Breaking stuff, Security researcher @pixiepointsec | Pwn2Own Toronto 2023, Tokyo 2025, Ireland 2025

Joined August 2018
1 Photos and videos
Rafał Goryl retweeted
1 Dec 2025
My very first blog post is live: kiddo-pwn.github.io/blog/202… During research, I've run into and documented a simple universal SQLite Injection RCE trick. Enjoy! N-day Analysis about Synology Beestation RCE (CVE-2024-50629~50631) by legendary DEVCORE 🎃 🍊 Thanks to @u1f383 @orange_8361 for original finding and allowing to post, and to @the_emmons for the invaluable references 🔥 Enjoy the Demo! PoC: github.com/kiddo-pwn/CVE-202…
13
112
416
33,476
Rafał Goryl retweeted
22 Oct 2025
All of us the last 3 months of Pwn2own or just me?
1
15
1,409
Rafał Goryl retweeted
Another successful collision: @_voix44er from PixiePoint Security succeeded in exploiting the Phillips Hue Bridge, but the bugs he used were collisions with a previous entry. He still earns $10,000 and 2 Master of Pwn points. #Pwn2Own
4
15
4,129
Rafał Goryl retweeted
Boom! Rafal Goryl (@voix44er) of PixiePoint Security needed two attempts but was able to get his exploit of the Phillips Hue Bridge working. He heads off to the disclosure room to provide all the details. #Pwn2Own
2
2
17
3,596
Rafał Goryl retweeted
And... hot on the heels will be @voix44er attempting the Philips Hue Bridge this week! All the best and have fun!
1
1
7
3,250
Rafał Goryl retweeted
If u think that Windows research is all we do, think again! In our first IOT blog, @voix44er details the Wolfbox EV charger setup, attack surface, his #Pwn2Own Automotive 2025 bug, exploitation, and best of all, displaying our name on it (in styleee...)! pixiepointsecurity.com/blog/…

19
69
6,240
Rafał Goryl retweeted
[ZDI-25-329|CVE-2025-5750] (0Day) (Pwn2Own) WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: Rafal Goryl of PixiePoint Security) zerodayinitiative.com/adviso…
3
14
3,590
Rafał Goryl retweeted
How China Is Building an Army of Hackers. With commentary from ZDI's Dustin Childs and footage from #Pwn2Own Automotive youtu.be/8kpnSb4yGR0?si=Jxoo… via @YouTube
1
12
48
10,022
Rafał Goryl retweeted
Proud to see @_jaelkoh (with @saidelike) talking about undocumented internals of KTM, the bugs and exploits in 'Hunting for Overlooked Cookies in Windows 11 KTM and Baking Exploits for Them'. No ovens required for this recipe!
3
10
2,608
Rafał Goryl retweeted
28 Mar 2025
A novel way to implement loops: godbolt.org/z/164jvGz1b
18
31
682
54,696
Rafał Goryl retweeted
28 Feb 2025
I've been working in cybersecurity for over 25 years. Here are my key insights.
27
146
1,027
48,298
Rafał Goryl retweeted
Confirmed (with a collision)! Rafal Goryl of PixiePoint Security used a 2 bug chain to exploit the WOLFBOX Level 2 EV Charger, but one of the bugs was previously known. He earns himself $18,750 and 3.75 Master of Pwn points. #P2OAuto
1
11
3,073
Rafał Goryl retweeted
Annnddd... the odds ARE in your favor! Congrats @voix44er ! This result is just the cherry on the cake. Regardless of what it may be, what we don't see is the dedication and hard work put into the research.. 💪💪💪
Success! On his second attempt, Rafal Goryl of PixiePoint Security was able to exploit the WOLFBOX EV charger. He heads off the the disclosure room to provide us with all the details. #P2OAuto #Pwn2Own
3
9
1,563
Rafał Goryl retweeted
Hello world! First post in 2025; @voix44er attempting to pwn WolfBox EV charger at #P2OAuto on Day 2. “May the odds be ever in your favor”!
5
13
2,188
Rafał Goryl retweeted
Paged Out! Issue #5 is out now! pagedout.institute/?page=iss… Happy reading! Please RT and tell your friends! :)
5
124
213
60,895
Rafał Goryl retweeted
24 Jun 2024
[ZDI-24-839|CVE-2024-6248] (Pwn2Own) Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability (CVSS 7.5; Credit: Rafal Goryl) zerodayinitiative.com/adviso…
2
3
600
Rafał Goryl retweeted
6 Jun 2024
The libarchive e8 vulnerability is actually really cool, but the ZDI advisory doesn't explain why it's so wild lol. For some reason, I know about RAR filters, so let me provide the background. 🧵 1/n
3
173
596
116,718
Rafał Goryl retweeted
7 Jun 2024
2
37
205
22,718
10 May 2024
Excited to be at @offensive_con! If you want to, feel free to hit me up.
4
108