A Cybersecurity Consultancy Boutique that Provides Niche & Bespoke Research Services

Joined September 2019
4 Photos and videos
9% into 2026 and look what @cloudlldb already have... :)
1
16
4,014
And... hot on the heels will be @voix44er attempting the Philips Hue Bridge this week! All the best and have fun!
1
1
7
3,250
Looks like @__neverm0r_ and @b1thvn_ TyphoonPwn entry is patched this month as CVE-2025-55681... thanks @SecuriTeam_SSD for the fun experience!
2
17
4,515
If u think that Windows research is all we do, think again! In our first IOT blog, @voix44er details the Wolfbox EV charger setup, attack surface, his #Pwn2Own Automotive 2025 bug, exploitation, and best of all, displaying our name on it (in styleee...)! pixiepointsecurity.com/blog/…

19
69
6,240
Proud to see @_jaelkoh (with @saidelike) talking about undocumented internals of KTM, the bugs and exploits in 'Hunting for Overlooked Cookies in Windows 11 KTM and Baking Exploits for Them'. No ovens required for this recipe!
3
10
2,608
Unfortunate, but still a good showing! 🫡
Replying to @thezdi
Confirmed (with a collision)! Rafal Goryl of PixiePoint Security used a 2 bug chain to exploit the WOLFBOX Level 2 EV Charger, but one of the bugs was previously known. He earns himself $18,750 and 3.75 Master of Pwn points. #P2OAuto
1
3
781
Annnddd... the odds ARE in your favor! Congrats @voix44er ! This result is just the cherry on the cake. Regardless of what it may be, what we don't see is the dedication and hard work put into the research.. 💪💪💪
Success! On his second attempt, Rafal Goryl of PixiePoint Security was able to exploit the WOLFBOX EV charger. He heads off the the disclosure room to provide us with all the details. #P2OAuto #Pwn2Own
3
9
1,563
Hello world! First post in 2025; @voix44er attempting to pwn WolfBox EV charger at #P2OAuto on Day 2. “May the odds be ever in your favor”!
5
13
2,188
Sometimes your past has a way of sneaking up/"garbage-collecting" on you.. Well done @b1thvn_, and thanks @TheZDIBugs for tracking these zerodayinitiative.com/adviso… zerodayinitiative.com/adviso…

1
3
1,171
All shells are spawned equal, regardless of memory-corruption bugs or not! CVE-2021-34462: Exploiting the Windows AppXSvc Service Logic-Error Vulnerability pixiepointsecurity.com/blog/…

1
32
66
13,708
Credit: Dewang Ahluwalia
1,398
New year, new blog post! CVE-2021-31985: Exploiting the Windows Defender AsProtect Heap Overflow Vulnerability pixiepointsecurity.com/blog/…

1
63
154
30,674
Credit: Wei Lei
4
1,397
As it is confirmed to be the ITW CVE-2022-24521, we also contributed the content to GP0 for interested folks googleprojectzero.github.io/…

RCA for 1 of the 2 CLFS bugs patched in April 2022. While we can't determine the CVE, we did managed to exploit it ;) ... credit: @b1thvn_ pixiepointsecurity.com/blog/…
1
14
51
Props to @maddiestone for maintaining this ITW RCA program :)
1
4
RCA for 1 of the 2 CLFS bugs patched in April 2022. While we can't determine the CVE, we did managed to exploit it ;) ... credit: @b1thvn_ pixiepointsecurity.com/blog/…
56
143
Demo of CVE-2021-31985... credit: Wei Lei
2
24
112