lands with management - in language that translates into decisions.

Alerts

See how many vulnerabilities are out there

The CISA catalog collects vulnerabilities known to have been actually used in attacks - not the ones that could theoretically cause harm. It holds 1 656 entries today and only ever grows; 172 were added in 2026 alone. The four newest are below.

Updated:

  • Medium CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Cisco · Secure Firewall Management Center (FMC)
  • Medium CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability Fortinet · FortiOS
  • Critical CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability Arista · VeloCloud Orchestrator
  • Critical CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability Check Point · SmartConsole

Shipping a device to customers?

Tell me briefly what it is and where you are in the process. I'll tell you whether and how I can help - no strings attached.