Vulnerability Researcher & Exploit Developer
“Some things in life are unpredictable, your Cyber Security doesn’t have to be one of them”
Paolo Stagno (aka VoidSec) has worked as a Penetration Tester for a wide range of clients across top-tier international banks, major tech companies and various Fortune 1000 industries. He was responsible for discovering and exploiting new unknown vulnerabilities in applications, network infrastructure components, IoT devices, protocols, and technologies.
He is now a freelance Vulnerability Researcher and Exploit Developer focused on Windows offensive application security (kernel and user-land). He enjoys understanding the digital world we live in, disassembling, reverse engineering and exploiting complex products and code.
In his own research, he discovered various vulnerabilities in the software of multiple vendors and tech giants like eBay, Facebook, Fastweb, Google, HP, McAfee, Microsoft, Oracle, Paypal, TIM and many others.
Since the beginning of his career, he has enjoyed sharing his expertise with the security community through his website and blog (https://voidsec.com). He is also an active speaker in various security conferences around the globe like HITB, Typhooncon, Hacktivity, SEC-T, Droidcon, HackInBo, M0leCon, TOHack and Meethack.
A list of public vulnerabilities and CVEs that I have discovered can be found on https://voidsec.com/advisories/
- Offensive Security: OSCE
- eLearnSecurity: eCRE, eCXD, eCPPT, eWPTX, eWPT, eJPT
- CompTIA: CASP+, PenTest+
- Pentester Academy: SLAE32
Courses I’ve attended:
- Corelan: Win32 Exploit Development Advanced and Bootcamp
- Ashfaq Ansari: Windows Kernel Exploitation Advanced
- SANS: SEC760, SEC660
- Signal Labs: Vulnerability Research & Fuzzing
- Mossé Cyber Security Institute: MVRE – Certified Vulnerability Researcher & Exploit Developer
- Ptrace Security: Advanced Software Exploitation
- Sektor7 RED TEAM Operator: Malware Development Intermediate and Essentials, Privilege Escalation, Windows Persistence
- eLearnSecurity: eWDP
- Hyperiongray: Zero Day Hunting
- Kamil Frankowicz: Fuzzing, From zero to first 0-day!
- Justin Searle: Assessing and Exploiting Control Systems & IoT